{
  "schema": "sosec.cis-controls-v8.1.safeguard-prd-register.v1",
  "research_cutoff": "2026-07-28",
  "normative_reference": "CIS Controls v8.1",
  "scope": {
    "controls": 18,
    "safeguards": 153,
    "prd_dimensions_per_safeguard": 12,
    "minimum_requirements_per_dimension": 6,
    "maximum_requirements_per_dimension": 9,
    "minimum_requirements_per_safeguard": 72,
    "maximum_requirements_per_safeguard": 108,
    "total_atomic_requirements": 13020,
    "requirement_count_distribution": {
      "72": 37,
      "84": 70,
      "96": 41,
      "108": 5
    },
    "category_totals": {
      "outcome": 1085,
      "scope": 1085,
      "ownership": 1085,
      "data": 1085,
      "integration": 1085,
      "control": 1085,
      "timing": 1085,
      "exception": 1085,
      "evidence": 1085,
      "security": 1085,
      "testing": 1085,
      "operations": 1085
    }
  },
  "method": {
    "normative_identity": "Safeguard ID, short title, IG, Asset Class, and Security Function are used for nominative reference to the pinned official sources.",
    "assessment_context": "CAS dependencies and measure identifiers are mapped as source context without republishing the official assessment text.",
    "original_analysis": "Every atomic requirement is original SOSEC implementation, product, evidence, boundary, test, or operating guidance.",
    "acceptance_boundary": "The register is a reusable PRD and review baseline. Enterprise risk, architecture, law, safety, provider contracts, and authorized testing determine local applicability.",
    "license_boundary": "The register is not an official CIS publication, certification, replacement edition, or grant of rights to reproduce CIS material."
  },
  "categories": [
    {
      "key": "outcome",
      "code": "OUT",
      "en": "Outcome and decision",
      "zh": "目标与决策"
    },
    {
      "key": "scope",
      "code": "SCP",
      "en": "Population and applicability",
      "zh": "总体与适用性"
    },
    {
      "key": "ownership",
      "code": "OWN",
      "en": "Ownership and approval",
      "zh": "责任与审批"
    },
    {
      "key": "data",
      "code": "DAT",
      "en": "Data contract and identity",
      "zh": "数据契约与身份"
    },
    {
      "key": "integration",
      "code": "INT",
      "en": "Dependencies and integrations",
      "zh": "依赖与集成"
    },
    {
      "key": "control",
      "code": "CTL",
      "en": "Control flow and enforcement",
      "zh": "控制流与执行"
    },
    {
      "key": "timing",
      "code": "TIM",
      "en": "Timing and lifecycle",
      "zh": "时序与生命周期"
    },
    {
      "key": "exception",
      "code": "EXC",
      "en": "Exceptions and failure modes",
      "zh": "例外与失效模式"
    },
    {
      "key": "evidence",
      "code": "EVD",
      "en": "Evidence and metrics",
      "zh": "证据与指标"
    },
    {
      "key": "security",
      "code": "SEC",
      "en": "Security, privacy, and resilience",
      "zh": "安全、隐私与韧性"
    },
    {
      "key": "testing",
      "code": "TST",
      "en": "Verification and adversarial tests",
      "zh": "验证与对抗测试"
    },
    {
      "key": "operations",
      "code": "OPS",
      "en": "Operations, change, and closure",
      "zh": "运营、变更与收口"
    }
  ],
  "safeguards": [
    {
      "id": "1.1",
      "control": 1,
      "title_en": "Establish and Maintain Detailed Enterprise Asset Inventory",
      "title_zh": "企业资产总账",
      "first_ig": 1,
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Devices",
      "security_function": "Identify",
      "patterns": [
        "inventory"
      ],
      "expanded_complexity": true,
      "cas_context": {
        "dependencies": [],
        "variables": [
          "GV1",
          "GV2",
          "M1",
          "M2",
          "M3",
          "M4",
          "M5",
          "M6",
          "M7",
          "M8"
        ],
        "metric_branches": 2,
        "has_assumptions": true,
        "has_procedural_review": true
      },
      "official_cadence_terms": [
        "bi-annually",
        "annually"
      ],
      "implementation_contract": {
        "en": {
          "scope": "The population includes every device able to store or process enterprise data: managed and unmanaged endpoints, servers, network appliances, virtual machines, ephemeral cloud instances, containers' host/control-plane assets, mobile, IoT/OT, lab and regularly connected third-party devices.",
          "build": "Make one asset authority reconcile procurement, MDM/EDR, hypervisors, cloud organizations and accounts, network discovery, DHCP/IPAM, and disposal records.",
          "proof": "Prove both completeness and field quality against an independently assembled aggregate population.",
          "boundary": "A scanner's silence never proves absence: sleeping laptops, private subnets, serverless services, SaaS tenants, isolated OT and travel devices need other sources."
        },
        "zh": {
          "scope": "范围包括一切能够存储或处理企业数据的设备：受管与非受管终端、服务器、网络设备、虚机、云实例、容器宿主与控制面、移动设备、IoT/OT、实验设备，以及经常接入的第三方设备。",
          "build": "指定一个资产权威台账，持续对账采购、MDM/EDR、虚拟化、云组织与账号、网络发现、DHCP/IPAM 和报废记录。",
          "proof": "用独立拼出的“应有资产总体”同时检验覆盖率和字段质量。",
          "boundary": "扫描器没看到不代表资产不存在；休眠笔记本、私网、Serverless、SaaS 租户、隔离 OT 和出差设备要靠别的来源。"
        }
      },
      "category_counts": {
        "outcome": 7,
        "scope": 7,
        "ownership": 7,
        "data": 7,
        "integration": 7,
        "control": 7,
        "timing": 7,
        "exception": 7,
        "evidence": 7,
        "security": 7,
        "testing": 7,
        "operations": 7
      },
      "requirement_count": 84,
      "requirements": [
        {
          "code": "CIS-1.1-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "1.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Establish and Maintain Detailed Enterprise Asset Inventory; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“企业资产总账”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-1.1-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "1.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 1.1, official Asset Class Devices, Security Function Identify, and IG1 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 1.1、官方资产类别“设备”、安全功能“识别”和首次出现的 IG1，并保存来源抓取日期。"
        },
        {
          "code": "CIS-1.1-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "1.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “The population includes every device able to store or process enterprise data: managed and unmanaged endpoints, servers, network appliances, virtual machines, ephemeral cloud instances, containers' host/control-plane assets, mobile, IoT/OT, lab and regularly connected third-party devices.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“范围包括一切能够存储或处理企业数据的设备：受管与非受管终端、服务器、网络设备、虚机、云实例、容器宿主与控制面、移动设备、IoT/OT、实验设备，以及经常接入的第三方设备。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-1.1-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "1.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-1.1-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "1.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Establish and Maintain Detailed Enterprise Asset Inventory to its operating object—physical, virtual, cloud, mobile, IoT/OT, lab, and regularly connected third-party enterprise assets—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“企业资产总账”连接到其运营对象——物理、虚拟、云、移动、IoT/OT、实验环境以及经常接入的第三方企业资产——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-1.1-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "1.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "For Establish and Maintain Detailed Enterprise Asset Inventory, express success as an observable decision over observed, approved, unapproved, ownerless, stale, duplicate, and retired object identity; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“企业资产总账”，以 已观测、已批准、未批准、无责任人、陈旧、重复和已退役对象身份 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-1.1-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "1.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "For the expanded Establish and Maintain Detailed Enterprise Asset Inventory scope, resolve conflicts among security, safety, privacy, legal, availability, customer, and operational objectives through an explicit risk decision.",
          "zh": "对“企业资产总账”的扩展范围，通过显式风险决策解决安全、安全生产、隐私、法律、可用性、客户和运营目标冲突。"
        },
        {
          "code": "CIS-1.1-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "1.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-1.1-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "1.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-1.1-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "1.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-1.1-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "1.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-1.1-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "1.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across sleeping, ephemeral, disconnected, unmanaged, duplicated, shared-address, and safety-sensitive assets; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 休眠、短生、离线、未托管、重复、共享地址以及安全关键资产 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-1.1-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "1.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Include dormant, ephemeral, disconnected, externally managed, provider-held, aliased, cloned, and cross-tenant objects in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 休眠、短生、离线、外部托管、提供商持有、别名、克隆和跨租户对象 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-1.1-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "1.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Define nested scope at enterprise, business service, tenant, environment, platform, object, identity, data set, and transaction levels; prohibit a parent result from hiding a failing child.",
          "zh": "按企业、业务服务、租户、环境、平台、对象、身份、数据集和交易定义嵌套范围，禁止父级结果遮蔽失败子级。"
        },
        {
          "code": "CIS-1.1-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "1.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-1.1-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "1.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-1.1-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "1.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-1.1-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "1.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-1.1-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "1.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind asset owners, platform and network operators, procurement, and security operations to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 资产责任人、平台与网络运营方、采购和安全运营 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-1.1-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "1.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Name who may transition discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-1.1-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "1.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Model delegated authority, quorum or dual approval where warranted, escalation deadlines, provider handoffs, conflict resolution, and executive risk acceptance.",
          "zh": "建模委派权限、必要时的双人或法定人数审批、升级期限、提供商交接、冲突解决和管理层风险接受。"
        },
        {
          "code": "CIS-1.1-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "1.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-1.1-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "1.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-1.1-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "1.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV1, GV2, M1, M2, M3, M4, M5, M6, M7, M8) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV1, GV2, M1, M2, M3, M4, M5, M6, M7, M8）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-1.1-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "1.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-1.1-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "1.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the reconciled enterprise asset authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把经过多源对账的企业资产权威台账作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-1.1-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "1.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence.",
          "zh": "对生命周期“发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-1.1-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "1.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Version schemas and state transitions with migration, backfill, deduplication, lineage, historical denominator, deletion, and rollback semantics.",
          "zh": "对模式和状态转换做版本管理，定义迁移、回填、去重、血缘、历史分母、删除和回滚语义。"
        },
        {
          "code": "CIS-1.1-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "1.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for no explicit predecessor in the pinned CAS page; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 固定 CAS 页面没有列出显式前置项 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-1.1-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "1.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-1.1-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "1.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-1.1-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "1.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-1.1-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "1.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile procurement, EDR/MDM, hypervisors, cloud inventories, DHCP/IPAM, network discovery, and disposal records and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 采购、EDR/MDM、虚拟化平台、云清单、DHCP/IPAM、网络发现与报废记录，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-1.1-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "1.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Require every connector carrying observed, approved, unapproved, ownerless, stale, duplicate, and retired object identity to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 已观测、已批准、未批准、无责任人、陈旧、重复和已退役对象身份 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-1.1-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "1.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Define consistency rules across disagreeing sources, source precedence, confidence, reconciliation queues, dead-letter handling, reprocessing, and end-to-end trace identity.",
          "zh": "定义冲突来源的一致性、优先级、置信度、对账队列、死信、重处理和端到端追踪身份。"
        },
        {
          "code": "CIS-1.1-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "1.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Make one asset authority reconcile procurement, MDM/EDR, hypervisors, cloud organizations and accounts, network discovery, DHCP/IPAM, and disposal records.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“指定一个资产权威台账，持续对账采购、MDM/EDR、虚拟化、云组织与账号、网络发现、DHCP/IPAM 和报废记录。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-1.1-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "1.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-1.1-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "1.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-1.1-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "1.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-1.1-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "1.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the reconciled enterprise asset authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在经过多源对账的企业资产权威台账中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-1.1-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "1.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Implement the explicit state machine discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-1.1-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "1.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Specify concurrent decisions, partial success, compensating transactions, repeated requests, stale policy, dependency outage, and recovery from an interrupted state transition.",
          "zh": "定义并发决策、部分成功、补偿事务、重复请求、陈旧策略、依赖中断和中途状态转换恢复。"
        },
        {
          "code": "CIS-1.1-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "1.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (bi-annually, annually); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（bi-annually, annually）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-1.1-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "1.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-1.1-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "1.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-1.1-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "1.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-1.1-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "1.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in physical, virtual, cloud, mobile, IoT/OT, lab, and regularly connected third-party enterprise assets; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 物理、虚拟、云、移动、IoT/OT、实验环境以及经常接入的第三方企业资产 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-1.1-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "1.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence; alert before each deadline becomes overdue.",
          "zh": "为“发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-1.1-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "1.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Allocate an end-to-end SLO budget across discovery, collection, processing, approval, enforcement, verification, and closure; prioritize overdue work by consequence and exposure.",
          "zh": "把端到端 SLO 预算分配到发现、采集、处理、审批、执行、验证和关闭，并按后果与暴露排列逾期工作。"
        },
        {
          "code": "CIS-1.1-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "1.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “A scanner's silence never proves absence: sleeping laptops, private subnets, serverless services, SaaS tenants, isolated OT and travel devices need other sources.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“扫描器没看到不代表资产不存在；休眠笔记本、私网、Serverless、SaaS 租户、隔离 OT 和出差设备要靠别的来源。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-1.1-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "1.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-1.1-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "1.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-1.1-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "1.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-1.1-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "1.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat sleeping, ephemeral, disconnected, unmanaged, duplicated, shared-address, and safety-sensitive assets as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 休眠、短生、离线、未托管、重复、共享地址以及安全关键资产 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-1.1-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "1.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Treat dormant, ephemeral, disconnected, externally managed, provider-held, aliased, cloned, and cross-tenant objects as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 休眠、短生、离线、外部托管、提供商持有、别名、克隆和跨租户对象 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-1.1-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "1.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Exercise compound failures where an exception, stale source, provider outage, unavailable owner, and degraded control overlap; define one safe command and one accountable decision.",
          "zh": "演练例外、陈旧来源、提供商中断、责任人不可用和控制降级同时出现的复合故障，明确一条安全指令和一个责任决策。"
        },
        {
          "code": "CIS-1.1-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "1.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Prove both completeness and field quality against an independently assembled aggregate population.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“用独立拼出的“应有资产总体”同时检验覆盖率和字段质量。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-1.1-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "1.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-1.1-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "1.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 2 pinned CAS metric branch(es), 10 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 2 个指标分支、10 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-1.1-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "1.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-1.1-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "1.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the reconciled enterprise asset authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以经过多源对账的企业资产权威台账和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-1.1-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "1.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Publish matched, missing, duplicate, stale, ownerless, unapproved, unevaluable, and retired-without-proof counts with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 匹配、缺失、重复、陈旧、无责任人、未批准、不可评估及无证明退役数量，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-1.1-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "1.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Require an independent party to reconstruct the decision from source receipts and reproduce the population, state transition, calculation, test result, exception, and final closure.",
          "zh": "要求独立人员使用来源回执重建决策，并复现总体、状态转换、计算、测试结果、例外和最终关闭。"
        },
        {
          "code": "CIS-1.1-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "1.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-1.1-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "1.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-1.1-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "1.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-1.1-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "1.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-1.1-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "1.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the reconciled enterprise asset authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护经过多源对账的企业资产权威台账的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-1.1-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "1.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Restrict authority to change discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-1.1-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "1.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Threat-model the implementation system itself: forged evidence, poisoned inventory, privilege abuse, cross-tenant confusion, policy rollback, audit deletion, denial of service, and recovery compromise.",
          "zh": "威胁建模实施系统自身：伪造证据、污染清单、权限滥用、跨租户混淆、策略回滚、审计删除、拒绝服务和恢复失陷。"
        },
        {
          "code": "CIS-1.1-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "1.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-1.1-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "1.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-1.1-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "1.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-1.1-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "1.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-1.1-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "1.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise approved and unauthorized seeded assets, a disappearing asset, a duplicate identity, and a failed discovery source through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 已批准与未授权的植入资产、突然消失的资产、重复身份和失效的发现源，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-1.1-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "1.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Run the positive control a seeded approved object reconciled from two independent sources; exercise negative, stale, duplicate, bypass, and outage controls including an unknown object, duplicate identity, stale record, vanished object, failed source, and cross-tenant collision.",
          "zh": "运行正向控制“从两个独立来源对账的一项植入已批准对象”，并执行包含“未知对象、重复身份、陈旧记录、突然消失对象、失效来源和跨租户碰撞”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-1.1-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "1.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Build a pairwise platform-and-failure matrix, then add high-consequence multi-factor cases, historical regression, source substitution, red-team challenge, and assessor replay.",
          "zh": "建立平台—故障两两组合矩阵，再加入高后果多因素案例、历史回归、来源替换、红队挑战和评估方重放。"
        },
        {
          "code": "CIS-1.1-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "1.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-1.1-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "1.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-1.1-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "1.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-1.1-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "1.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-1.1-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "1.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever procurement, EDR/MDM, hypervisors, cloud inventories, DHCP/IPAM, network discovery, and disposal records change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 采购、EDR/MDM、虚拟化平台、云清单、DHCP/IPAM、网络发现与报废记录 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-1.1-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "1.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Use matched, missing, duplicate, stale, ownerless, unapproved, unevaluable, and retired-without-proof counts to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 匹配、缺失、重复、陈旧、无责任人、未批准、不可评估及无证明退役数量 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-1.1-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "1.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Use canary deployment, kill criteria, rollback, backlog burn-down, exception reduction, source-quality targets, quarterly design review, and a measurable retirement plan.",
          "zh": "采用金丝雀、停止标准、回滚、积压燃尽、例外缩减、来源质量目标、季度设计复核和可量化退役计划。"
        }
      ]
    },
    {
      "id": "1.2",
      "control": 1,
      "title_en": "Address Unauthorized Assets",
      "title_zh": "处置未授权资产",
      "first_ig": 1,
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Devices",
      "security_function": "Respond",
      "patterns": [
        "inventory"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "1.1"
        ],
        "variables": [
          "GV1",
          "GV2",
          "M1",
          "M2",
          "M3",
          "M4",
          "M5"
        ],
        "metric_branches": 1,
        "has_assumptions": true,
        "has_procedural_review": false
      },
      "official_cadence_terms": [
        "weekly"
      ],
      "implementation_contract": {
        "en": {
          "scope": "The denominator is every asset observed outside the approved state, including unknown hardware, unmanaged virtual machines, stale cloud resources, rogue wireless devices and approved assets connected through an unapproved path.",
          "build": "Define a weekly-or-faster disposition queue joining the asset register to NAC, MDM, EDR, cloud and network evidence.",
          "proof": "Plant an unauthorized test device and cloud instance, then confirm detection, ticket creation, containment at every reachable path and final inventory update.",
          "boundary": "Sleeping, roaming, powered-off and segmented assets stay open until custody or enforcement is established."
        },
        "zh": {
          "scope": "总体是所有未处于批准状态的资产，包括未知硬件、未管虚机、遗留云资源、私接无线设备，以及从未批准路径接入的已批准设备。",
          "build": "至少每周把资产台账与 NAC、MDM、EDR、云和网络观测合并成处置队列。",
          "proof": "在测试范围接入未授权设备并创建未授权云实例，验证发现、工单、所有可达路径上的隔离和最终台账更新。",
          "boundary": "休眠、漫游、关机和被分段隔离的设备，在确认保管或强制策略前仍是开放事项。"
        }
      },
      "category_counts": {
        "outcome": 6,
        "scope": 6,
        "ownership": 6,
        "data": 6,
        "integration": 6,
        "control": 6,
        "timing": 6,
        "exception": 6,
        "evidence": 6,
        "security": 6,
        "testing": 6,
        "operations": 6
      },
      "requirement_count": 72,
      "requirements": [
        {
          "code": "CIS-1.2-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "1.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Address Unauthorized Assets; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“处置未授权资产”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-1.2-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "1.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 1.2, official Asset Class Devices, Security Function Respond, and IG1 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 1.2、官方资产类别“设备”、安全功能“响应”和首次出现的 IG1，并保存来源抓取日期。"
        },
        {
          "code": "CIS-1.2-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "1.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “The denominator is every asset observed outside the approved state, including unknown hardware, unmanaged virtual machines, stale cloud resources, rogue wireless devices and approved assets connected through an unapproved path.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“总体是所有未处于批准状态的资产，包括未知硬件、未管虚机、遗留云资源、私接无线设备，以及从未批准路径接入的已批准设备。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-1.2-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "1.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-1.2-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "1.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Address Unauthorized Assets to its operating object—physical, virtual, cloud, mobile, IoT/OT, lab, and regularly connected third-party enterprise assets—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“处置未授权资产”连接到其运营对象——物理、虚拟、云、移动、IoT/OT、实验环境以及经常接入的第三方企业资产——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-1.2-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "1.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "For Address Unauthorized Assets, express success as an observable decision over observed, approved, unapproved, ownerless, stale, duplicate, and retired object identity; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“处置未授权资产”，以 已观测、已批准、未批准、无责任人、陈旧、重复和已退役对象身份 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-1.2-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "1.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-1.2-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "1.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-1.2-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "1.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-1.2-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "1.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-1.2-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "1.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across sleeping, ephemeral, disconnected, unmanaged, duplicated, shared-address, and safety-sensitive assets; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 休眠、短生、离线、未托管、重复、共享地址以及安全关键资产 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-1.2-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "1.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Include dormant, ephemeral, disconnected, externally managed, provider-held, aliased, cloned, and cross-tenant objects in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 休眠、短生、离线、外部托管、提供商持有、别名、克隆和跨租户对象 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-1.2-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "1.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-1.2-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "1.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-1.2-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "1.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-1.2-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "1.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-1.2-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "1.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind asset owners, platform and network operators, procurement, and security operations to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 资产责任人、平台与网络运营方、采购和安全运营 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-1.2-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "1.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Name who may transition discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-1.2-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "1.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-1.2-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "1.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-1.2-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "1.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV1, GV2, M1, M2, M3, M4, M5) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV1, GV2, M1, M2, M3, M4, M5）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-1.2-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "1.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-1.2-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "1.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the reconciled enterprise asset authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把经过多源对账的企业资产权威台账作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-1.2-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "1.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence.",
          "zh": "对生命周期“发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-1.2-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "1.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 1.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 1.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-1.2-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "1.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-1.2-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "1.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-1.2-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "1.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-1.2-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "1.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile procurement, EDR/MDM, hypervisors, cloud inventories, DHCP/IPAM, network discovery, and disposal records and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 采购、EDR/MDM、虚拟化平台、云清单、DHCP/IPAM、网络发现与报废记录，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-1.2-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "1.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Require every connector carrying observed, approved, unapproved, ownerless, stale, duplicate, and retired object identity to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 已观测、已批准、未批准、无责任人、陈旧、重复和已退役对象身份 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-1.2-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "1.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Define a weekly-or-faster disposition queue joining the asset register to NAC, MDM, EDR, cloud and network evidence.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“至少每周把资产台账与 NAC、MDM、EDR、云和网络观测合并成处置队列。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-1.2-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "1.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-1.2-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "1.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-1.2-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "1.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-1.2-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "1.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the reconciled enterprise asset authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在经过多源对账的企业资产权威台账中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-1.2-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "1.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Implement the explicit state machine discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-1.2-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "1.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (weekly); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（weekly）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-1.2-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "1.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-1.2-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "1.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-1.2-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "1.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-1.2-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "1.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in physical, virtual, cloud, mobile, IoT/OT, lab, and regularly connected third-party enterprise assets; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 物理、虚拟、云、移动、IoT/OT、实验环境以及经常接入的第三方企业资产 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-1.2-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "1.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence; alert before each deadline becomes overdue.",
          "zh": "为“发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-1.2-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "1.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “Sleeping, roaming, powered-off and segmented assets stay open until custody or enforcement is established.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“休眠、漫游、关机和被分段隔离的设备，在确认保管或强制策略前仍是开放事项。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-1.2-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "1.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-1.2-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "1.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-1.2-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "1.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-1.2-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "1.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat sleeping, ephemeral, disconnected, unmanaged, duplicated, shared-address, and safety-sensitive assets as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 休眠、短生、离线、未托管、重复、共享地址以及安全关键资产 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-1.2-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "1.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Treat dormant, ephemeral, disconnected, externally managed, provider-held, aliased, cloned, and cross-tenant objects as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 休眠、短生、离线、外部托管、提供商持有、别名、克隆和跨租户对象 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-1.2-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "1.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Plant an unauthorized test device and cloud instance, then confirm detection, ticket creation, containment at every reachable path and final inventory update.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“在测试范围接入未授权设备并创建未授权云实例，验证发现、工单、所有可达路径上的隔离和最终台账更新。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-1.2-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "1.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-1.2-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "1.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 7 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、7 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-1.2-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "1.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-1.2-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "1.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the reconciled enterprise asset authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以经过多源对账的企业资产权威台账和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-1.2-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "1.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Publish matched, missing, duplicate, stale, ownerless, unapproved, unevaluable, and retired-without-proof counts with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 匹配、缺失、重复、陈旧、无责任人、未批准、不可评估及无证明退役数量，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-1.2-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "1.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-1.2-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "1.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-1.2-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "1.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-1.2-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "1.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-1.2-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "1.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the reconciled enterprise asset authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护经过多源对账的企业资产权威台账的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-1.2-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "1.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Restrict authority to change discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-1.2-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "1.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-1.2-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "1.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-1.2-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "1.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-1.2-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "1.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-1.2-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "1.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise approved and unauthorized seeded assets, a disappearing asset, a duplicate identity, and a failed discovery source through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 已批准与未授权的植入资产、突然消失的资产、重复身份和失效的发现源，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-1.2-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "1.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Run the positive control a seeded approved object reconciled from two independent sources; exercise negative, stale, duplicate, bypass, and outage controls including an unknown object, duplicate identity, stale record, vanished object, failed source, and cross-tenant collision.",
          "zh": "运行正向控制“从两个独立来源对账的一项植入已批准对象”，并执行包含“未知对象、重复身份、陈旧记录、突然消失对象、失效来源和跨租户碰撞”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-1.2-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "1.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-1.2-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "1.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-1.2-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "1.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-1.2-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "1.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-1.2-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "1.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever procurement, EDR/MDM, hypervisors, cloud inventories, DHCP/IPAM, network discovery, and disposal records change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 采购、EDR/MDM、虚拟化平台、云清单、DHCP/IPAM、网络发现与报废记录 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-1.2-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "1.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Use matched, missing, duplicate, stale, ownerless, unapproved, unevaluable, and retired-without-proof counts to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 匹配、缺失、重复、陈旧、无责任人、未批准、不可评估及无证明退役数量 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "1.3",
      "control": 1,
      "title_en": "Utilize an Active Discovery Tool",
      "title_zh": "主动发现",
      "first_ig": 2,
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Devices",
      "security_function": "Detect",
      "patterns": [
        "inventory",
        "discovery"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "4.1"
        ],
        "variables": [
          "GV1",
          "GV3",
          "M1",
          "M2",
          "M3",
          "M4",
          "M5",
          "M6",
          "M7"
        ],
        "metric_branches": 2,
        "has_assumptions": true,
        "has_procedural_review": false
      },
      "official_cadence_terms": [
        "daily"
      ],
      "implementation_contract": {
        "en": {
          "scope": "Cover every scannable routed zone, address family, cloud network and remote-access range at the required cadence; distinguish excluded, unreachable and deliberately non-scannable space.",
          "build": "Operate authenticated or unauthenticated discovery from enough vantage points to cross segmentation without bypassing safety constraints.",
          "proof": "Measure scheduled zones, successfully scanned zones, address space attempted, responsive objects normalized, and discoveries reconciled.",
          "boundary": "Discovery coverage is zones successfully completed divided by in-scope zones, not discovered assets divided by an existing inventory; the latter can exceed 100% and reward duplicates."
        },
        "zh": {
          "scope": "覆盖全部可安全扫描的路由网段、地址族、云网络和远程接入地址段，并明确排除、不可达和因安全原因不能主动扫描的区域。",
          "build": "从足够多的视角执行有凭据或无凭据发现，跨越分段但不绕过安全限制。",
          "proof": "统计计划网段、成功完成网段、尝试地址空间、归一对象和完成对账的发现。",
          "boundary": "覆盖率应为成功扫描的范围除以应扫范围，不能用“发现资产数/现有台账数”，后者会因重复而超过 100%。"
        }
      },
      "category_counts": {
        "outcome": 7,
        "scope": 7,
        "ownership": 7,
        "data": 7,
        "integration": 7,
        "control": 7,
        "timing": 7,
        "exception": 7,
        "evidence": 7,
        "security": 7,
        "testing": 7,
        "operations": 7
      },
      "requirement_count": 84,
      "requirements": [
        {
          "code": "CIS-1.3-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "1.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Utilize an Active Discovery Tool; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“主动发现”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-1.3-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "1.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 1.3, official Asset Class Devices, Security Function Detect, and IG2 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 1.3、官方资产类别“设备”、安全功能“检测”和首次出现的 IG2，并保存来源抓取日期。"
        },
        {
          "code": "CIS-1.3-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "1.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Cover every scannable routed zone, address family, cloud network and remote-access range at the required cadence; distinguish excluded, unreachable and deliberately non-scannable space.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“覆盖全部可安全扫描的路由网段、地址族、云网络和远程接入地址段，并明确排除、不可达和因安全原因不能主动扫描的区域。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-1.3-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "1.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-1.3-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "1.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Utilize an Active Discovery Tool to its operating object—physical, virtual, cloud, mobile, IoT/OT, lab, and regularly connected third-party enterprise assets—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“主动发现”连接到其运营对象——物理、虚拟、云、移动、IoT/OT、实验环境以及经常接入的第三方企业资产——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-1.3-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "1.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "For Utilize an Active Discovery Tool, express success as an observable decision over observed, approved, unapproved, ownerless, stale, duplicate, and retired object identity; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“主动发现”，以 已观测、已批准、未批准、无责任人、陈旧、重复和已退役对象身份 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-1.3-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "1.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "For Utilize an Active Discovery Tool, express success as an observable decision over coverage of every intended discovery vantage point, source, job, parser, and reconciliation path; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“主动发现”，以 所有预期发现视角、来源、任务、解析器和对账路径的覆盖 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-1.3-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "1.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-1.3-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "1.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-1.3-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "1.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-1.3-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "1.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-1.3-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "1.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across sleeping, ephemeral, disconnected, unmanaged, duplicated, shared-address, and safety-sensitive assets; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 休眠、短生、离线、未托管、重复、共享地址以及安全关键资产 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-1.3-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "1.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Include dormant, ephemeral, disconnected, externally managed, provider-held, aliased, cloned, and cross-tenant objects in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 休眠、短生、离线、外部托管、提供商持有、别名、克隆和跨租户对象 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-1.3-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "1.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Include unreachable zones, short-lived objects, blind spots, rate limits, credential failure, encrypted or proprietary protocols, and silent sensors in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 不可达区域、短生对象、盲区、限流、凭据失败、加密或专有协议和静默传感器 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-1.3-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "1.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-1.3-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "1.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-1.3-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "1.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-1.3-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "1.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-1.3-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "1.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind asset owners, platform and network operators, procurement, and security operations to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 资产责任人、平台与网络运营方、采购和安全运营 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-1.3-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "1.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Name who may transition discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-1.3-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "1.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Name who may transition scheduled → started → observed → normalized → reconciled → dispositioned, with explicit partial and failed states, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 计划 → 启动 → 观测 → 归一化 → 对账 → 处置，并显式保留部分与失败状态，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-1.3-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "1.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-1.3-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "1.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-1.3-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "1.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV1, GV3, M1, M2, M3, M4, M5, M6, M7) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV1, GV3, M1, M2, M3, M4, M5, M6, M7）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-1.3-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "1.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-1.3-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "1.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the reconciled enterprise asset authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把经过多源对账的企业资产权威台账作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-1.3-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "1.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence.",
          "zh": "对生命周期“发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-1.3-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "1.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle scheduled → started → observed → normalized → reconciled → dispositioned, with explicit partial and failed states.",
          "zh": "对生命周期“计划 → 启动 → 观测 → 归一化 → 对账 → 处置，并显式保留部分与失败状态”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-1.3-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "1.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 4.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 4.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-1.3-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "1.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-1.3-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "1.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-1.3-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "1.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-1.3-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "1.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile procurement, EDR/MDM, hypervisors, cloud inventories, DHCP/IPAM, network discovery, and disposal records and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 采购、EDR/MDM、虚拟化平台、云清单、DHCP/IPAM、网络发现与报废记录，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-1.3-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "1.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Require every connector carrying observed, approved, unapproved, ownerless, stale, duplicate, and retired object identity to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 已观测、已批准、未批准、无责任人、陈旧、重复和已退役对象身份 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-1.3-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "1.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Require every connector carrying coverage of every intended discovery vantage point, source, job, parser, and reconciliation path to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 所有预期发现视角、来源、任务、解析器和对账路径的覆盖 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-1.3-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "1.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Operate authenticated or unauthenticated discovery from enough vantage points to cross segmentation without bypassing safety constraints.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“从足够多的视角执行有凭据或无凭据发现，跨越分段但不绕过安全限制。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-1.3-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "1.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-1.3-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "1.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-1.3-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "1.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-1.3-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "1.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the reconciled enterprise asset authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在经过多源对账的企业资产权威台账中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-1.3-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "1.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Implement the explicit state machine discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-1.3-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "1.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Implement the explicit state machine scheduled → started → observed → normalized → reconciled → dispositioned, with explicit partial and failed states; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“计划 → 启动 → 观测 → 归一化 → 对账 → 处置，并显式保留部分与失败状态”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-1.3-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "1.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (daily); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（daily）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-1.3-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "1.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-1.3-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "1.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-1.3-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "1.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-1.3-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "1.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in physical, virtual, cloud, mobile, IoT/OT, lab, and regularly connected third-party enterprise assets; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 物理、虚拟、云、移动、IoT/OT、实验环境以及经常接入的第三方企业资产 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-1.3-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "1.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence; alert before each deadline becomes overdue.",
          "zh": "为“发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-1.3-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "1.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for scheduled → started → observed → normalized → reconciled → dispositioned, with explicit partial and failed states; alert before each deadline becomes overdue.",
          "zh": "为“计划 → 启动 → 观测 → 归一化 → 对账 → 处置，并显式保留部分与失败状态”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-1.3-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "1.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “Discovery coverage is zones successfully completed divided by in-scope zones, not discovered assets divided by an existing inventory; the latter can exceed 100% and reward duplicates.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“覆盖率应为成功扫描的范围除以应扫范围，不能用“发现资产数/现有台账数”，后者会因重复而超过 100%。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-1.3-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "1.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-1.3-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "1.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-1.3-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "1.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-1.3-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "1.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat sleeping, ephemeral, disconnected, unmanaged, duplicated, shared-address, and safety-sensitive assets as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 休眠、短生、离线、未托管、重复、共享地址以及安全关键资产 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-1.3-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "1.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Treat dormant, ephemeral, disconnected, externally managed, provider-held, aliased, cloned, and cross-tenant objects as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 休眠、短生、离线、外部托管、提供商持有、别名、克隆和跨租户对象 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-1.3-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "1.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Treat unreachable zones, short-lived objects, blind spots, rate limits, credential failure, encrypted or proprietary protocols, and silent sensors as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 不可达区域、短生对象、盲区、限流、凭据失败、加密或专有协议和静默传感器 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-1.3-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "1.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Measure scheduled zones, successfully scanned zones, address space attempted, responsive objects normalized, and discoveries reconciled.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“统计计划网段、成功完成网段、尝试地址空间、归一对象和完成对账的发现。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-1.3-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "1.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-1.3-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "1.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 2 pinned CAS metric branch(es), 9 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 2 个指标分支、9 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-1.3-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "1.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-1.3-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "1.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the reconciled enterprise asset authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以经过多源对账的企业资产权威台账和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-1.3-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "1.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Publish matched, missing, duplicate, stale, ownerless, unapproved, unevaluable, and retired-without-proof counts with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 匹配、缺失、重复、陈旧、无责任人、未批准、不可评估及无证明退役数量，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-1.3-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "1.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Publish scheduled, successful, partial, failed, stale, blind, newly discovered, unmatched, and reconciled observations with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 计划、成功、部分、失败、陈旧、盲区、新发现、未匹配和已对账观测，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-1.3-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "1.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-1.3-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "1.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-1.3-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "1.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-1.3-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "1.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-1.3-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "1.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the reconciled enterprise asset authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护经过多源对账的企业资产权威台账的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-1.3-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "1.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Restrict authority to change discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-1.3-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "1.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Restrict authority to change scheduled → started → observed → normalized → reconciled → dispositioned, with explicit partial and failed states; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“计划 → 启动 → 观测 → 归一化 → 对账 → 处置，并显式保留部分与失败状态”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-1.3-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "1.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-1.3-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "1.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-1.3-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "1.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-1.3-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "1.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-1.3-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "1.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise approved and unauthorized seeded assets, a disappearing asset, a duplicate identity, and a failed discovery source through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 已批准与未授权的植入资产、突然消失的资产、重复身份和失效的发现源，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-1.3-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "1.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Run the positive control a seeded approved object reconciled from two independent sources; exercise negative, stale, duplicate, bypass, and outage controls including an unknown object, duplicate identity, stale record, vanished object, failed source, and cross-tenant collision.",
          "zh": "运行正向控制“从两个独立来源对账的一项植入已批准对象”，并执行包含“未知对象、重复身份、陈旧记录、突然消失对象、失效来源和跨租户碰撞”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-1.3-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "1.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Run the positive control a known object visible from each representative vantage point; exercise negative, stale, duplicate, bypass, and outage controls including an unknown and short-lived object, failed credential, blocked scan, silent sensor, parser drift, and uncovered segment.",
          "zh": "运行正向控制“从每个代表性视角可见的一项已知对象”，并执行包含“未知与短生对象、凭据失败、扫描受阻、传感器静默、解析漂移和未覆盖网段”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-1.3-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "1.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-1.3-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "1.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-1.3-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "1.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-1.3-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "1.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-1.3-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "1.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever procurement, EDR/MDM, hypervisors, cloud inventories, DHCP/IPAM, network discovery, and disposal records change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 采购、EDR/MDM、虚拟化平台、云清单、DHCP/IPAM、网络发现与报废记录 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-1.3-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "1.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Use matched, missing, duplicate, stale, ownerless, unapproved, unevaluable, and retired-without-proof counts to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 匹配、缺失、重复、陈旧、无责任人、未批准、不可评估及无证明退役数量 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-1.3-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "1.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Use scheduled, successful, partial, failed, stale, blind, newly discovered, unmatched, and reconciled observations to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 计划、成功、部分、失败、陈旧、盲区、新发现、未匹配和已对账观测 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "1.4",
      "control": 1,
      "title_en": "Use Dynamic Host Configuration Protocol (DHCP) Logging to Update Enterprise Asset Inventory",
      "title_zh": "DHCP 与 IPAM 观测",
      "first_ig": 2,
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Devices",
      "security_function": "Identify",
      "patterns": [
        "inventory",
        "telemetry"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "1.1"
        ],
        "variables": [
          "GV41",
          "M1",
          "M2",
          "M3",
          "M4",
          "M5",
          "M6",
          "M7"
        ],
        "metric_branches": 3,
        "has_assumptions": true,
        "has_procedural_review": false
      },
      "official_cadence_terms": [
        "weekly"
      ],
      "implementation_contract": {
        "en": {
          "scope": "The scope is every enterprise-managed DHCP service and equivalent address allocator across campuses, wireless, VPN, IPv4/IPv6, cloud and virtual networks.",
          "build": "Send authoritative lease and allocation events to a protected collector, preserve server, tenant, MAC or client identifier, hostname, address, lease time and network context, and reconcile them into the asset register at least weekly.",
          "proof": "Generate a lease from a known test client, verify collection, parsing, asset matching and timely expiry; then use an unknown client to confirm it enters the unauthorized queue.",
          "boundary": "A positive count of correctly logging servers is success, despite the current CAS text interpreting one such measure as stale inventory."
        },
        "zh": {
          "scope": "范围是园区、无线、VPN、IPv4/IPv6、云和虚拟网络中全部企业管理的 DHCP 或等效地址分配器。",
          "build": "把权威租约与分配事件送到受保护收集端，保留服务器、租户、MAC 或客户端标识、主机名、地址、租期和网络上下文，至少每周回写资产台账。",
          "proof": "用已知测试客户端申请租约，验证采集、解析、资产匹配和按时过期；再用未知客户端确认其进入未授权队列。",
          "boundary": "CAS 当前文本把“正确输出日志的服务器数大于零”解释成台账陈旧，正负含义写反。"
        }
      },
      "category_counts": {
        "outcome": 7,
        "scope": 7,
        "ownership": 7,
        "data": 7,
        "integration": 7,
        "control": 7,
        "timing": 7,
        "exception": 7,
        "evidence": 7,
        "security": 7,
        "testing": 7,
        "operations": 7
      },
      "requirement_count": 84,
      "requirements": [
        {
          "code": "CIS-1.4-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "1.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Use Dynamic Host Configuration Protocol (DHCP) Logging to Update Enterprise Asset Inventory; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“DHCP 与 IPAM 观测”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-1.4-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "1.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 1.4, official Asset Class Devices, Security Function Identify, and IG2 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 1.4、官方资产类别“设备”、安全功能“识别”和首次出现的 IG2，并保存来源抓取日期。"
        },
        {
          "code": "CIS-1.4-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "1.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “The scope is every enterprise-managed DHCP service and equivalent address allocator across campuses, wireless, VPN, IPv4/IPv6, cloud and virtual networks.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“范围是园区、无线、VPN、IPv4/IPv6、云和虚拟网络中全部企业管理的 DHCP 或等效地址分配器。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-1.4-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "1.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-1.4-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "1.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Use Dynamic Host Configuration Protocol (DHCP) Logging to Update Enterprise Asset Inventory to its operating object—physical, virtual, cloud, mobile, IoT/OT, lab, and regularly connected third-party enterprise assets—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“DHCP 与 IPAM 观测”连接到其运营对象——物理、虚拟、云、移动、IoT/OT、实验环境以及经常接入的第三方企业资产——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-1.4-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "1.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "For Use Dynamic Host Configuration Protocol (DHCP) Logging to Update Enterprise Asset Inventory, express success as an observable decision over observed, approved, unapproved, ownerless, stale, duplicate, and retired object identity; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“DHCP 与 IPAM 观测”，以 已观测、已批准、未批准、无责任人、陈旧、重复和已退役对象身份 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-1.4-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "1.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "For Use Dynamic Host Configuration Protocol (DHCP) Logging to Update Enterprise Asset Inventory, express success as an observable decision over complete, attributable, timely, protected, searchable, and actionable security telemetry plus source health; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“DHCP 与 IPAM 观测”，以 完整、可归因、及时、受保护、可检索、可行动的安全遥测及来源健康 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-1.4-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "1.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-1.4-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "1.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-1.4-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "1.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-1.4-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "1.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-1.4-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "1.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across sleeping, ephemeral, disconnected, unmanaged, duplicated, shared-address, and safety-sensitive assets; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 休眠、短生、离线、未托管、重复、共享地址以及安全关键资产 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-1.4-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "1.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Include dormant, ephemeral, disconnected, externally managed, provider-held, aliased, cloned, and cross-tenant objects in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 休眠、短生、离线、外部托管、提供商持有、别名、克隆和跨租户对象 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-1.4-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "1.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Include clock skew, actor loss, field truncation, parser drift, dropped or duplicate events, privacy redaction, provider gaps, encrypted paths, quota, and archive failure in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 时钟偏移、行为者丢失、字段截断、解析漂移、事件丢失或重复、隐私脱敏、提供商缺口、加密路径、配额和归档故障 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-1.4-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "1.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-1.4-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "1.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-1.4-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "1.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-1.4-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "1.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-1.4-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "1.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind asset owners, platform and network operators, procurement, and security operations to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 资产责任人、平台与网络运营方、采购和安全运营 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-1.4-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "1.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Name who may transition discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-1.4-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "1.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Name who may transition event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-1.4-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "1.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-1.4-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "1.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-1.4-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "1.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV41, M1, M2, M3, M4, M5, M6, M7) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV41, M1, M2, M3, M4, M5, M6, M7）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-1.4-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "1.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-1.4-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "1.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the reconciled enterprise asset authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把经过多源对账的企业资产权威台账作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-1.4-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "1.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence.",
          "zh": "对生命周期“发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-1.4-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "1.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired.",
          "zh": "对生命周期“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-1.4-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "1.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 1.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 1.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-1.4-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "1.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-1.4-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "1.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-1.4-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "1.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-1.4-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "1.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile procurement, EDR/MDM, hypervisors, cloud inventories, DHCP/IPAM, network discovery, and disposal records and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 采购、EDR/MDM、虚拟化平台、云清单、DHCP/IPAM、网络发现与报废记录，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-1.4-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "1.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Require every connector carrying observed, approved, unapproved, ownerless, stale, duplicate, and retired object identity to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 已观测、已批准、未批准、无责任人、陈旧、重复和已退役对象身份 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-1.4-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "1.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Require every connector carrying complete, attributable, timely, protected, searchable, and actionable security telemetry plus source health to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 完整、可归因、及时、受保护、可检索、可行动的安全遥测及来源健康 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-1.4-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "1.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Send authoritative lease and allocation events to a protected collector, preserve server, tenant, MAC or client identifier, hostname, address, lease time and network context, and reconcile them into the asset register at least weekly.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“把权威租约与分配事件送到受保护收集端，保留服务器、租户、MAC 或客户端标识、主机名、地址、租期和网络上下文，至少每周回写资产台账。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-1.4-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "1.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-1.4-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "1.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-1.4-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "1.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-1.4-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "1.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the reconciled enterprise asset authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在经过多源对账的企业资产权威台账中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-1.4-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "1.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Implement the explicit state machine discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-1.4-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "1.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Implement the explicit state machine event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-1.4-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "1.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (weekly); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（weekly）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-1.4-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "1.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-1.4-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "1.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-1.4-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "1.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-1.4-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "1.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in physical, virtual, cloud, mobile, IoT/OT, lab, and regularly connected third-party enterprise assets; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 物理、虚拟、云、移动、IoT/OT、实验环境以及经常接入的第三方企业资产 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-1.4-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "1.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence; alert before each deadline becomes overdue.",
          "zh": "为“发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-1.4-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "1.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired; alert before each deadline becomes overdue.",
          "zh": "为“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-1.4-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "1.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “A positive count of correctly logging servers is success, despite the current CAS text interpreting one such measure as stale inventory.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“CAS 当前文本把“正确输出日志的服务器数大于零”解释成台账陈旧，正负含义写反。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-1.4-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "1.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-1.4-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "1.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-1.4-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "1.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-1.4-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "1.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat sleeping, ephemeral, disconnected, unmanaged, duplicated, shared-address, and safety-sensitive assets as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 休眠、短生、离线、未托管、重复、共享地址以及安全关键资产 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-1.4-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "1.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Treat dormant, ephemeral, disconnected, externally managed, provider-held, aliased, cloned, and cross-tenant objects as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 休眠、短生、离线、外部托管、提供商持有、别名、克隆和跨租户对象 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-1.4-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "1.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Treat clock skew, actor loss, field truncation, parser drift, dropped or duplicate events, privacy redaction, provider gaps, encrypted paths, quota, and archive failure as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 时钟偏移、行为者丢失、字段截断、解析漂移、事件丢失或重复、隐私脱敏、提供商缺口、加密路径、配额和归档故障 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-1.4-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "1.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Generate a lease from a known test client, verify collection, parsing, asset matching and timely expiry; then use an unknown client to confirm it enters the unauthorized queue.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“用已知测试客户端申请租约，验证采集、解析、资产匹配和按时过期；再用未知客户端确认其进入未授权队列。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-1.4-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "1.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-1.4-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "1.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 3 pinned CAS metric branch(es), 8 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 3 个指标分支、8 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-1.4-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "1.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-1.4-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "1.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the reconciled enterprise asset authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以经过多源对账的企业资产权威台账和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-1.4-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "1.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Publish matched, missing, duplicate, stale, ownerless, unapproved, unevaluable, and retired-without-proof counts with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 匹配、缺失、重复、陈旧、无责任人、未批准、不可评估及无证明退役数量，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-1.4-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "1.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Publish healthy, silent, partial, late, malformed, duplicate, unowned, unreviewed, alerted, investigated, and archived sources or events with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 健康、静默、部分、迟到、畸形、重复、无责任人、未审阅、已告警、已调查和已归档来源或事件，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-1.4-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "1.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-1.4-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "1.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-1.4-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "1.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-1.4-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "1.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-1.4-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "1.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the reconciled enterprise asset authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护经过多源对账的企业资产权威台账的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-1.4-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "1.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Restrict authority to change discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-1.4-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "1.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Restrict authority to change event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-1.4-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "1.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-1.4-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "1.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-1.4-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "1.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-1.4-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "1.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-1.4-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "1.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise approved and unauthorized seeded assets, a disappearing asset, a duplicate identity, and a failed discovery source through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 已批准与未授权的植入资产、突然消失的资产、重复身份和失效的发现源，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-1.4-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "1.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Run the positive control a seeded approved object reconciled from two independent sources; exercise negative, stale, duplicate, bypass, and outage controls including an unknown object, duplicate identity, stale record, vanished object, failed source, and cross-tenant collision.",
          "zh": "运行正向控制“从两个独立来源对账的一项植入已批准对象”，并执行包含“未知对象、重复身份、陈旧记录、突然消失对象、失效来源和跨租户碰撞”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-1.4-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "1.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Run the positive control an allowed and denied canary event traced from source through review; exercise negative, stale, duplicate, bypass, and outage controls including source loss, parser/schema change, time skew, queue overflow, duplicate delivery, provider export outage, missed alert, and unreadable archive.",
          "zh": "运行正向控制“一项允许与拒绝金丝雀事件从来源贯穿到审阅”，并执行包含“来源丢失、解析器/模式变化、时钟偏移、队列溢出、重复投递、提供商导出中断、漏报和归档不可读”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-1.4-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "1.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-1.4-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "1.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-1.4-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "1.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-1.4-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "1.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-1.4-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "1.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever procurement, EDR/MDM, hypervisors, cloud inventories, DHCP/IPAM, network discovery, and disposal records change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 采购、EDR/MDM、虚拟化平台、云清单、DHCP/IPAM、网络发现与报废记录 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-1.4-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "1.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Use matched, missing, duplicate, stale, ownerless, unapproved, unevaluable, and retired-without-proof counts to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 匹配、缺失、重复、陈旧、无责任人、未批准、不可评估及无证明退役数量 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-1.4-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "1.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Use healthy, silent, partial, late, malformed, duplicate, unowned, unreviewed, alerted, investigated, and archived sources or events to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 健康、静默、部分、迟到、畸形、重复、无责任人、未审阅、已告警、已调查和已归档来源或事件 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "1.5",
      "control": 1,
      "title_en": "Use a Passive Asset Discovery Tool",
      "title_zh": "被动发现",
      "first_ig": 3,
      "implementation_groups": [
        3
      ],
      "asset_class": "Devices",
      "security_function": "Detect",
      "patterns": [
        "inventory",
        "discovery"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "4.2",
          "12.4"
        ],
        "variables": [
          "GV3",
          "GV4",
          "M1",
          "M2",
          "M3",
          "M4",
          "M5"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [
        "weekly",
        "at least weekly"
      ],
      "implementation_contract": {
        "en": {
          "scope": "Include network segments where passive telemetry can lawfully and technically observe asset presence, particularly unmanaged, fragile, IoT and OT populations.",
          "build": "Place passive sensors or consume switch, flow, wireless-controller and cloud-flow telemetry at documented choke points.",
          "proof": "Replay a benign test protocol and attach an unregistered device on each representative segment.",
          "boundary": "A sensor that is online but sees no expected heartbeat has failed."
        },
        "zh": {
          "scope": "覆盖适合且允许被动观测资产存在的网段，尤其是非受管、脆弱、IoT 和 OT。",
          "build": "在已记录的关键点放置被动探针，或消费交换机、流日志、无线控制器与云流量遥测；持续监控传感器健康、TAP/SPAN 丢包、时钟、解析器版本和网段映射。",
          "proof": "在各类代表网段回放无害协议并接入未登记设备，验证包或流到达、识别、台账关联和告警时延。",
          "boundary": "探针在线却看不到应有心跳也算失败。"
        }
      },
      "category_counts": {
        "outcome": 7,
        "scope": 7,
        "ownership": 7,
        "data": 7,
        "integration": 7,
        "control": 7,
        "timing": 7,
        "exception": 7,
        "evidence": 7,
        "security": 7,
        "testing": 7,
        "operations": 7
      },
      "requirement_count": 84,
      "requirements": [
        {
          "code": "CIS-1.5-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "1.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Use a Passive Asset Discovery Tool; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“被动发现”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-1.5-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "1.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 1.5, official Asset Class Devices, Security Function Detect, and IG3 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 1.5、官方资产类别“设备”、安全功能“检测”和首次出现的 IG3，并保存来源抓取日期。"
        },
        {
          "code": "CIS-1.5-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "1.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Include network segments where passive telemetry can lawfully and technically observe asset presence, particularly unmanaged, fragile, IoT and OT populations.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“覆盖适合且允许被动观测资产存在的网段，尤其是非受管、脆弱、IoT 和 OT。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-1.5-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "1.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-1.5-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "1.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Use a Passive Asset Discovery Tool to its operating object—physical, virtual, cloud, mobile, IoT/OT, lab, and regularly connected third-party enterprise assets—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“被动发现”连接到其运营对象——物理、虚拟、云、移动、IoT/OT、实验环境以及经常接入的第三方企业资产——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-1.5-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "1.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "For Use a Passive Asset Discovery Tool, express success as an observable decision over observed, approved, unapproved, ownerless, stale, duplicate, and retired object identity; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“被动发现”，以 已观测、已批准、未批准、无责任人、陈旧、重复和已退役对象身份 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-1.5-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "1.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "For Use a Passive Asset Discovery Tool, express success as an observable decision over coverage of every intended discovery vantage point, source, job, parser, and reconciliation path; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“被动发现”，以 所有预期发现视角、来源、任务、解析器和对账路径的覆盖 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-1.5-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "1.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-1.5-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "1.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-1.5-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "1.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-1.5-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "1.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-1.5-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "1.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across sleeping, ephemeral, disconnected, unmanaged, duplicated, shared-address, and safety-sensitive assets; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 休眠、短生、离线、未托管、重复、共享地址以及安全关键资产 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-1.5-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "1.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Include dormant, ephemeral, disconnected, externally managed, provider-held, aliased, cloned, and cross-tenant objects in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 休眠、短生、离线、外部托管、提供商持有、别名、克隆和跨租户对象 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-1.5-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "1.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Include unreachable zones, short-lived objects, blind spots, rate limits, credential failure, encrypted or proprietary protocols, and silent sensors in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 不可达区域、短生对象、盲区、限流、凭据失败、加密或专有协议和静默传感器 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-1.5-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "1.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-1.5-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "1.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-1.5-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "1.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-1.5-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "1.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-1.5-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "1.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind asset owners, platform and network operators, procurement, and security operations to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 资产责任人、平台与网络运营方、采购和安全运营 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-1.5-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "1.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Name who may transition discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-1.5-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "1.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Name who may transition scheduled → started → observed → normalized → reconciled → dispositioned, with explicit partial and failed states, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 计划 → 启动 → 观测 → 归一化 → 对账 → 处置，并显式保留部分与失败状态，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-1.5-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "1.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-1.5-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "1.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-1.5-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "1.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV3, GV4, M1, M2, M3, M4, M5) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV3, GV4, M1, M2, M3, M4, M5）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-1.5-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "1.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-1.5-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "1.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the reconciled enterprise asset authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把经过多源对账的企业资产权威台账作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-1.5-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "1.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence.",
          "zh": "对生命周期“发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-1.5-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "1.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle scheduled → started → observed → normalized → reconciled → dispositioned, with explicit partial and failed states.",
          "zh": "对生命周期“计划 → 启动 → 观测 → 归一化 → 对账 → 处置，并显式保留部分与失败状态”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-1.5-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "1.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 4.2, Safeguard 12.4; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 4.2、Safeguard 12.4 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-1.5-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "1.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-1.5-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "1.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-1.5-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "1.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-1.5-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "1.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile procurement, EDR/MDM, hypervisors, cloud inventories, DHCP/IPAM, network discovery, and disposal records and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 采购、EDR/MDM、虚拟化平台、云清单、DHCP/IPAM、网络发现与报废记录，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-1.5-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "1.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Require every connector carrying observed, approved, unapproved, ownerless, stale, duplicate, and retired object identity to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 已观测、已批准、未批准、无责任人、陈旧、重复和已退役对象身份 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-1.5-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "1.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Require every connector carrying coverage of every intended discovery vantage point, source, job, parser, and reconciliation path to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 所有预期发现视角、来源、任务、解析器和对账路径的覆盖 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-1.5-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "1.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Place passive sensors or consume switch, flow, wireless-controller and cloud-flow telemetry at documented choke points.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“在已记录的关键点放置被动探针，或消费交换机、流日志、无线控制器与云流量遥测；持续监控传感器健康、TAP/SPAN 丢包、时钟、解析器版本和网段映射。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-1.5-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "1.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-1.5-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "1.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-1.5-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "1.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-1.5-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "1.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the reconciled enterprise asset authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在经过多源对账的企业资产权威台账中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-1.5-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "1.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Implement the explicit state machine discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-1.5-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "1.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Implement the explicit state machine scheduled → started → observed → normalized → reconciled → dispositioned, with explicit partial and failed states; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“计划 → 启动 → 观测 → 归一化 → 对账 → 处置，并显式保留部分与失败状态”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-1.5-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "1.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (weekly, at least weekly); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（weekly, at least weekly）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-1.5-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "1.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-1.5-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "1.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-1.5-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "1.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-1.5-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "1.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in physical, virtual, cloud, mobile, IoT/OT, lab, and regularly connected third-party enterprise assets; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 物理、虚拟、云、移动、IoT/OT、实验环境以及经常接入的第三方企业资产 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-1.5-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "1.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence; alert before each deadline becomes overdue.",
          "zh": "为“发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-1.5-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "1.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for scheduled → started → observed → normalized → reconciled → dispositioned, with explicit partial and failed states; alert before each deadline becomes overdue.",
          "zh": "为“计划 → 启动 → 观测 → 归一化 → 对账 → 处置，并显式保留部分与失败状态”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-1.5-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "1.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “A sensor that is online but sees no expected heartbeat has failed.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“探针在线却看不到应有心跳也算失败。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-1.5-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "1.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-1.5-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "1.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-1.5-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "1.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-1.5-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "1.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat sleeping, ephemeral, disconnected, unmanaged, duplicated, shared-address, and safety-sensitive assets as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 休眠、短生、离线、未托管、重复、共享地址以及安全关键资产 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-1.5-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "1.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Treat dormant, ephemeral, disconnected, externally managed, provider-held, aliased, cloned, and cross-tenant objects as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 休眠、短生、离线、外部托管、提供商持有、别名、克隆和跨租户对象 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-1.5-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "1.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Treat unreachable zones, short-lived objects, blind spots, rate limits, credential failure, encrypted or proprietary protocols, and silent sensors as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 不可达区域、短生对象、盲区、限流、凭据失败、加密或专有协议和静默传感器 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-1.5-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "1.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Replay a benign test protocol and attach an unregistered device on each representative segment.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“在各类代表网段回放无害协议并接入未登记设备，验证包或流到达、识别、台账关联和告警时延。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-1.5-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "1.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-1.5-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "1.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 7 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、7 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-1.5-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "1.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-1.5-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "1.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the reconciled enterprise asset authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以经过多源对账的企业资产权威台账和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-1.5-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "1.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Publish matched, missing, duplicate, stale, ownerless, unapproved, unevaluable, and retired-without-proof counts with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 匹配、缺失、重复、陈旧、无责任人、未批准、不可评估及无证明退役数量，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-1.5-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "1.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Publish scheduled, successful, partial, failed, stale, blind, newly discovered, unmatched, and reconciled observations with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 计划、成功、部分、失败、陈旧、盲区、新发现、未匹配和已对账观测，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-1.5-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "1.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-1.5-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "1.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-1.5-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "1.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-1.5-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "1.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-1.5-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "1.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the reconciled enterprise asset authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护经过多源对账的企业资产权威台账的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-1.5-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "1.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Restrict authority to change discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-1.5-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "1.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Restrict authority to change scheduled → started → observed → normalized → reconciled → dispositioned, with explicit partial and failed states; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“计划 → 启动 → 观测 → 归一化 → 对账 → 处置，并显式保留部分与失败状态”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-1.5-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "1.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-1.5-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "1.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-1.5-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "1.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-1.5-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "1.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-1.5-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "1.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise approved and unauthorized seeded assets, a disappearing asset, a duplicate identity, and a failed discovery source through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 已批准与未授权的植入资产、突然消失的资产、重复身份和失效的发现源，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-1.5-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "1.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Run the positive control a seeded approved object reconciled from two independent sources; exercise negative, stale, duplicate, bypass, and outage controls including an unknown object, duplicate identity, stale record, vanished object, failed source, and cross-tenant collision.",
          "zh": "运行正向控制“从两个独立来源对账的一项植入已批准对象”，并执行包含“未知对象、重复身份、陈旧记录、突然消失对象、失效来源和跨租户碰撞”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-1.5-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "1.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Run the positive control a known object visible from each representative vantage point; exercise negative, stale, duplicate, bypass, and outage controls including an unknown and short-lived object, failed credential, blocked scan, silent sensor, parser drift, and uncovered segment.",
          "zh": "运行正向控制“从每个代表性视角可见的一项已知对象”，并执行包含“未知与短生对象、凭据失败、扫描受阻、传感器静默、解析漂移和未覆盖网段”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-1.5-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "1.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-1.5-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "1.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-1.5-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "1.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-1.5-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "1.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-1.5-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "1.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever procurement, EDR/MDM, hypervisors, cloud inventories, DHCP/IPAM, network discovery, and disposal records change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 采购、EDR/MDM、虚拟化平台、云清单、DHCP/IPAM、网络发现与报废记录 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-1.5-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "1.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Use matched, missing, duplicate, stale, ownerless, unapproved, unevaluable, and retired-without-proof counts to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 匹配、缺失、重复、陈旧、无责任人、未批准、不可评估及无证明退役数量 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-1.5-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "1.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Use scheduled, successful, partial, failed, stale, blind, newly discovered, unmatched, and reconciled observations to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 计划、成功、部分、失败、陈旧、盲区、新发现、未匹配和已对账观测 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "2.1",
      "control": 2,
      "title_en": "Establish and Maintain a Software Inventory",
      "title_zh": "软件总账",
      "first_ig": 1,
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Software",
      "security_function": "Identify",
      "patterns": [
        "software_dev",
        "inventory"
      ],
      "expanded_complexity": true,
      "cas_context": {
        "dependencies": [],
        "variables": [
          "GV5",
          "GV6",
          "M1",
          "M2",
          "M3",
          "M4"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [
        "bi-annually",
        "annually"
      ],
      "implementation_contract": {
        "en": {
          "scope": "The population includes operating systems, installed packages, browser and office extensions, mobile apps, firmware where managed as software, container images, language dependencies, SaaS applications, cloud marketplace images and internally built releases.",
          "build": "Reconcile endpoint and server inventory, package managers, MDM, container registries, SBOMs, CI/CD catalogs, cloud and SaaS administration into one software authority linked to assets and business owners.",
          "proof": "Select samples from endpoints, clusters, repositories, cloud accounts and expense/SSO catalogs and trace both directions.",
          "boundary": "Agent-only inventories miss portable binaries, build-time dependencies, dormant images, SaaS purchased outside SSO and firmware."
        },
        "zh": {
          "scope": "软件总体包括操作系统、安装包、浏览器与办公扩展、移动应用、按软件管理的固件、容器镜像、语言依赖、SaaS、云市场镜像和自研发布物。",
          "build": "把终端/服务器采集、包管理器、MDM、镜像仓库、SBOM、CI/CD、云与 SaaS 管理面统一到软件权威台账，并关联资产和业务责任人。",
          "proof": "从终端、集群、仓库、云账号和费用/SSO 目录双向抽样。",
          "boundary": "只靠 Agent 会漏掉便携程序、构建依赖、休眠镜像、未接 SSO 的影子 SaaS 和固件。"
        }
      },
      "category_counts": {
        "outcome": 8,
        "scope": 8,
        "ownership": 8,
        "data": 8,
        "integration": 8,
        "control": 8,
        "timing": 8,
        "exception": 8,
        "evidence": 8,
        "security": 8,
        "testing": 8,
        "operations": 8
      },
      "requirement_count": 96,
      "requirements": [
        {
          "code": "CIS-2.1-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "2.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Establish and Maintain a Software Inventory; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“软件总账”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-2.1-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "2.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 2.1, official Asset Class Software, Security Function Identify, and IG1 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 2.1、官方资产类别“软件”、安全功能“识别”和首次出现的 IG1，并保存来源抓取日期。"
        },
        {
          "code": "CIS-2.1-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "2.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “The population includes operating systems, installed packages, browser and office extensions, mobile apps, firmware where managed as software, container images, language dependencies, SaaS applications, cloud marketplace images and internally built releases.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“软件总体包括操作系统、安装包、浏览器与办公扩展、移动应用、按软件管理的固件、容器镜像、语言依赖、SaaS、云市场镜像和自研发布物。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-2.1-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "2.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-2.1-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "2.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Establish and Maintain a Software Inventory to its operating object—operating systems, packages, firmware, extensions, container images, dependencies, SaaS applications, and internally built releases—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“软件总账”连接到其运营对象——操作系统、软件包、固件、扩展、容器镜像、依赖、SaaS 应用和内部构建发布物——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-2.1-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "2.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "For Establish and Maintain a Software Inventory, express success as an observable decision over source-to-production software identity, design invariant, component trust, build provenance, test result, deployment state, runtime outcome, and vulnerability response; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“软件总账”，以 从源码到生产的软件身份、设计不变量、组件信任、构建来源、测试结果、部署状态、运行结果和漏洞响应 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-2.1-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "2.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "For Establish and Maintain a Software Inventory, express success as an observable decision over observed, approved, unapproved, ownerless, stale, duplicate, and retired object identity; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“软件总账”，以 已观测、已批准、未批准、无责任人、陈旧、重复和已退役对象身份 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-2.1-OUT-08",
          "local_code": "OUT-08",
          "display_code": "O08",
          "safeguard_id": "2.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "For the expanded Establish and Maintain a Software Inventory scope, resolve conflicts among security, safety, privacy, legal, availability, customer, and operational objectives through an explicit risk decision.",
          "zh": "对“软件总账”的扩展范围，通过显式风险决策解决安全、安全生产、隐私、法律、可用性、客户和运营目标冲突。"
        },
        {
          "code": "CIS-2.1-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "2.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-2.1-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "2.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-2.1-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "2.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-2.1-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "2.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-2.1-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "2.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across portable binaries, dormant images, static linking, shadow SaaS, mutable packages, unsupported editions, and environment-specific authorization; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 便携二进制、休眠镜像、静态链接、影子 SaaS、可变软件包、不受支持版本及环境相关授权 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-2.1-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "2.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Include generated and copied code, forks, vendoring, transitive dependencies, mutable tags, build plugins, feature flags, tenant logic, secrets, emergency release, and provider components in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 生成与复制代码、分叉、vendoring、传递依赖、可变标签、构建插件、功能开关、租户逻辑、秘密、紧急发布和提供商组件 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-2.1-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "2.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Include dormant, ephemeral, disconnected, externally managed, provider-held, aliased, cloned, and cross-tenant objects in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 休眠、短生、离线、外部托管、提供商持有、别名、克隆和跨租户对象 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-2.1-SCP-08",
          "local_code": "SCP-08",
          "display_code": "P08",
          "safeguard_id": "2.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Define nested scope at enterprise, business service, tenant, environment, platform, object, identity, data set, and transaction levels; prohibit a parent result from hiding a failing child.",
          "zh": "按企业、业务服务、租户、环境、平台、对象、身份、数据集和交易定义嵌套范围，禁止父级结果遮蔽失败子级。"
        },
        {
          "code": "CIS-2.1-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "2.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-2.1-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "2.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-2.1-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "2.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-2.1-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "2.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-2.1-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "2.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind software and application owners, platform engineering, developers, procurement, and security to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 软件与应用责任人、平台工程、开发、采购和安全团队 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-2.1-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "2.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Name who may transition designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-2.1-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "2.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Name who may transition discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-2.1-OWN-08",
          "local_code": "OWN-08",
          "display_code": "W08",
          "safeguard_id": "2.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Model delegated authority, quorum or dual approval where warranted, escalation deadlines, provider handoffs, conflict resolution, and executive risk acceptance.",
          "zh": "建模委派权限、必要时的双人或法定人数审批、升级期限、提供商交接、冲突解决和管理层风险接受。"
        },
        {
          "code": "CIS-2.1-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "2.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-2.1-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "2.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-2.1-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "2.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV5, GV6, M1, M2, M3, M4) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV5, GV6, M1, M2, M3, M4）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-2.1-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "2.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-2.1-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "2.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the reconciled software and deployment authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把经过部署对账的软件权威台账作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-2.1-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "2.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired.",
          "zh": "对生命周期“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-2.1-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "2.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence.",
          "zh": "对生命周期“发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-2.1-DAT-08",
          "local_code": "DAT-08",
          "display_code": "D08",
          "safeguard_id": "2.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Version schemas and state transitions with migration, backfill, deduplication, lineage, historical denominator, deletion, and rollback semantics.",
          "zh": "对模式和状态转换做版本管理，定义迁移、回填、去重、血缘、历史分母、删除和回滚语义。"
        },
        {
          "code": "CIS-2.1-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "2.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for no explicit predecessor in the pinned CAS page; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 固定 CAS 页面没有列出显式前置项 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-2.1-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "2.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-2.1-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "2.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-2.1-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "2.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-2.1-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "2.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile endpoint/package inventories, MDM, registries, SBOMs, CI/CD, cloud catalogs, SSO, procurement, and publisher lifecycle sources and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 终端与包清单、MDM、制品库、SBOM、CI/CD、云目录、SSO、采购和发布方生命周期来源，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-2.1-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "2.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Require every connector carrying source-to-production software identity, design invariant, component trust, build provenance, test result, deployment state, runtime outcome, and vulnerability response to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 从源码到生产的软件身份、设计不变量、组件信任、构建来源、测试结果、部署状态、运行结果和漏洞响应 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-2.1-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "2.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Require every connector carrying observed, approved, unapproved, ownerless, stale, duplicate, and retired object identity to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 已观测、已批准、未批准、无责任人、陈旧、重复和已退役对象身份 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-2.1-INT-08",
          "local_code": "INT-08",
          "display_code": "I08",
          "safeguard_id": "2.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Define consistency rules across disagreeing sources, source precedence, confidence, reconciliation queues, dead-letter handling, reprocessing, and end-to-end trace identity.",
          "zh": "定义冲突来源的一致性、优先级、置信度、对账队列、死信、重处理和端到端追踪身份。"
        },
        {
          "code": "CIS-2.1-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "2.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Reconcile endpoint and server inventory, package managers, MDM, container registries, SBOMs, CI/CD catalogs, cloud and SaaS administration into one software authority linked to assets and business owners.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“把终端/服务器采集、包管理器、MDM、镜像仓库、SBOM、CI/CD、云与 SaaS 管理面统一到软件权威台账，并关联资产和业务责任人。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-2.1-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "2.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-2.1-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "2.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-2.1-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "2.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-2.1-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "2.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the reconciled software and deployment authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在经过部署对账的软件权威台账中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-2.1-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "2.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Implement the explicit state machine designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-2.1-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "2.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Implement the explicit state machine discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-2.1-CTL-08",
          "local_code": "CTL-08",
          "display_code": "C08",
          "safeguard_id": "2.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Specify concurrent decisions, partial success, compensating transactions, repeated requests, stale policy, dependency outage, and recovery from an interrupted state transition.",
          "zh": "定义并发决策、部分成功、补偿事务、重复请求、陈旧策略、依赖中断和中途状态转换恢复。"
        },
        {
          "code": "CIS-2.1-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "2.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (bi-annually, annually); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（bi-annually, annually）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-2.1-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "2.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-2.1-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "2.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-2.1-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "2.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-2.1-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "2.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in operating systems, packages, firmware, extensions, container images, dependencies, SaaS applications, and internally built releases; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 操作系统、软件包、固件、扩展、容器镜像、依赖、SaaS 应用和内部构建发布物 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-2.1-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "2.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; alert before each deadline becomes overdue.",
          "zh": "为“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-2.1-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "2.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence; alert before each deadline becomes overdue.",
          "zh": "为“发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-2.1-TIM-08",
          "local_code": "TIM-08",
          "display_code": "T08",
          "safeguard_id": "2.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Allocate an end-to-end SLO budget across discovery, collection, processing, approval, enforcement, verification, and closure; prioritize overdue work by consequence and exposure.",
          "zh": "把端到端 SLO 预算分配到发现、采集、处理、审批、执行、验证和关闭，并按后果与暴露排列逾期工作。"
        },
        {
          "code": "CIS-2.1-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "2.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “Agent-only inventories miss portable binaries, build-time dependencies, dormant images, SaaS purchased outside SSO and firmware.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“只靠 Agent 会漏掉便携程序、构建依赖、休眠镜像、未接 SSO 的影子 SaaS 和固件。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-2.1-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "2.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-2.1-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "2.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-2.1-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "2.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-2.1-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "2.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat portable binaries, dormant images, static linking, shadow SaaS, mutable packages, unsupported editions, and environment-specific authorization as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 便携二进制、休眠镜像、静态链接、影子 SaaS、可变软件包、不受支持版本及环境相关授权 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-2.1-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "2.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Treat generated and copied code, forks, vendoring, transitive dependencies, mutable tags, build plugins, feature flags, tenant logic, secrets, emergency release, and provider components as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 生成与复制代码、分叉、vendoring、传递依赖、可变标签、构建插件、功能开关、租户逻辑、秘密、紧急发布和提供商组件 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-2.1-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "2.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Treat dormant, ephemeral, disconnected, externally managed, provider-held, aliased, cloned, and cross-tenant objects as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 休眠、短生、离线、外部托管、提供商持有、别名、克隆和跨租户对象 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-2.1-EXC-08",
          "local_code": "EXC-08",
          "display_code": "X08",
          "safeguard_id": "2.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Exercise compound failures where an exception, stale source, provider outage, unavailable owner, and degraded control overlap; define one safe command and one accountable decision.",
          "zh": "演练例外、陈旧来源、提供商中断、责任人不可用和控制降级同时出现的复合故障，明确一条安全指令和一个责任决策。"
        },
        {
          "code": "CIS-2.1-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "2.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Select samples from endpoints, clusters, repositories, cloud accounts and expense/SSO catalogs and trace both directions.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“从终端、集群、仓库、云账号和费用/SSO 目录双向抽样。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-2.1-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "2.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-2.1-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "2.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 6 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、6 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-2.1-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "2.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-2.1-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "2.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the reconciled software and deployment authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以经过部署对账的软件权威台账和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-2.1-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "2.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Publish reviewed, unreviewed, reproducible, provenance-bound, vulnerable, test-failed, exception, deployed-unverified, drifted, rolled-back, and regression-protected releases with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已评审、未评审、可复现、来源绑定、存在漏洞、测试失败、例外、已部署未验证、漂移、已回滚和受回归保护发布物，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-2.1-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "2.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Publish matched, missing, duplicate, stale, ownerless, unapproved, unevaluable, and retired-without-proof counts with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 匹配、缺失、重复、陈旧、无责任人、未批准、不可评估及无证明退役数量，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-2.1-EVD-08",
          "local_code": "EVD-08",
          "display_code": "E08",
          "safeguard_id": "2.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Require an independent party to reconstruct the decision from source receipts and reproduce the population, state transition, calculation, test result, exception, and final closure.",
          "zh": "要求独立人员使用来源回执重建决策，并复现总体、状态转换、计算、测试结果、例外和最终关闭。"
        },
        {
          "code": "CIS-2.1-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "2.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-2.1-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "2.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-2.1-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "2.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-2.1-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "2.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-2.1-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "2.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the reconciled software and deployment authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护经过部署对账的软件权威台账的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-2.1-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "2.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Restrict authority to change designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-2.1-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "2.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Restrict authority to change discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-2.1-SEC-08",
          "local_code": "SEC-08",
          "display_code": "S08",
          "safeguard_id": "2.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Threat-model the implementation system itself: forged evidence, poisoned inventory, privilege abuse, cross-tenant confusion, policy rollback, audit deletion, denial of service, and recovery compromise.",
          "zh": "威胁建模实施系统自身：伪造证据、污染清单、权限滥用、跨租户混淆、策略回滚、审计删除、拒绝服务和恢复失陷。"
        },
        {
          "code": "CIS-2.1-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "2.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-2.1-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "2.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-2.1-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "2.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-2.1-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "2.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-2.1-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "2.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise an approved release, an unapproved binary, an unexpected dependency, a short-lived image, and a publisher end-of-support event through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 获批发布物、未批准二进制、意外依赖、短生镜像和发布方终止支持事件，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-2.1-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "2.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Run the positive control a trusted build that preserves the security invariant through deployment and runtime; exercise negative, stale, duplicate, bypass, and outage controls including a substituted dependency, unreviewed change, poisoned build input, failed security test, bypass path, vulnerable release, rollback, and regression.",
          "zh": "运行正向控制“一个把安全不变量贯穿部署与运行的可信构建”，并执行包含“依赖替换、未评审变更、构建输入污染、安全测试失败、绕过路径、漏洞发布、回滚和回归”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-2.1-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "2.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Run the positive control a seeded approved object reconciled from two independent sources; exercise negative, stale, duplicate, bypass, and outage controls including an unknown object, duplicate identity, stale record, vanished object, failed source, and cross-tenant collision.",
          "zh": "运行正向控制“从两个独立来源对账的一项植入已批准对象”，并执行包含“未知对象、重复身份、陈旧记录、突然消失对象、失效来源和跨租户碰撞”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-2.1-TST-08",
          "local_code": "TST-08",
          "display_code": "V08",
          "safeguard_id": "2.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Build a pairwise platform-and-failure matrix, then add high-consequence multi-factor cases, historical regression, source substitution, red-team challenge, and assessor replay.",
          "zh": "建立平台—故障两两组合矩阵，再加入高后果多因素案例、历史回归、来源替换、红队挑战和评估方重放。"
        },
        {
          "code": "CIS-2.1-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "2.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-2.1-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "2.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-2.1-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "2.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-2.1-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "2.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-2.1-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "2.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever endpoint/package inventories, MDM, registries, SBOMs, CI/CD, cloud catalogs, SSO, procurement, and publisher lifecycle sources change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 终端与包清单、MDM、制品库、SBOM、CI/CD、云目录、SSO、采购和发布方生命周期来源 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-2.1-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "2.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Use reviewed, unreviewed, reproducible, provenance-bound, vulnerable, test-failed, exception, deployed-unverified, drifted, rolled-back, and regression-protected releases to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已评审、未评审、可复现、来源绑定、存在漏洞、测试失败、例外、已部署未验证、漂移、已回滚和受回归保护发布物 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-2.1-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "2.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Use matched, missing, duplicate, stale, ownerless, unapproved, unevaluable, and retired-without-proof counts to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 匹配、缺失、重复、陈旧、无责任人、未批准、不可评估及无证明退役数量 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-2.1-OPS-08",
          "local_code": "OPS-08",
          "display_code": "R08",
          "safeguard_id": "2.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Use canary deployment, kill criteria, rollback, backlog burn-down, exception reduction, source-quality targets, quarterly design review, and a measurable retirement plan.",
          "zh": "采用金丝雀、停止标准、回滚、积压燃尽、例外缩减、来源质量目标、季度设计复核和可量化退役计划。"
        }
      ]
    },
    {
      "id": "2.2",
      "control": 2,
      "title_en": "Ensure Authorized Software is Currently Supported",
      "title_zh": "支持状态",
      "first_ig": 1,
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Software",
      "security_function": "Identify",
      "patterns": [
        "software_dev",
        "vulnerability"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "2.1"
        ],
        "variables": [
          "GV5",
          "GV6",
          "M1",
          "M2",
          "M3",
          "M4",
          "M5",
          "M6",
          "M7"
        ],
        "metric_branches": 4,
        "has_assumptions": true,
        "has_procedural_review": false
      },
      "official_cadence_terms": [
        "monthly"
      ],
      "implementation_contract": {
        "en": {
          "scope": "Assess every authorized product and version against a named publisher or accountable internal support channel, including OS editions, firmware, libraries, container bases, appliances and SaaS features.",
          "build": "The software owner records end-of-support dates, update channel, current supported target and migration decision.",
          "proof": "Verify lifecycle claims at the vendor or maintained-project source, then sample the deployed artifacts and use each artifact as the version authority.",
          "boundary": "The current CAS measures reverse its “with exception” and “without exception” variables, so implementers must define their own stable denominator."
        },
        "zh": {
          "scope": "逐项判断授权产品和版本是否有明确发布者或可问责的内部支持渠道，覆盖 OS 版本线、固件、库、容器基础、设备和 SaaS 功能。",
          "build": "软件责任人记录停止支持日、更新渠道、当前受支持目标和迁移决定；至少每月或供应商通知时复核。",
          "proof": "在厂商或维护项目的一手来源核验生命周期，并抽查实际部署版本而非台账标签。",
          "boundary": "CAS 把“有例外”和“无例外”变量写反，必须自建稳定分母。"
        }
      },
      "category_counts": {
        "outcome": 7,
        "scope": 7,
        "ownership": 7,
        "data": 7,
        "integration": 7,
        "control": 7,
        "timing": 7,
        "exception": 7,
        "evidence": 7,
        "security": 7,
        "testing": 7,
        "operations": 7
      },
      "requirement_count": 84,
      "requirements": [
        {
          "code": "CIS-2.2-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "2.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Ensure Authorized Software is Currently Supported; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“支持状态”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-2.2-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "2.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 2.2, official Asset Class Software, Security Function Identify, and IG1 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 2.2、官方资产类别“软件”、安全功能“识别”和首次出现的 IG1，并保存来源抓取日期。"
        },
        {
          "code": "CIS-2.2-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "2.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Assess every authorized product and version against a named publisher or accountable internal support channel, including OS editions, firmware, libraries, container bases, appliances and SaaS features.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“逐项判断授权产品和版本是否有明确发布者或可问责的内部支持渠道，覆盖 OS 版本线、固件、库、容器基础、设备和 SaaS 功能。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-2.2-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "2.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-2.2-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "2.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Ensure Authorized Software is Currently Supported to its operating object—operating systems, packages, firmware, extensions, container images, dependencies, SaaS applications, and internally built releases—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“支持状态”连接到其运营对象——操作系统、软件包、固件、扩展、容器镜像、依赖、SaaS 应用和内部构建发布物——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-2.2-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "2.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "For Ensure Authorized Software is Currently Supported, express success as an observable decision over source-to-production software identity, design invariant, component trust, build provenance, test result, deployment state, runtime outcome, and vulnerability response; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“支持状态”，以 从源码到生产的软件身份、设计不变量、组件信任、构建来源、测试结果、部署状态、运行结果和漏洞响应 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-2.2-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "2.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "For Ensure Authorized Software is Currently Supported, express success as an observable decision over affected artifact identity, exploitability, business consequence, remediation choice, deployed fix, compensating control, and residual exposure; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“支持状态”，以 受影响制品身份、可利用性、业务后果、修复选择、已部署修复、补偿控制和残余暴露 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-2.2-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "2.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-2.2-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "2.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-2.2-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "2.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-2.2-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "2.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-2.2-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "2.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across portable binaries, dormant images, static linking, shadow SaaS, mutable packages, unsupported editions, and environment-specific authorization; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 便携二进制、休眠镜像、静态链接、影子 SaaS、可变软件包、不受支持版本及环境相关授权 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-2.2-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "2.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Include generated and copied code, forks, vendoring, transitive dependencies, mutable tags, build plugins, feature flags, tenant logic, secrets, emergency release, and provider components in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 生成与复制代码、分叉、vendoring、传递依赖、可变标签、构建插件、功能开关、租户逻辑、秘密、紧急发布和提供商组件 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-2.2-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "2.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Include unknown versions, false positives, unavailable fixes, vendor lag, ephemeral workloads, unscannable platforms, inherited dependencies, mitigation-only states, and recurrence in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 未知版本、误报、无可用修复、厂商滞后、短生工作负载、不可扫描平台、继承依赖、仅缓解状态和复发 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-2.2-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "2.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-2.2-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "2.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-2.2-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "2.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-2.2-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "2.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-2.2-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "2.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind software and application owners, platform engineering, developers, procurement, and security to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 软件与应用责任人、平台工程、开发、采购和安全团队 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-2.2-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "2.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Name who may transition designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-2.2-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "2.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Name who may transition discovered → validated → prioritized → assigned → fixed/mitigated/excepted → deployed → retested → closed/reopened, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 发现 → 验证 → 定级 → 分派 → 修复/缓解/例外 → 部署 → 复测 → 关闭/重开，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-2.2-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "2.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-2.2-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "2.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-2.2-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "2.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV5, GV6, M1, M2, M3, M4, M5, M6, M7) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV5, GV6, M1, M2, M3, M4, M5, M6, M7）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-2.2-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "2.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-2.2-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "2.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the reconciled software and deployment authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把经过部署对账的软件权威台账作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-2.2-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "2.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired.",
          "zh": "对生命周期“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-2.2-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "2.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle discovered → validated → prioritized → assigned → fixed/mitigated/excepted → deployed → retested → closed/reopened.",
          "zh": "对生命周期“发现 → 验证 → 定级 → 分派 → 修复/缓解/例外 → 部署 → 复测 → 关闭/重开”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-2.2-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "2.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 2.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 2.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-2.2-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "2.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-2.2-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "2.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-2.2-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "2.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-2.2-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "2.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile endpoint/package inventories, MDM, registries, SBOMs, CI/CD, cloud catalogs, SSO, procurement, and publisher lifecycle sources and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 终端与包清单、MDM、制品库、SBOM、CI/CD、云目录、SSO、采购和发布方生命周期来源，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-2.2-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "2.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Require every connector carrying source-to-production software identity, design invariant, component trust, build provenance, test result, deployment state, runtime outcome, and vulnerability response to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 从源码到生产的软件身份、设计不变量、组件信任、构建来源、测试结果、部署状态、运行结果和漏洞响应 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-2.2-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "2.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Require every connector carrying affected artifact identity, exploitability, business consequence, remediation choice, deployed fix, compensating control, and residual exposure to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 受影响制品身份、可利用性、业务后果、修复选择、已部署修复、补偿控制和残余暴露 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-2.2-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "2.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “The software owner records end-of-support dates, update channel, current supported target and migration decision.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“软件责任人记录停止支持日、更新渠道、当前受支持目标和迁移决定；至少每月或供应商通知时复核。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-2.2-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "2.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-2.2-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "2.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-2.2-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "2.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-2.2-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "2.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the reconciled software and deployment authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在经过部署对账的软件权威台账中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-2.2-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "2.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Implement the explicit state machine designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-2.2-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "2.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Implement the explicit state machine discovered → validated → prioritized → assigned → fixed/mitigated/excepted → deployed → retested → closed/reopened; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“发现 → 验证 → 定级 → 分派 → 修复/缓解/例外 → 部署 → 复测 → 关闭/重开”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-2.2-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "2.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (monthly); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（monthly）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-2.2-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "2.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-2.2-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "2.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-2.2-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "2.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-2.2-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "2.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in operating systems, packages, firmware, extensions, container images, dependencies, SaaS applications, and internally built releases; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 操作系统、软件包、固件、扩展、容器镜像、依赖、SaaS 应用和内部构建发布物 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-2.2-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "2.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; alert before each deadline becomes overdue.",
          "zh": "为“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-2.2-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "2.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for discovered → validated → prioritized → assigned → fixed/mitigated/excepted → deployed → retested → closed/reopened; alert before each deadline becomes overdue.",
          "zh": "为“发现 → 验证 → 定级 → 分派 → 修复/缓解/例外 → 部署 → 复测 → 关闭/重开”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-2.2-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "2.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “The current CAS measures reverse its “with exception” and “without exception” variables, so implementers must define their own stable denominator.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“CAS 把“有例外”和“无例外”变量写反，必须自建稳定分母。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-2.2-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "2.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-2.2-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "2.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-2.2-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "2.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-2.2-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "2.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat portable binaries, dormant images, static linking, shadow SaaS, mutable packages, unsupported editions, and environment-specific authorization as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 便携二进制、休眠镜像、静态链接、影子 SaaS、可变软件包、不受支持版本及环境相关授权 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-2.2-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "2.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Treat generated and copied code, forks, vendoring, transitive dependencies, mutable tags, build plugins, feature flags, tenant logic, secrets, emergency release, and provider components as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 生成与复制代码、分叉、vendoring、传递依赖、可变标签、构建插件、功能开关、租户逻辑、秘密、紧急发布和提供商组件 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-2.2-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "2.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Treat unknown versions, false positives, unavailable fixes, vendor lag, ephemeral workloads, unscannable platforms, inherited dependencies, mitigation-only states, and recurrence as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 未知版本、误报、无可用修复、厂商滞后、短生工作负载、不可扫描平台、继承依赖、仅缓解状态和复发 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-2.2-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "2.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Verify lifecycle claims at the vendor or maintained-project source, then sample the deployed artifacts and use each artifact as the version authority.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“在厂商或维护项目的一手来源核验生命周期，并抽查实际部署版本而非台账标签。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-2.2-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "2.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-2.2-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "2.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 4 pinned CAS metric branch(es), 9 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 4 个指标分支、9 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-2.2-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "2.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-2.2-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "2.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the reconciled software and deployment authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以经过部署对账的软件权威台账和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-2.2-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "2.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Publish reviewed, unreviewed, reproducible, provenance-bound, vulnerable, test-failed, exception, deployed-unverified, drifted, rolled-back, and regression-protected releases with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已评审、未评审、可复现、来源绑定、存在漏洞、测试失败、例外、已部署未验证、漂移、已回滚和受回归保护发布物，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-2.2-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "2.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Publish open, validated, false-positive, overdue, mitigated, excepted, deployed-unverified, retest-failed, reopened, and exposure-weighted findings with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 开放、已验证、误报、逾期、已缓解、例外、已部署未验证、复测失败、重开和暴露加权发现，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-2.2-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "2.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-2.2-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "2.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-2.2-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "2.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-2.2-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "2.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-2.2-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "2.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the reconciled software and deployment authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护经过部署对账的软件权威台账的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-2.2-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "2.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Restrict authority to change designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-2.2-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "2.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Restrict authority to change discovered → validated → prioritized → assigned → fixed/mitigated/excepted → deployed → retested → closed/reopened; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“发现 → 验证 → 定级 → 分派 → 修复/缓解/例外 → 部署 → 复测 → 关闭/重开”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-2.2-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "2.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-2.2-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "2.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-2.2-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "2.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-2.2-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "2.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-2.2-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "2.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise an approved release, an unapproved binary, an unexpected dependency, a short-lived image, and a publisher end-of-support event through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 获批发布物、未批准二进制、意外依赖、短生镜像和发布方终止支持事件，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-2.2-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "2.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Run the positive control a trusted build that preserves the security invariant through deployment and runtime; exercise negative, stale, duplicate, bypass, and outage controls including a substituted dependency, unreviewed change, poisoned build input, failed security test, bypass path, vulnerable release, rollback, and regression.",
          "zh": "运行正向控制“一个把安全不变量贯穿部署与运行的可信构建”，并执行包含“依赖替换、未评审变更、构建输入污染、安全测试失败、绕过路径、漏洞发布、回滚和回归”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-2.2-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "2.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Run the positive control a known vulnerable artifact repaired and independently retested; exercise negative, stale, duplicate, bypass, and outage controls including credential failure, wrong version match, unavailable fix, mitigation bypass, failed deployment, rollback, recurring finding, and exposed unowned asset.",
          "zh": "运行正向控制“一项已知漏洞制品完成修复并独立复测”，并执行包含“凭据失败、版本误配、无可用修复、缓解绕过、部署失败、回滚、问题复发和外露无主资产”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-2.2-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "2.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-2.2-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "2.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-2.2-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "2.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-2.2-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "2.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-2.2-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "2.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever endpoint/package inventories, MDM, registries, SBOMs, CI/CD, cloud catalogs, SSO, procurement, and publisher lifecycle sources change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 终端与包清单、MDM、制品库、SBOM、CI/CD、云目录、SSO、采购和发布方生命周期来源 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-2.2-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "2.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Use reviewed, unreviewed, reproducible, provenance-bound, vulnerable, test-failed, exception, deployed-unverified, drifted, rolled-back, and regression-protected releases to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已评审、未评审、可复现、来源绑定、存在漏洞、测试失败、例外、已部署未验证、漂移、已回滚和受回归保护发布物 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-2.2-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "2.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Use open, validated, false-positive, overdue, mitigated, excepted, deployed-unverified, retest-failed, reopened, and exposure-weighted findings to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 开放、已验证、误报、逾期、已缓解、例外、已部署未验证、复测失败、重开和暴露加权发现 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "2.3",
      "control": 2,
      "title_en": "Address Unauthorized Software",
      "title_zh": "未授权软件处置",
      "first_ig": 1,
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Software",
      "security_function": "Respond",
      "patterns": [
        "software_dev"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "1.1",
          "2.1"
        ],
        "variables": [
          "GV1",
          "GV5",
          "GV7",
          "M1",
          "M2",
          "M3",
          "M4"
        ],
        "metric_branches": 2,
        "has_assumptions": true,
        "has_procedural_review": false
      },
      "official_cadence_terms": [
        "monthly"
      ],
      "implementation_contract": {
        "en": {
          "scope": "Include installed, portable, remotely executed, sideloaded, containerized and user-authorized SaaS software whose product, version, source, environment or purpose falls outside policy.",
          "build": "At least monthly, join discovery to the authorized inventory and assign remove, block, quarantine or authorize decisions.",
          "proof": "Install a benign unapproved binary, extension and container in test scope; verify discovery, containment, ticket evidence and non-reinstallation.",
          "boundary": "Forensic retention may delay deletion but requires execution prevention and custody."
        },
        "zh": {
          "scope": "范围包含以安装、便携、远程执行、侧载、容器和用户授权 SaaS 形式出现，且产品、版本、来源、环境或用途不符合政策的软件。",
          "build": "至少每月把发现结果与授权清单对账，作出移除、拦截、隔离或正式授权决定。",
          "proof": "在测试范围安装无害未批准二进制、扩展和容器，验证发现、控制、工单证据和不能再次安装。",
          "boundary": "取证保全可以延迟删除，但需阻止执行并记录保管。"
        }
      },
      "category_counts": {
        "outcome": 6,
        "scope": 6,
        "ownership": 6,
        "data": 6,
        "integration": 6,
        "control": 6,
        "timing": 6,
        "exception": 6,
        "evidence": 6,
        "security": 6,
        "testing": 6,
        "operations": 6
      },
      "requirement_count": 72,
      "requirements": [
        {
          "code": "CIS-2.3-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "2.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Address Unauthorized Software; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“未授权软件处置”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-2.3-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "2.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 2.3, official Asset Class Software, Security Function Respond, and IG1 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 2.3、官方资产类别“软件”、安全功能“响应”和首次出现的 IG1，并保存来源抓取日期。"
        },
        {
          "code": "CIS-2.3-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "2.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Include installed, portable, remotely executed, sideloaded, containerized and user-authorized SaaS software whose product, version, source, environment or purpose falls outside policy.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“范围包含以安装、便携、远程执行、侧载、容器和用户授权 SaaS 形式出现，且产品、版本、来源、环境或用途不符合政策的软件。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-2.3-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "2.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-2.3-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "2.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Address Unauthorized Software to its operating object—operating systems, packages, firmware, extensions, container images, dependencies, SaaS applications, and internally built releases—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“未授权软件处置”连接到其运营对象——操作系统、软件包、固件、扩展、容器镜像、依赖、SaaS 应用和内部构建发布物——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-2.3-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "2.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "For Address Unauthorized Software, express success as an observable decision over source-to-production software identity, design invariant, component trust, build provenance, test result, deployment state, runtime outcome, and vulnerability response; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“未授权软件处置”，以 从源码到生产的软件身份、设计不变量、组件信任、构建来源、测试结果、部署状态、运行结果和漏洞响应 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-2.3-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "2.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-2.3-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "2.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-2.3-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "2.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-2.3-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "2.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-2.3-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "2.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across portable binaries, dormant images, static linking, shadow SaaS, mutable packages, unsupported editions, and environment-specific authorization; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 便携二进制、休眠镜像、静态链接、影子 SaaS、可变软件包、不受支持版本及环境相关授权 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-2.3-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "2.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Include generated and copied code, forks, vendoring, transitive dependencies, mutable tags, build plugins, feature flags, tenant logic, secrets, emergency release, and provider components in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 生成与复制代码、分叉、vendoring、传递依赖、可变标签、构建插件、功能开关、租户逻辑、秘密、紧急发布和提供商组件 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-2.3-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "2.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-2.3-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "2.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-2.3-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "2.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-2.3-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "2.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-2.3-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "2.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind software and application owners, platform engineering, developers, procurement, and security to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 软件与应用责任人、平台工程、开发、采购和安全团队 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-2.3-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "2.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Name who may transition designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-2.3-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "2.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-2.3-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "2.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-2.3-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "2.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV1, GV5, GV7, M1, M2, M3, M4) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV1, GV5, GV7, M1, M2, M3, M4）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-2.3-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "2.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-2.3-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "2.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the reconciled software and deployment authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把经过部署对账的软件权威台账作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-2.3-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "2.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired.",
          "zh": "对生命周期“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-2.3-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "2.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 1.1, Safeguard 2.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 1.1、Safeguard 2.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-2.3-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "2.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-2.3-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "2.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-2.3-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "2.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-2.3-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "2.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile endpoint/package inventories, MDM, registries, SBOMs, CI/CD, cloud catalogs, SSO, procurement, and publisher lifecycle sources and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 终端与包清单、MDM、制品库、SBOM、CI/CD、云目录、SSO、采购和发布方生命周期来源，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-2.3-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "2.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Require every connector carrying source-to-production software identity, design invariant, component trust, build provenance, test result, deployment state, runtime outcome, and vulnerability response to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 从源码到生产的软件身份、设计不变量、组件信任、构建来源、测试结果、部署状态、运行结果和漏洞响应 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-2.3-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "2.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “At least monthly, join discovery to the authorized inventory and assign remove, block, quarantine or authorize decisions.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“至少每月把发现结果与授权清单对账，作出移除、拦截、隔离或正式授权决定。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-2.3-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "2.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-2.3-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "2.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-2.3-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "2.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-2.3-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "2.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the reconciled software and deployment authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在经过部署对账的软件权威台账中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-2.3-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "2.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Implement the explicit state machine designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-2.3-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "2.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (monthly); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（monthly）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-2.3-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "2.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-2.3-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "2.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-2.3-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "2.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-2.3-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "2.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in operating systems, packages, firmware, extensions, container images, dependencies, SaaS applications, and internally built releases; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 操作系统、软件包、固件、扩展、容器镜像、依赖、SaaS 应用和内部构建发布物 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-2.3-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "2.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; alert before each deadline becomes overdue.",
          "zh": "为“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-2.3-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "2.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “Forensic retention may delay deletion but requires execution prevention and custody.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“取证保全可以延迟删除，但需阻止执行并记录保管。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-2.3-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "2.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-2.3-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "2.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-2.3-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "2.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-2.3-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "2.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat portable binaries, dormant images, static linking, shadow SaaS, mutable packages, unsupported editions, and environment-specific authorization as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 便携二进制、休眠镜像、静态链接、影子 SaaS、可变软件包、不受支持版本及环境相关授权 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-2.3-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "2.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Treat generated and copied code, forks, vendoring, transitive dependencies, mutable tags, build plugins, feature flags, tenant logic, secrets, emergency release, and provider components as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 生成与复制代码、分叉、vendoring、传递依赖、可变标签、构建插件、功能开关、租户逻辑、秘密、紧急发布和提供商组件 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-2.3-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "2.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Install a benign unapproved binary, extension and container in test scope; verify discovery, containment, ticket evidence and non-reinstallation.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“在测试范围安装无害未批准二进制、扩展和容器，验证发现、控制、工单证据和不能再次安装。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-2.3-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "2.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-2.3-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "2.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 2 pinned CAS metric branch(es), 7 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 2 个指标分支、7 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-2.3-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "2.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-2.3-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "2.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the reconciled software and deployment authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以经过部署对账的软件权威台账和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-2.3-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "2.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Publish reviewed, unreviewed, reproducible, provenance-bound, vulnerable, test-failed, exception, deployed-unverified, drifted, rolled-back, and regression-protected releases with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已评审、未评审、可复现、来源绑定、存在漏洞、测试失败、例外、已部署未验证、漂移、已回滚和受回归保护发布物，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-2.3-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "2.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-2.3-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "2.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-2.3-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "2.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-2.3-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "2.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-2.3-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "2.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the reconciled software and deployment authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护经过部署对账的软件权威台账的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-2.3-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "2.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Restrict authority to change designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-2.3-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "2.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-2.3-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "2.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-2.3-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "2.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-2.3-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "2.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-2.3-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "2.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise an approved release, an unapproved binary, an unexpected dependency, a short-lived image, and a publisher end-of-support event through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 获批发布物、未批准二进制、意外依赖、短生镜像和发布方终止支持事件，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-2.3-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "2.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Run the positive control a trusted build that preserves the security invariant through deployment and runtime; exercise negative, stale, duplicate, bypass, and outage controls including a substituted dependency, unreviewed change, poisoned build input, failed security test, bypass path, vulnerable release, rollback, and regression.",
          "zh": "运行正向控制“一个把安全不变量贯穿部署与运行的可信构建”，并执行包含“依赖替换、未评审变更、构建输入污染、安全测试失败、绕过路径、漏洞发布、回滚和回归”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-2.3-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "2.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-2.3-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "2.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-2.3-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "2.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-2.3-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "2.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-2.3-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "2.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever endpoint/package inventories, MDM, registries, SBOMs, CI/CD, cloud catalogs, SSO, procurement, and publisher lifecycle sources change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 终端与包清单、MDM、制品库、SBOM、CI/CD、云目录、SSO、采购和发布方生命周期来源 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-2.3-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "2.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Use reviewed, unreviewed, reproducible, provenance-bound, vulnerable, test-failed, exception, deployed-unverified, drifted, rolled-back, and regression-protected releases to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已评审、未评审、可复现、来源绑定、存在漏洞、测试失败、例外、已部署未验证、漂移、已回滚和受回归保护发布物 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "2.4",
      "control": 2,
      "title_en": "Utilize Automated Software Inventory Tools",
      "title_zh": "自动化软件发现",
      "first_ig": 2,
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Software",
      "security_function": "Detect",
      "patterns": [
        "software_dev",
        "inventory"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "1.1",
          "2.3"
        ],
        "variables": [
          "GV1",
          "GV7",
          "M1",
          "M2",
          "M3",
          "M4",
          "M5"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "Cover all platforms capable of automated collection and declare where an agent, API, registry scan, package query or image analysis is used.",
          "build": "Operate tools on a defined schedule, monitor collection age and failures, normalize product/version identities, and reconcile results to both asset and software authorities.",
          "proof": "Measure assets with fresh, successful, sufficiently detailed results over eligible assets, then sample raw evidence against the normalized inventory.",
          "boundary": "Unsupported platforms and privacy constraints require a named alternative source."
        },
        "zh": {
          "scope": "覆盖所有能自动采集的平台，并说明使用 Agent、API、仓库扫描、包查询还是镜像分析。",
          "build": "按固定周期运行工具，监测采集年龄和失败，归一产品/版本身份，并同时与资产、软件台账对账。",
          "proof": "以“成功且新鲜、信息足够的结果/符合条件的资产”为覆盖率，再把原始证据抽回归一台账核验。",
          "boundary": "不支持的平台和隐私约束要有具名替代来源。"
        }
      },
      "category_counts": {
        "outcome": 7,
        "scope": 7,
        "ownership": 7,
        "data": 7,
        "integration": 7,
        "control": 7,
        "timing": 7,
        "exception": 7,
        "evidence": 7,
        "security": 7,
        "testing": 7,
        "operations": 7
      },
      "requirement_count": 84,
      "requirements": [
        {
          "code": "CIS-2.4-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "2.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Utilize Automated Software Inventory Tools; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“自动化软件发现”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-2.4-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "2.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 2.4, official Asset Class Software, Security Function Detect, and IG2 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 2.4、官方资产类别“软件”、安全功能“检测”和首次出现的 IG2，并保存来源抓取日期。"
        },
        {
          "code": "CIS-2.4-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "2.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Cover all platforms capable of automated collection and declare where an agent, API, registry scan, package query or image analysis is used.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“覆盖所有能自动采集的平台，并说明使用 Agent、API、仓库扫描、包查询还是镜像分析。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-2.4-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "2.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-2.4-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "2.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Utilize Automated Software Inventory Tools to its operating object—operating systems, packages, firmware, extensions, container images, dependencies, SaaS applications, and internally built releases—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“自动化软件发现”连接到其运营对象——操作系统、软件包、固件、扩展、容器镜像、依赖、SaaS 应用和内部构建发布物——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-2.4-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "2.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "For Utilize Automated Software Inventory Tools, express success as an observable decision over source-to-production software identity, design invariant, component trust, build provenance, test result, deployment state, runtime outcome, and vulnerability response; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“自动化软件发现”，以 从源码到生产的软件身份、设计不变量、组件信任、构建来源、测试结果、部署状态、运行结果和漏洞响应 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-2.4-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "2.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "For Utilize Automated Software Inventory Tools, express success as an observable decision over observed, approved, unapproved, ownerless, stale, duplicate, and retired object identity; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“自动化软件发现”，以 已观测、已批准、未批准、无责任人、陈旧、重复和已退役对象身份 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-2.4-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "2.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-2.4-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "2.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-2.4-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "2.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-2.4-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "2.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-2.4-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "2.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across portable binaries, dormant images, static linking, shadow SaaS, mutable packages, unsupported editions, and environment-specific authorization; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 便携二进制、休眠镜像、静态链接、影子 SaaS、可变软件包、不受支持版本及环境相关授权 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-2.4-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "2.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Include generated and copied code, forks, vendoring, transitive dependencies, mutable tags, build plugins, feature flags, tenant logic, secrets, emergency release, and provider components in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 生成与复制代码、分叉、vendoring、传递依赖、可变标签、构建插件、功能开关、租户逻辑、秘密、紧急发布和提供商组件 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-2.4-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "2.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Include dormant, ephemeral, disconnected, externally managed, provider-held, aliased, cloned, and cross-tenant objects in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 休眠、短生、离线、外部托管、提供商持有、别名、克隆和跨租户对象 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-2.4-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "2.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-2.4-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "2.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-2.4-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "2.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-2.4-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "2.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-2.4-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "2.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind software and application owners, platform engineering, developers, procurement, and security to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 软件与应用责任人、平台工程、开发、采购和安全团队 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-2.4-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "2.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Name who may transition designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-2.4-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "2.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Name who may transition discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-2.4-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "2.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-2.4-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "2.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-2.4-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "2.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV1, GV7, M1, M2, M3, M4, M5) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV1, GV7, M1, M2, M3, M4, M5）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-2.4-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "2.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-2.4-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "2.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the reconciled software and deployment authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把经过部署对账的软件权威台账作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-2.4-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "2.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired.",
          "zh": "对生命周期“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-2.4-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "2.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence.",
          "zh": "对生命周期“发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-2.4-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "2.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 1.1, Safeguard 2.3; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 1.1、Safeguard 2.3 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-2.4-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "2.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-2.4-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "2.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-2.4-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "2.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-2.4-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "2.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile endpoint/package inventories, MDM, registries, SBOMs, CI/CD, cloud catalogs, SSO, procurement, and publisher lifecycle sources and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 终端与包清单、MDM、制品库、SBOM、CI/CD、云目录、SSO、采购和发布方生命周期来源，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-2.4-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "2.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Require every connector carrying source-to-production software identity, design invariant, component trust, build provenance, test result, deployment state, runtime outcome, and vulnerability response to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 从源码到生产的软件身份、设计不变量、组件信任、构建来源、测试结果、部署状态、运行结果和漏洞响应 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-2.4-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "2.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Require every connector carrying observed, approved, unapproved, ownerless, stale, duplicate, and retired object identity to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 已观测、已批准、未批准、无责任人、陈旧、重复和已退役对象身份 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-2.4-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "2.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Operate tools on a defined schedule, monitor collection age and failures, normalize product/version identities, and reconcile results to both asset and software authorities.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“按固定周期运行工具，监测采集年龄和失败，归一产品/版本身份，并同时与资产、软件台账对账。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-2.4-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "2.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-2.4-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "2.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-2.4-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "2.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-2.4-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "2.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the reconciled software and deployment authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在经过部署对账的软件权威台账中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-2.4-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "2.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Implement the explicit state machine designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-2.4-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "2.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Implement the explicit state machine discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-2.4-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "2.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-2.4-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "2.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-2.4-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "2.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-2.4-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "2.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-2.4-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "2.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in operating systems, packages, firmware, extensions, container images, dependencies, SaaS applications, and internally built releases; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 操作系统、软件包、固件、扩展、容器镜像、依赖、SaaS 应用和内部构建发布物 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-2.4-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "2.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; alert before each deadline becomes overdue.",
          "zh": "为“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-2.4-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "2.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence; alert before each deadline becomes overdue.",
          "zh": "为“发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-2.4-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "2.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “Unsupported platforms and privacy constraints require a named alternative source.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“不支持的平台和隐私约束要有具名替代来源。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-2.4-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "2.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-2.4-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "2.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-2.4-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "2.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-2.4-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "2.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat portable binaries, dormant images, static linking, shadow SaaS, mutable packages, unsupported editions, and environment-specific authorization as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 便携二进制、休眠镜像、静态链接、影子 SaaS、可变软件包、不受支持版本及环境相关授权 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-2.4-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "2.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Treat generated and copied code, forks, vendoring, transitive dependencies, mutable tags, build plugins, feature flags, tenant logic, secrets, emergency release, and provider components as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 生成与复制代码、分叉、vendoring、传递依赖、可变标签、构建插件、功能开关、租户逻辑、秘密、紧急发布和提供商组件 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-2.4-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "2.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Treat dormant, ephemeral, disconnected, externally managed, provider-held, aliased, cloned, and cross-tenant objects as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 休眠、短生、离线、外部托管、提供商持有、别名、克隆和跨租户对象 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-2.4-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "2.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Measure assets with fresh, successful, sufficiently detailed results over eligible assets, then sample raw evidence against the normalized inventory.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“以“成功且新鲜、信息足够的结果/符合条件的资产”为覆盖率，再把原始证据抽回归一台账核验。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-2.4-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "2.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-2.4-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "2.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 7 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、7 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-2.4-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "2.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-2.4-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "2.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the reconciled software and deployment authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以经过部署对账的软件权威台账和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-2.4-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "2.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Publish reviewed, unreviewed, reproducible, provenance-bound, vulnerable, test-failed, exception, deployed-unverified, drifted, rolled-back, and regression-protected releases with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已评审、未评审、可复现、来源绑定、存在漏洞、测试失败、例外、已部署未验证、漂移、已回滚和受回归保护发布物，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-2.4-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "2.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Publish matched, missing, duplicate, stale, ownerless, unapproved, unevaluable, and retired-without-proof counts with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 匹配、缺失、重复、陈旧、无责任人、未批准、不可评估及无证明退役数量，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-2.4-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "2.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-2.4-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "2.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-2.4-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "2.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-2.4-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "2.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-2.4-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "2.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the reconciled software and deployment authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护经过部署对账的软件权威台账的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-2.4-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "2.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Restrict authority to change designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-2.4-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "2.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Restrict authority to change discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-2.4-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "2.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-2.4-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "2.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-2.4-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "2.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-2.4-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "2.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-2.4-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "2.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise an approved release, an unapproved binary, an unexpected dependency, a short-lived image, and a publisher end-of-support event through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 获批发布物、未批准二进制、意外依赖、短生镜像和发布方终止支持事件，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-2.4-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "2.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Run the positive control a trusted build that preserves the security invariant through deployment and runtime; exercise negative, stale, duplicate, bypass, and outage controls including a substituted dependency, unreviewed change, poisoned build input, failed security test, bypass path, vulnerable release, rollback, and regression.",
          "zh": "运行正向控制“一个把安全不变量贯穿部署与运行的可信构建”，并执行包含“依赖替换、未评审变更、构建输入污染、安全测试失败、绕过路径、漏洞发布、回滚和回归”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-2.4-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "2.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Run the positive control a seeded approved object reconciled from two independent sources; exercise negative, stale, duplicate, bypass, and outage controls including an unknown object, duplicate identity, stale record, vanished object, failed source, and cross-tenant collision.",
          "zh": "运行正向控制“从两个独立来源对账的一项植入已批准对象”，并执行包含“未知对象、重复身份、陈旧记录、突然消失对象、失效来源和跨租户碰撞”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-2.4-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "2.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-2.4-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "2.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-2.4-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "2.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-2.4-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "2.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-2.4-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "2.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever endpoint/package inventories, MDM, registries, SBOMs, CI/CD, cloud catalogs, SSO, procurement, and publisher lifecycle sources change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 终端与包清单、MDM、制品库、SBOM、CI/CD、云目录、SSO、采购和发布方生命周期来源 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-2.4-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "2.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Use reviewed, unreviewed, reproducible, provenance-bound, vulnerable, test-failed, exception, deployed-unverified, drifted, rolled-back, and regression-protected releases to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已评审、未评审、可复现、来源绑定、存在漏洞、测试失败、例外、已部署未验证、漂移、已回滚和受回归保护发布物 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-2.4-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "2.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Use matched, missing, duplicate, stale, ownerless, unapproved, unevaluable, and retired-without-proof counts to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 匹配、缺失、重复、陈旧、无责任人、未批准、不可评估及无证明退役数量 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "2.5",
      "control": 2,
      "title_en": "Allowlist Authorized Software",
      "title_zh": "应用允许清单",
      "first_ig": 2,
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Software",
      "security_function": "Protect",
      "patterns": [
        "software_dev",
        "enforcement"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "1.1",
          "2.1",
          "2.3",
          "4.1"
        ],
        "variables": [
          "GV3",
          "GV5",
          "GV7",
          "GV8",
          "GV9",
          "M1",
          "M2",
          "M3",
          "M4",
          "M5",
          "M6"
        ],
        "metric_branches": 2,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [
        "bi-annually",
        "annually"
      ],
      "implementation_contract": {
        "en": {
          "scope": "The executable population includes binaries, packages, installers, interpreters and application launch paths in the protected environment.",
          "build": "Build policy from known business workflows and trusted distribution, enforce at OS, endpoint, container admission or application control, and maintain emergency and update paths.",
          "proof": "Run approved applications and updates as positive controls, then unsigned, renamed, copied-to-writable-path and signed-but-unapproved binaries as negative controls.",
          "boundary": "Allowlisting does not judge safe behavior and cannot replace vulnerability or malware controls."
        },
        "zh": {
          "scope": "执行总体包括受保护环境里的二进制、安装器、解释器和应用启动路径。",
          "build": "从已知业务流程和可信分发建立策略，在 OS、终端、容器准入或应用控制层执行，并保留应急与更新通道。",
          "proof": "以获批应用和更新作正控，以未签名、改名、复制到可写路径以及“已签名但未批准”二进制作负控。",
          "boundary": "允许清单不判断行为安全，不能替代漏洞和恶意软件控制。"
        }
      },
      "category_counts": {
        "outcome": 7,
        "scope": 7,
        "ownership": 7,
        "data": 7,
        "integration": 7,
        "control": 7,
        "timing": 7,
        "exception": 7,
        "evidence": 7,
        "security": 7,
        "testing": 7,
        "operations": 7
      },
      "requirement_count": 84,
      "requirements": [
        {
          "code": "CIS-2.5-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "2.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Allowlist Authorized Software; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“应用允许清单”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-2.5-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "2.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 2.5, official Asset Class Software, Security Function Protect, and IG2 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 2.5、官方资产类别“软件”、安全功能“保护”和首次出现的 IG2，并保存来源抓取日期。"
        },
        {
          "code": "CIS-2.5-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "2.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “The executable population includes binaries, packages, installers, interpreters and application launch paths in the protected environment.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“执行总体包括受保护环境里的二进制、安装器、解释器和应用启动路径。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-2.5-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "2.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-2.5-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "2.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Allowlist Authorized Software to its operating object—operating systems, packages, firmware, extensions, container images, dependencies, SaaS applications, and internally built releases—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“应用允许清单”连接到其运营对象——操作系统、软件包、固件、扩展、容器镜像、依赖、SaaS 应用和内部构建发布物——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-2.5-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "2.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "For Allowlist Authorized Software, express success as an observable decision over source-to-production software identity, design invariant, component trust, build provenance, test result, deployment state, runtime outcome, and vulnerability response; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“应用允许清单”，以 从源码到生产的软件身份、设计不变量、组件信任、构建来源、测试结果、部署状态、运行结果和漏洞响应 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-2.5-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "2.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "For Allowlist Authorized Software, express success as an observable decision over an enforceable allow, deny, contain, quarantine, require, remove, or transform decision at the closest reliable control point; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“应用允许清单”，以 在最近可靠控制点执行允许、拒绝、遏制、隔离、强制、移除或转换决策 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-2.5-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "2.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-2.5-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "2.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-2.5-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "2.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-2.5-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "2.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-2.5-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "2.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across portable binaries, dormant images, static linking, shadow SaaS, mutable packages, unsupported editions, and environment-specific authorization; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 便携二进制、休眠镜像、静态链接、影子 SaaS、可变软件包、不受支持版本及环境相关授权 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-2.5-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "2.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Include generated and copied code, forks, vendoring, transitive dependencies, mutable tags, build plugins, feature flags, tenant logic, secrets, emergency release, and provider components in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 生成与复制代码、分叉、vendoring、传递依赖、可变标签、构建插件、功能开关、租户逻辑、秘密、紧急发布和提供商组件 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-2.5-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "2.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Include audit-only mode, unsupported platforms, local overrides, race conditions, cached state, alternate paths, fail-open behavior, and emergency bypass in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 仅审计模式、不支持平台、本地覆盖、竞态、缓存状态、替代路径、故障开放和紧急绕过 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-2.5-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "2.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-2.5-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "2.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-2.5-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "2.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-2.5-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "2.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-2.5-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "2.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind software and application owners, platform engineering, developers, procurement, and security to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 软件与应用责任人、平台工程、开发、采购和安全团队 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-2.5-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "2.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Name who may transition designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-2.5-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "2.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Name who may transition observe → evaluate → decide → enforce → verify outcome → rollback/close, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-2.5-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "2.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-2.5-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "2.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-2.5-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "2.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV3, GV5, GV7, GV8, GV9, M1, M2, M3, M4, M5, M6) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV3, GV5, GV7, GV8, GV9, M1, M2, M3, M4, M5, M6）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-2.5-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "2.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-2.5-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "2.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the reconciled software and deployment authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把经过部署对账的软件权威台账作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-2.5-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "2.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired.",
          "zh": "对生命周期“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-2.5-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "2.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle observe → evaluate → decide → enforce → verify outcome → rollback/close.",
          "zh": "对生命周期“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-2.5-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "2.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 1.1, Safeguard 2.1, Safeguard 2.3, Safeguard 4.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 1.1、Safeguard 2.1、Safeguard 2.3、Safeguard 4.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-2.5-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "2.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-2.5-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "2.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-2.5-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "2.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-2.5-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "2.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile endpoint/package inventories, MDM, registries, SBOMs, CI/CD, cloud catalogs, SSO, procurement, and publisher lifecycle sources and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 终端与包清单、MDM、制品库、SBOM、CI/CD、云目录、SSO、采购和发布方生命周期来源，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-2.5-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "2.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Require every connector carrying source-to-production software identity, design invariant, component trust, build provenance, test result, deployment state, runtime outcome, and vulnerability response to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 从源码到生产的软件身份、设计不变量、组件信任、构建来源、测试结果、部署状态、运行结果和漏洞响应 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-2.5-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "2.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Require every connector carrying an enforceable allow, deny, contain, quarantine, require, remove, or transform decision at the closest reliable control point to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 在最近可靠控制点执行允许、拒绝、遏制、隔离、强制、移除或转换决策 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-2.5-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "2.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Build policy from known business workflows and trusted distribution, enforce at OS, endpoint, container admission or application control, and maintain emergency and update paths.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“从已知业务流程和可信分发建立策略，在 OS、终端、容器准入或应用控制层执行，并保留应急与更新通道。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-2.5-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "2.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-2.5-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "2.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-2.5-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "2.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-2.5-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "2.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the reconciled software and deployment authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在经过部署对账的软件权威台账中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-2.5-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "2.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Implement the explicit state machine designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-2.5-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "2.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Implement the explicit state machine observe → evaluate → decide → enforce → verify outcome → rollback/close; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-2.5-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "2.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (bi-annually, annually); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（bi-annually, annually）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-2.5-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "2.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-2.5-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "2.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-2.5-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "2.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-2.5-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "2.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in operating systems, packages, firmware, extensions, container images, dependencies, SaaS applications, and internally built releases; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 操作系统、软件包、固件、扩展、容器镜像、依赖、SaaS 应用和内部构建发布物 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-2.5-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "2.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; alert before each deadline becomes overdue.",
          "zh": "为“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-2.5-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "2.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for observe → evaluate → decide → enforce → verify outcome → rollback/close; alert before each deadline becomes overdue.",
          "zh": "为“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-2.5-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "2.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “Allowlisting does not judge safe behavior and cannot replace vulnerability or malware controls.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“允许清单不判断行为安全，不能替代漏洞和恶意软件控制。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-2.5-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "2.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-2.5-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "2.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-2.5-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "2.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-2.5-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "2.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat portable binaries, dormant images, static linking, shadow SaaS, mutable packages, unsupported editions, and environment-specific authorization as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 便携二进制、休眠镜像、静态链接、影子 SaaS、可变软件包、不受支持版本及环境相关授权 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-2.5-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "2.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Treat generated and copied code, forks, vendoring, transitive dependencies, mutable tags, build plugins, feature flags, tenant logic, secrets, emergency release, and provider components as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 生成与复制代码、分叉、vendoring、传递依赖、可变标签、构建插件、功能开关、租户逻辑、秘密、紧急发布和提供商组件 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-2.5-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "2.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Treat audit-only mode, unsupported platforms, local overrides, race conditions, cached state, alternate paths, fail-open behavior, and emergency bypass as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 仅审计模式、不支持平台、本地覆盖、竞态、缓存状态、替代路径、故障开放和紧急绕过 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-2.5-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "2.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Run approved applications and updates as positive controls, then unsigned, renamed, copied-to-writable-path and signed-but-unapproved binaries as negative controls.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“以获批应用和更新作正控，以未签名、改名、复制到可写路径以及“已签名但未批准”二进制作负控。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-2.5-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "2.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-2.5-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "2.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 2 pinned CAS metric branch(es), 11 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 2 个指标分支、11 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-2.5-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "2.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-2.5-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "2.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the reconciled software and deployment authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以经过部署对账的软件权威台账和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-2.5-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "2.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Publish reviewed, unreviewed, reproducible, provenance-bound, vulnerable, test-failed, exception, deployed-unverified, drifted, rolled-back, and regression-protected releases with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已评审、未评审、可复现、来源绑定、存在漏洞、测试失败、例外、已部署未验证、漂移、已回滚和受回归保护发布物，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-2.5-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "2.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Publish eligible, enforcing, audit-only, failed, bypassed, excepted, rolled-back, and outcome-verified populations with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 适用、已执行、仅审计、失败、被绕过、例外、已回滚和结果已验证总体，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-2.5-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "2.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-2.5-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "2.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-2.5-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "2.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-2.5-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "2.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-2.5-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "2.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the reconciled software and deployment authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护经过部署对账的软件权威台账的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-2.5-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "2.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Restrict authority to change designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-2.5-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "2.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Restrict authority to change observe → evaluate → decide → enforce → verify outcome → rollback/close; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-2.5-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "2.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-2.5-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "2.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-2.5-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "2.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-2.5-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "2.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-2.5-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "2.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise an approved release, an unapproved binary, an unexpected dependency, a short-lived image, and a publisher end-of-support event through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 获批发布物、未批准二进制、意外依赖、短生镜像和发布方终止支持事件，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-2.5-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "2.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Run the positive control a trusted build that preserves the security invariant through deployment and runtime; exercise negative, stale, duplicate, bypass, and outage controls including a substituted dependency, unreviewed change, poisoned build input, failed security test, bypass path, vulnerable release, rollback, and regression.",
          "zh": "运行正向控制“一个把安全不变量贯穿部署与运行的可信构建”，并执行包含“依赖替换、未评审变更、构建输入污染、安全测试失败、绕过路径、漏洞发布、回滚和回归”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-2.5-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "2.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Run the positive control an approved business action that completes through the enforced path; exercise negative, stale, duplicate, bypass, and outage controls including a prohibited action, alternate path, local override, stale policy, control outage, emergency bypass, and rollback failure.",
          "zh": "运行正向控制“通过受控路径完成的一项获批业务动作”，并执行包含“禁止动作、替代路径、本地覆盖、陈旧策略、控制中断、紧急绕过和回滚失败”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-2.5-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "2.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-2.5-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "2.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-2.5-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "2.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-2.5-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "2.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-2.5-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "2.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever endpoint/package inventories, MDM, registries, SBOMs, CI/CD, cloud catalogs, SSO, procurement, and publisher lifecycle sources change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 终端与包清单、MDM、制品库、SBOM、CI/CD、云目录、SSO、采购和发布方生命周期来源 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-2.5-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "2.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Use reviewed, unreviewed, reproducible, provenance-bound, vulnerable, test-failed, exception, deployed-unverified, drifted, rolled-back, and regression-protected releases to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已评审、未评审、可复现、来源绑定、存在漏洞、测试失败、例外、已部署未验证、漂移、已回滚和受回归保护发布物 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-2.5-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "2.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Use eligible, enforcing, audit-only, failed, bypassed, excepted, rolled-back, and outcome-verified populations to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 适用、已执行、仅审计、失败、被绕过、例外、已回滚和结果已验证总体 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "2.6",
      "control": 2,
      "title_en": "Allowlist Authorized Libraries",
      "title_zh": "库允许清单",
      "first_ig": 2,
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Software",
      "security_function": "Protect",
      "patterns": [
        "software_dev",
        "enforcement"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "2.1",
          "2.5",
          "4.2"
        ],
        "variables": [
          "GV8",
          "GV9",
          "M1",
          "M2",
          "M3",
          "M4"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [
        "bi-annually",
        "annually"
      ],
      "implementation_contract": {
        "en": {
          "scope": "The population is every dynamically or statically incorporated library, framework, package, plugin and shared object used at build or runtime, including transitive dependencies and container layers.",
          "build": "Pin approved component identity, version or constrained range, source repository, integrity digest and permitted application/environment in lockfiles, artifact repositories, build policy and runtime loading controls where supported.",
          "proof": "Build the same application with an approved component, an unexpected transitive dependency, a dependency-confusion name and a modified digest.",
          "boundary": "Static linking and vendoring hide runtime package queries; dynamically generated code and customer plugins need separate trust boundaries."
        },
        "zh": {
          "scope": "总体是构建或运行时直接、传递、动态或静态引入的库、框架、包、插件和共享对象，也包括容器层。",
          "build": "在锁文件、制品仓库、构建策略和可支持的运行时加载控制中，固定组件身份、版本或窄范围、来源、完整性摘要和允许的应用/环境；阻断公共仓库回退和未审查插件目录，并设置责任人与紧急更新通道。",
          "proof": "用获批组件、意外传递依赖、依赖混淆名称和被修改摘要分别构建同一应用，验证拒绝或显式评审、制品/SBOM 关联和抽样运行一致。",
          "boundary": "静态链接和 Vendoring 会躲过运行时包查询；动态生成代码与客户插件需要单独信任边界。"
        }
      },
      "category_counts": {
        "outcome": 7,
        "scope": 7,
        "ownership": 7,
        "data": 7,
        "integration": 7,
        "control": 7,
        "timing": 7,
        "exception": 7,
        "evidence": 7,
        "security": 7,
        "testing": 7,
        "operations": 7
      },
      "requirement_count": 84,
      "requirements": [
        {
          "code": "CIS-2.6-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "2.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Allowlist Authorized Libraries; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“库允许清单”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-2.6-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "2.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 2.6, official Asset Class Software, Security Function Protect, and IG2 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 2.6、官方资产类别“软件”、安全功能“保护”和首次出现的 IG2，并保存来源抓取日期。"
        },
        {
          "code": "CIS-2.6-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "2.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “The population is every dynamically or statically incorporated library, framework, package, plugin and shared object used at build or runtime, including transitive dependencies and container layers.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“总体是构建或运行时直接、传递、动态或静态引入的库、框架、包、插件和共享对象，也包括容器层。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-2.6-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "2.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-2.6-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "2.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Allowlist Authorized Libraries to its operating object—operating systems, packages, firmware, extensions, container images, dependencies, SaaS applications, and internally built releases—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“库允许清单”连接到其运营对象——操作系统、软件包、固件、扩展、容器镜像、依赖、SaaS 应用和内部构建发布物——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-2.6-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "2.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "For Allowlist Authorized Libraries, express success as an observable decision over source-to-production software identity, design invariant, component trust, build provenance, test result, deployment state, runtime outcome, and vulnerability response; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“库允许清单”，以 从源码到生产的软件身份、设计不变量、组件信任、构建来源、测试结果、部署状态、运行结果和漏洞响应 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-2.6-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "2.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "For Allowlist Authorized Libraries, express success as an observable decision over an enforceable allow, deny, contain, quarantine, require, remove, or transform decision at the closest reliable control point; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“库允许清单”，以 在最近可靠控制点执行允许、拒绝、遏制、隔离、强制、移除或转换决策 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-2.6-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "2.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-2.6-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "2.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-2.6-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "2.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-2.6-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "2.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-2.6-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "2.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across portable binaries, dormant images, static linking, shadow SaaS, mutable packages, unsupported editions, and environment-specific authorization; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 便携二进制、休眠镜像、静态链接、影子 SaaS、可变软件包、不受支持版本及环境相关授权 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-2.6-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "2.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Include generated and copied code, forks, vendoring, transitive dependencies, mutable tags, build plugins, feature flags, tenant logic, secrets, emergency release, and provider components in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 生成与复制代码、分叉、vendoring、传递依赖、可变标签、构建插件、功能开关、租户逻辑、秘密、紧急发布和提供商组件 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-2.6-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "2.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Include audit-only mode, unsupported platforms, local overrides, race conditions, cached state, alternate paths, fail-open behavior, and emergency bypass in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 仅审计模式、不支持平台、本地覆盖、竞态、缓存状态、替代路径、故障开放和紧急绕过 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-2.6-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "2.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-2.6-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "2.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-2.6-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "2.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-2.6-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "2.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-2.6-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "2.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind software and application owners, platform engineering, developers, procurement, and security to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 软件与应用责任人、平台工程、开发、采购和安全团队 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-2.6-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "2.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Name who may transition designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-2.6-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "2.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Name who may transition observe → evaluate → decide → enforce → verify outcome → rollback/close, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-2.6-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "2.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-2.6-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "2.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-2.6-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "2.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV8, GV9, M1, M2, M3, M4) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV8, GV9, M1, M2, M3, M4）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-2.6-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "2.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-2.6-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "2.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the reconciled software and deployment authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把经过部署对账的软件权威台账作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-2.6-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "2.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired.",
          "zh": "对生命周期“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-2.6-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "2.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle observe → evaluate → decide → enforce → verify outcome → rollback/close.",
          "zh": "对生命周期“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-2.6-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "2.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 2.1, Safeguard 2.5, Safeguard 4.2; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 2.1、Safeguard 2.5、Safeguard 4.2 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-2.6-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "2.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-2.6-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "2.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-2.6-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "2.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-2.6-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "2.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile endpoint/package inventories, MDM, registries, SBOMs, CI/CD, cloud catalogs, SSO, procurement, and publisher lifecycle sources and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 终端与包清单、MDM、制品库、SBOM、CI/CD、云目录、SSO、采购和发布方生命周期来源，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-2.6-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "2.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Require every connector carrying source-to-production software identity, design invariant, component trust, build provenance, test result, deployment state, runtime outcome, and vulnerability response to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 从源码到生产的软件身份、设计不变量、组件信任、构建来源、测试结果、部署状态、运行结果和漏洞响应 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-2.6-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "2.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Require every connector carrying an enforceable allow, deny, contain, quarantine, require, remove, or transform decision at the closest reliable control point to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 在最近可靠控制点执行允许、拒绝、遏制、隔离、强制、移除或转换决策 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-2.6-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "2.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Pin approved component identity, version or constrained range, source repository, integrity digest and permitted application/environment in lockfiles, artifact repositories, build policy and runtime loading controls where supported.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“在锁文件、制品仓库、构建策略和可支持的运行时加载控制中，固定组件身份、版本或窄范围、来源、完整性摘要和允许的应用/环境；阻断公共仓库回退和未审查插件目录，并设置责任人与紧急更新通道。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-2.6-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "2.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-2.6-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "2.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-2.6-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "2.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-2.6-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "2.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the reconciled software and deployment authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在经过部署对账的软件权威台账中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-2.6-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "2.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Implement the explicit state machine designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-2.6-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "2.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Implement the explicit state machine observe → evaluate → decide → enforce → verify outcome → rollback/close; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-2.6-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "2.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (bi-annually, annually); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（bi-annually, annually）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-2.6-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "2.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-2.6-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "2.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-2.6-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "2.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-2.6-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "2.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in operating systems, packages, firmware, extensions, container images, dependencies, SaaS applications, and internally built releases; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 操作系统、软件包、固件、扩展、容器镜像、依赖、SaaS 应用和内部构建发布物 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-2.6-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "2.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; alert before each deadline becomes overdue.",
          "zh": "为“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-2.6-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "2.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for observe → evaluate → decide → enforce → verify outcome → rollback/close; alert before each deadline becomes overdue.",
          "zh": "为“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-2.6-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "2.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “Static linking and vendoring hide runtime package queries; dynamically generated code and customer plugins need separate trust boundaries.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“静态链接和 Vendoring 会躲过运行时包查询；动态生成代码与客户插件需要单独信任边界。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-2.6-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "2.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-2.6-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "2.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-2.6-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "2.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-2.6-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "2.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat portable binaries, dormant images, static linking, shadow SaaS, mutable packages, unsupported editions, and environment-specific authorization as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 便携二进制、休眠镜像、静态链接、影子 SaaS、可变软件包、不受支持版本及环境相关授权 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-2.6-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "2.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Treat generated and copied code, forks, vendoring, transitive dependencies, mutable tags, build plugins, feature flags, tenant logic, secrets, emergency release, and provider components as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 生成与复制代码、分叉、vendoring、传递依赖、可变标签、构建插件、功能开关、租户逻辑、秘密、紧急发布和提供商组件 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-2.6-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "2.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Treat audit-only mode, unsupported platforms, local overrides, race conditions, cached state, alternate paths, fail-open behavior, and emergency bypass as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 仅审计模式、不支持平台、本地覆盖、竞态、缓存状态、替代路径、故障开放和紧急绕过 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-2.6-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "2.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Build the same application with an approved component, an unexpected transitive dependency, a dependency-confusion name and a modified digest.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“用获批组件、意外传递依赖、依赖混淆名称和被修改摘要分别构建同一应用，验证拒绝或显式评审、制品/SBOM 关联和抽样运行一致。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-2.6-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "2.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-2.6-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "2.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 6 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、6 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-2.6-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "2.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-2.6-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "2.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the reconciled software and deployment authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以经过部署对账的软件权威台账和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-2.6-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "2.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Publish reviewed, unreviewed, reproducible, provenance-bound, vulnerable, test-failed, exception, deployed-unverified, drifted, rolled-back, and regression-protected releases with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已评审、未评审、可复现、来源绑定、存在漏洞、测试失败、例外、已部署未验证、漂移、已回滚和受回归保护发布物，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-2.6-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "2.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Publish eligible, enforcing, audit-only, failed, bypassed, excepted, rolled-back, and outcome-verified populations with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 适用、已执行、仅审计、失败、被绕过、例外、已回滚和结果已验证总体，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-2.6-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "2.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-2.6-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "2.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-2.6-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "2.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-2.6-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "2.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-2.6-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "2.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the reconciled software and deployment authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护经过部署对账的软件权威台账的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-2.6-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "2.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Restrict authority to change designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-2.6-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "2.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Restrict authority to change observe → evaluate → decide → enforce → verify outcome → rollback/close; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-2.6-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "2.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-2.6-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "2.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-2.6-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "2.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-2.6-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "2.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-2.6-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "2.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise an approved release, an unapproved binary, an unexpected dependency, a short-lived image, and a publisher end-of-support event through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 获批发布物、未批准二进制、意外依赖、短生镜像和发布方终止支持事件，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-2.6-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "2.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Run the positive control a trusted build that preserves the security invariant through deployment and runtime; exercise negative, stale, duplicate, bypass, and outage controls including a substituted dependency, unreviewed change, poisoned build input, failed security test, bypass path, vulnerable release, rollback, and regression.",
          "zh": "运行正向控制“一个把安全不变量贯穿部署与运行的可信构建”，并执行包含“依赖替换、未评审变更、构建输入污染、安全测试失败、绕过路径、漏洞发布、回滚和回归”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-2.6-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "2.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Run the positive control an approved business action that completes through the enforced path; exercise negative, stale, duplicate, bypass, and outage controls including a prohibited action, alternate path, local override, stale policy, control outage, emergency bypass, and rollback failure.",
          "zh": "运行正向控制“通过受控路径完成的一项获批业务动作”，并执行包含“禁止动作、替代路径、本地覆盖、陈旧策略、控制中断、紧急绕过和回滚失败”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-2.6-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "2.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-2.6-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "2.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-2.6-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "2.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-2.6-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "2.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-2.6-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "2.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever endpoint/package inventories, MDM, registries, SBOMs, CI/CD, cloud catalogs, SSO, procurement, and publisher lifecycle sources change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 终端与包清单、MDM、制品库、SBOM、CI/CD、云目录、SSO、采购和发布方生命周期来源 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-2.6-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "2.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Use reviewed, unreviewed, reproducible, provenance-bound, vulnerable, test-failed, exception, deployed-unverified, drifted, rolled-back, and regression-protected releases to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已评审、未评审、可复现、来源绑定、存在漏洞、测试失败、例外、已部署未验证、漂移、已回滚和受回归保护发布物 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-2.6-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "2.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Use eligible, enforcing, audit-only, failed, bypassed, excepted, rolled-back, and outcome-verified populations to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 适用、已执行、仅审计、失败、被绕过、例外、已回滚和结果已验证总体 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "2.7",
      "control": 2,
      "title_en": "Allowlist Authorized Scripts",
      "title_zh": "脚本允许清单",
      "first_ig": 3,
      "implementation_groups": [
        3
      ],
      "asset_class": "Software",
      "security_function": "Protect",
      "patterns": [
        "software_dev",
        "enforcement"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "2.1",
          "4.1"
        ],
        "variables": [
          "GV3",
          "GV8",
          "M1",
          "M2",
          "M3",
          "M4"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [
        "bi-annually",
        "annually"
      ],
      "implementation_contract": {
        "en": {
          "scope": "Include shell, PowerShell, Python, JavaScript, office macros, CI/CD definitions, infrastructure-as-code hooks and other interpreted automation wherever scripts can alter enterprise state.",
          "build": "Enforce signed scripts, content hashes, controlled repositories, constrained interpreters and approved execution paths according to platform.",
          "proof": "Execute an approved script, a one-byte-modified copy, an inline command, an encoded command and a trusted script from an untrusted path.",
          "boundary": "Mutable network shares, generated scripts, notebooks and CI variables can change behavior without changing a filename."
        },
        "zh": {
          "scope": "包括 Shell、PowerShell、Python、JavaScript、办公宏、CI/CD 定义、基础设施代码钩子，以及所有可改变企业状态的解释执行内容。",
          "build": "按平台使用脚本签名、内容哈希、受控仓库、受限解释器和批准路径；把开发编写与生产执行分开，保护签名密钥，记录签署者与评审，并提供有日志、限时的运维破窗渠道。",
          "proof": "执行批准脚本、一字节修改副本、内联命令、编码命令和从不可信路径运行的可信脚本，验证阻断/隔离与能保留内容身份、父进程的持久日志；测试密钥撤销和策略回滚。",
          "boundary": "可写网络共享、生成脚本、Notebook 和 CI 变量能在文件名不变时改变行为。"
        }
      },
      "category_counts": {
        "outcome": 7,
        "scope": 7,
        "ownership": 7,
        "data": 7,
        "integration": 7,
        "control": 7,
        "timing": 7,
        "exception": 7,
        "evidence": 7,
        "security": 7,
        "testing": 7,
        "operations": 7
      },
      "requirement_count": 84,
      "requirements": [
        {
          "code": "CIS-2.7-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "2.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Allowlist Authorized Scripts; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“脚本允许清单”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-2.7-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "2.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 2.7, official Asset Class Software, Security Function Protect, and IG3 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 2.7、官方资产类别“软件”、安全功能“保护”和首次出现的 IG3，并保存来源抓取日期。"
        },
        {
          "code": "CIS-2.7-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "2.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Include shell, PowerShell, Python, JavaScript, office macros, CI/CD definitions, infrastructure-as-code hooks and other interpreted automation wherever scripts can alter enterprise state.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“包括 Shell、PowerShell、Python、JavaScript、办公宏、CI/CD 定义、基础设施代码钩子，以及所有可改变企业状态的解释执行内容。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-2.7-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "2.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-2.7-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "2.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Allowlist Authorized Scripts to its operating object—operating systems, packages, firmware, extensions, container images, dependencies, SaaS applications, and internally built releases—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“脚本允许清单”连接到其运营对象——操作系统、软件包、固件、扩展、容器镜像、依赖、SaaS 应用和内部构建发布物——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-2.7-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "2.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "For Allowlist Authorized Scripts, express success as an observable decision over source-to-production software identity, design invariant, component trust, build provenance, test result, deployment state, runtime outcome, and vulnerability response; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“脚本允许清单”，以 从源码到生产的软件身份、设计不变量、组件信任、构建来源、测试结果、部署状态、运行结果和漏洞响应 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-2.7-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "2.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "For Allowlist Authorized Scripts, express success as an observable decision over an enforceable allow, deny, contain, quarantine, require, remove, or transform decision at the closest reliable control point; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“脚本允许清单”，以 在最近可靠控制点执行允许、拒绝、遏制、隔离、强制、移除或转换决策 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-2.7-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "2.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-2.7-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "2.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-2.7-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "2.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-2.7-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "2.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-2.7-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "2.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across portable binaries, dormant images, static linking, shadow SaaS, mutable packages, unsupported editions, and environment-specific authorization; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 便携二进制、休眠镜像、静态链接、影子 SaaS、可变软件包、不受支持版本及环境相关授权 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-2.7-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "2.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Include generated and copied code, forks, vendoring, transitive dependencies, mutable tags, build plugins, feature flags, tenant logic, secrets, emergency release, and provider components in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 生成与复制代码、分叉、vendoring、传递依赖、可变标签、构建插件、功能开关、租户逻辑、秘密、紧急发布和提供商组件 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-2.7-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "2.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Include audit-only mode, unsupported platforms, local overrides, race conditions, cached state, alternate paths, fail-open behavior, and emergency bypass in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 仅审计模式、不支持平台、本地覆盖、竞态、缓存状态、替代路径、故障开放和紧急绕过 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-2.7-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "2.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-2.7-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "2.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-2.7-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "2.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-2.7-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "2.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-2.7-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "2.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind software and application owners, platform engineering, developers, procurement, and security to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 软件与应用责任人、平台工程、开发、采购和安全团队 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-2.7-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "2.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Name who may transition designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-2.7-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "2.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Name who may transition observe → evaluate → decide → enforce → verify outcome → rollback/close, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-2.7-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "2.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-2.7-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "2.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-2.7-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "2.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV3, GV8, M1, M2, M3, M4) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV3, GV8, M1, M2, M3, M4）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-2.7-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "2.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-2.7-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "2.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the reconciled software and deployment authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把经过部署对账的软件权威台账作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-2.7-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "2.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired.",
          "zh": "对生命周期“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-2.7-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "2.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle observe → evaluate → decide → enforce → verify outcome → rollback/close.",
          "zh": "对生命周期“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-2.7-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "2.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 2.1, Safeguard 4.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 2.1、Safeguard 4.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-2.7-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "2.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-2.7-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "2.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-2.7-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "2.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-2.7-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "2.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile endpoint/package inventories, MDM, registries, SBOMs, CI/CD, cloud catalogs, SSO, procurement, and publisher lifecycle sources and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 终端与包清单、MDM、制品库、SBOM、CI/CD、云目录、SSO、采购和发布方生命周期来源，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-2.7-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "2.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Require every connector carrying source-to-production software identity, design invariant, component trust, build provenance, test result, deployment state, runtime outcome, and vulnerability response to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 从源码到生产的软件身份、设计不变量、组件信任、构建来源、测试结果、部署状态、运行结果和漏洞响应 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-2.7-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "2.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Require every connector carrying an enforceable allow, deny, contain, quarantine, require, remove, or transform decision at the closest reliable control point to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 在最近可靠控制点执行允许、拒绝、遏制、隔离、强制、移除或转换决策 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-2.7-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "2.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Enforce signed scripts, content hashes, controlled repositories, constrained interpreters and approved execution paths according to platform.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“按平台使用脚本签名、内容哈希、受控仓库、受限解释器和批准路径；把开发编写与生产执行分开，保护签名密钥，记录签署者与评审，并提供有日志、限时的运维破窗渠道。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-2.7-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "2.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-2.7-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "2.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-2.7-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "2.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-2.7-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "2.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the reconciled software and deployment authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在经过部署对账的软件权威台账中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-2.7-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "2.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Implement the explicit state machine designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-2.7-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "2.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Implement the explicit state machine observe → evaluate → decide → enforce → verify outcome → rollback/close; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-2.7-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "2.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (bi-annually, annually); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（bi-annually, annually）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-2.7-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "2.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-2.7-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "2.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-2.7-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "2.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-2.7-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "2.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in operating systems, packages, firmware, extensions, container images, dependencies, SaaS applications, and internally built releases; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 操作系统、软件包、固件、扩展、容器镜像、依赖、SaaS 应用和内部构建发布物 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-2.7-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "2.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; alert before each deadline becomes overdue.",
          "zh": "为“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-2.7-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "2.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for observe → evaluate → decide → enforce → verify outcome → rollback/close; alert before each deadline becomes overdue.",
          "zh": "为“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-2.7-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "2.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “Mutable network shares, generated scripts, notebooks and CI variables can change behavior without changing a filename.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“可写网络共享、生成脚本、Notebook 和 CI 变量能在文件名不变时改变行为。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-2.7-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "2.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-2.7-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "2.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-2.7-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "2.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-2.7-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "2.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat portable binaries, dormant images, static linking, shadow SaaS, mutable packages, unsupported editions, and environment-specific authorization as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 便携二进制、休眠镜像、静态链接、影子 SaaS、可变软件包、不受支持版本及环境相关授权 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-2.7-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "2.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Treat generated and copied code, forks, vendoring, transitive dependencies, mutable tags, build plugins, feature flags, tenant logic, secrets, emergency release, and provider components as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 生成与复制代码、分叉、vendoring、传递依赖、可变标签、构建插件、功能开关、租户逻辑、秘密、紧急发布和提供商组件 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-2.7-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "2.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Treat audit-only mode, unsupported platforms, local overrides, race conditions, cached state, alternate paths, fail-open behavior, and emergency bypass as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 仅审计模式、不支持平台、本地覆盖、竞态、缓存状态、替代路径、故障开放和紧急绕过 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-2.7-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "2.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Execute an approved script, a one-byte-modified copy, an inline command, an encoded command and a trusted script from an untrusted path.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“执行批准脚本、一字节修改副本、内联命令、编码命令和从不可信路径运行的可信脚本，验证阻断/隔离与能保留内容身份、父进程的持久日志；测试密钥撤销和策略回滚。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-2.7-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "2.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-2.7-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "2.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 6 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、6 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-2.7-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "2.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-2.7-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "2.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the reconciled software and deployment authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以经过部署对账的软件权威台账和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-2.7-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "2.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Publish reviewed, unreviewed, reproducible, provenance-bound, vulnerable, test-failed, exception, deployed-unverified, drifted, rolled-back, and regression-protected releases with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已评审、未评审、可复现、来源绑定、存在漏洞、测试失败、例外、已部署未验证、漂移、已回滚和受回归保护发布物，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-2.7-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "2.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Publish eligible, enforcing, audit-only, failed, bypassed, excepted, rolled-back, and outcome-verified populations with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 适用、已执行、仅审计、失败、被绕过、例外、已回滚和结果已验证总体，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-2.7-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "2.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-2.7-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "2.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-2.7-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "2.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-2.7-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "2.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-2.7-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "2.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the reconciled software and deployment authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护经过部署对账的软件权威台账的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-2.7-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "2.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Restrict authority to change designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-2.7-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "2.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Restrict authority to change observe → evaluate → decide → enforce → verify outcome → rollback/close; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-2.7-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "2.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-2.7-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "2.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-2.7-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "2.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-2.7-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "2.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-2.7-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "2.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise an approved release, an unapproved binary, an unexpected dependency, a short-lived image, and a publisher end-of-support event through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 获批发布物、未批准二进制、意外依赖、短生镜像和发布方终止支持事件，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-2.7-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "2.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Run the positive control a trusted build that preserves the security invariant through deployment and runtime; exercise negative, stale, duplicate, bypass, and outage controls including a substituted dependency, unreviewed change, poisoned build input, failed security test, bypass path, vulnerable release, rollback, and regression.",
          "zh": "运行正向控制“一个把安全不变量贯穿部署与运行的可信构建”，并执行包含“依赖替换、未评审变更、构建输入污染、安全测试失败、绕过路径、漏洞发布、回滚和回归”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-2.7-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "2.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Run the positive control an approved business action that completes through the enforced path; exercise negative, stale, duplicate, bypass, and outage controls including a prohibited action, alternate path, local override, stale policy, control outage, emergency bypass, and rollback failure.",
          "zh": "运行正向控制“通过受控路径完成的一项获批业务动作”，并执行包含“禁止动作、替代路径、本地覆盖、陈旧策略、控制中断、紧急绕过和回滚失败”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-2.7-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "2.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-2.7-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "2.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-2.7-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "2.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-2.7-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "2.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-2.7-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "2.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever endpoint/package inventories, MDM, registries, SBOMs, CI/CD, cloud catalogs, SSO, procurement, and publisher lifecycle sources change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 终端与包清单、MDM、制品库、SBOM、CI/CD、云目录、SSO、采购和发布方生命周期来源 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-2.7-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "2.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Use reviewed, unreviewed, reproducible, provenance-bound, vulnerable, test-failed, exception, deployed-unverified, drifted, rolled-back, and regression-protected releases to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已评审、未评审、可复现、来源绑定、存在漏洞、测试失败、例外、已部署未验证、漂移、已回滚和受回归保护发布物 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-2.7-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "2.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Use eligible, enforcing, audit-only, failed, bypassed, excepted, rolled-back, and outcome-verified populations to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 适用、已执行、仅审计、失败、被绕过、例外、已回滚和结果已验证总体 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "3.1",
      "control": 3,
      "title_en": "Establish and Maintain a Data Management Process",
      "title_zh": "数据管理流程",
      "first_ig": 1,
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Data",
      "security_function": "Govern",
      "patterns": [
        "data_lifecycle",
        "governance"
      ],
      "expanded_complexity": true,
      "cas_context": {
        "dependencies": [],
        "variables": [
          "GV10",
          "GV11",
          "GV13",
          "GV14",
          "GV15",
          "GV16",
          "M1",
          "M2",
          "M3",
          "M4",
          "M5",
          "M6"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [
        "annually"
      ],
      "implementation_contract": {
        "en": {
          "scope": "The process covers enterprise data through collection, creation, use, sharing, archival and disposal across endpoints, servers, databases, cloud, SaaS, backups, analytics, AI systems and service providers.",
          "build": "Assign a data owner and custodian model, sensitivity criteria, handling rules, minimum and maximum retention, disposal methods, approved transfer locations and exception authority.",
          "proof": "Choose representative data types and trace each rule into a real system configuration and lifecycle event.",
          "boundary": "Unknown data starts at a conservative classification."
        },
        "zh": {
          "scope": "流程覆盖数据从收集、创建、使用、共享、归档到销毁的全生命周期，横跨终端、服务器、数据库、云、SaaS、备份、分析、AI 和服务商。",
          "build": "明确数据所有者与托管者、敏感度标准、处理规则、最短和最长保留、销毁方法、批准的传输位置及例外权。",
          "proof": "挑选代表数据类型，把每条规则追到真实系统配置和生命周期事件，检查责任人确认、保留/删除任务、传输限制与例外决定。",
          "boundary": "未知数据先按保守等级处理。"
        }
      },
      "category_counts": {
        "outcome": 8,
        "scope": 8,
        "ownership": 8,
        "data": 8,
        "integration": 8,
        "control": 8,
        "timing": 8,
        "exception": 8,
        "evidence": 8,
        "security": 8,
        "testing": 8,
        "operations": 8
      },
      "requirement_count": 96,
      "requirements": [
        {
          "code": "CIS-3.1-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "3.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Establish and Maintain a Data Management Process; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“数据管理流程”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-3.1-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "3.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 3.1, official Asset Class Data, Security Function Govern, and IG1 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 3.1、官方资产类别“数据”、安全功能“治理”和首次出现的 IG1，并保存来源抓取日期。"
        },
        {
          "code": "CIS-3.1-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "3.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “The process covers enterprise data through collection, creation, use, sharing, archival and disposal across endpoints, servers, databases, cloud, SaaS, backups, analytics, AI systems and service providers.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“流程覆盖数据从收集、创建、使用、共享、归档到销毁的全生命周期，横跨终端、服务器、数据库、云、SaaS、备份、分析、AI 和服务商。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-3.1-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "3.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-3.1-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "3.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Establish and Maintain a Data Management Process to its operating object—sensitive and business data, replicas, logs, backups, exports, derived data, AI corpora, keys, and data flows—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“数据管理流程”连接到其运营对象——敏感与业务数据、副本、日志、备份、导出、派生数据、AI 语料、密钥和数据流——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-3.1-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "3.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "For Establish and Maintain a Data Management Process, express success as an observable decision over data identity, sensitivity, owner, purpose, location, flow, access, retention, copy, derivation, and disposal state; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“数据管理流程”，以 数据身份、敏感度、责任人、目的、位置、流向、访问、保留、副本、派生与销毁状态 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-3.1-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "3.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "For Establish and Maintain a Data Management Process, express success as an observable decision over a documented decision system with policy, process, procedure, accountable owner, approval, and review; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“数据管理流程”，以 包含策略、流程、程序、责任人、审批和复核的文档化决策系统 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-3.1-OUT-08",
          "local_code": "OUT-08",
          "display_code": "O08",
          "safeguard_id": "3.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "For the expanded Establish and Maintain a Data Management Process scope, resolve conflicts among security, safety, privacy, legal, availability, customer, and operational objectives through an explicit risk decision.",
          "zh": "对“数据管理流程”的扩展范围，通过显式风险决策解决安全、安全生产、隐私、法律、可用性、客户和运营目标冲突。"
        },
        {
          "code": "CIS-3.1-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "3.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-3.1-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "3.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-3.1-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "3.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-3.1-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "3.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-3.1-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "3.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across unknown classification, encrypted or tokenized copies, cross-region replicas, immutable backups, derived data, litigation holds, and provider deletion limits; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 未知分类、加密或令牌化副本、跨地域副本、不可变备份、派生数据、诉讼保全及提供商删除限制 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-3.1-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "3.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Include unstructured and derived data, logs, caches, backups, exports, client-side copies, cross-region processing, AI corpora, holds, and provider residues in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 非结构化与派生数据、日志、缓存、备份、导出、客户端副本、跨地域处理、AI 语料、保全和提供商残留 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-3.1-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "3.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Include missing policy clauses, conflicting authorities, local deviations, obsolete documentation, and decisions made outside the governed workflow in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 策略条款缺失、权限冲突、本地偏离、文档过期及绕过治理流程的决策 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-3.1-SCP-08",
          "local_code": "SCP-08",
          "display_code": "P08",
          "safeguard_id": "3.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Define nested scope at enterprise, business service, tenant, environment, platform, object, identity, data set, and transaction levels; prohibit a parent result from hiding a failing child.",
          "zh": "按企业、业务服务、租户、环境、平台、对象、身份、数据集和交易定义嵌套范围，禁止父级结果遮蔽失败子级。"
        },
        {
          "code": "CIS-3.1-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "3.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-3.1-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "3.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-3.1-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "3.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-3.1-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "3.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-3.1-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "3.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind data owners and custodians, product teams, privacy, legal, security, records management, and providers to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 数据责任人与托管方、产品团队、隐私、法务、安全、档案管理和服务提供商 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-3.1-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "3.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Name who may transition created/collected → classified → approved use and flow → retained/held → disposed with verification, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-3.1-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "3.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Name who may transition draft → reviewed → approved → effective → exception/withdrawn → superseded, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-3.1-OWN-08",
          "local_code": "OWN-08",
          "display_code": "W08",
          "safeguard_id": "3.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Model delegated authority, quorum or dual approval where warranted, escalation deadlines, provider handoffs, conflict resolution, and executive risk acceptance.",
          "zh": "建模委派权限、必要时的双人或法定人数审批、升级期限、提供商交接、冲突解决和管理层风险接受。"
        },
        {
          "code": "CIS-3.1-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "3.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-3.1-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "3.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-3.1-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "3.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV10, GV11, GV13, GV14, GV15, GV16, M1, M2, M3, M4, M5, M6) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV10, GV11, GV13, GV14, GV15, GV16, M1, M2, M3, M4, M5, M6）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-3.1-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "3.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-3.1-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "3.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the data inventory, classification, ownership, and lifecycle authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把数据清单、分类、所有权与生命周期权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-3.1-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "3.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle created/collected → classified → approved use and flow → retained/held → disposed with verification.",
          "zh": "对生命周期“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-3.1-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "3.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle draft → reviewed → approved → effective → exception/withdrawn → superseded.",
          "zh": "对生命周期“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-3.1-DAT-08",
          "local_code": "DAT-08",
          "display_code": "D08",
          "safeguard_id": "3.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Version schemas and state transitions with migration, backfill, deduplication, lineage, historical denominator, deletion, and rollback semantics.",
          "zh": "对模式和状态转换做版本管理，定义迁移、回填、去重、血缘、历史分母、删除和回滚语义。"
        },
        {
          "code": "CIS-3.1-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "3.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for no explicit predecessor in the pinned CAS page; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 固定 CAS 页面没有列出显式前置项 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-3.1-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "3.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-3.1-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "3.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-3.1-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "3.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-3.1-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "3.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile data catalogs, schemas, DLP discovery, cloud/SaaS APIs, owner attestations, flow records, backup catalogs, and legal/privacy schedules and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 数据目录、模式、DLP 发现、云/SaaS API、责任人确认、流向记录、备份目录及法律与隐私期限，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-3.1-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "3.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Require every connector carrying data identity, sensitivity, owner, purpose, location, flow, access, retention, copy, derivation, and disposal state to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 数据身份、敏感度、责任人、目的、位置、流向、访问、保留、副本、派生与销毁状态 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-3.1-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "3.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Require every connector carrying a documented decision system with policy, process, procedure, accountable owner, approval, and review to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 包含策略、流程、程序、责任人、审批和复核的文档化决策系统 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-3.1-INT-08",
          "local_code": "INT-08",
          "display_code": "I08",
          "safeguard_id": "3.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Define consistency rules across disagreeing sources, source precedence, confidence, reconciliation queues, dead-letter handling, reprocessing, and end-to-end trace identity.",
          "zh": "定义冲突来源的一致性、优先级、置信度、对账队列、死信、重处理和端到端追踪身份。"
        },
        {
          "code": "CIS-3.1-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "3.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Assign a data owner and custodian model, sensitivity criteria, handling rules, minimum and maximum retention, disposal methods, approved transfer locations and exception authority.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“明确数据所有者与托管者、敏感度标准、处理规则、最短和最长保留、销毁方法、批准的传输位置及例外权。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-3.1-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "3.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-3.1-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "3.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-3.1-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "3.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-3.1-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "3.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the data inventory, classification, ownership, and lifecycle authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在数据清单、分类、所有权与生命周期权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-3.1-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "3.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Implement the explicit state machine created/collected → classified → approved use and flow → retained/held → disposed with verification; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-3.1-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "3.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Implement the explicit state machine draft → reviewed → approved → effective → exception/withdrawn → superseded; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-3.1-CTL-08",
          "local_code": "CTL-08",
          "display_code": "C08",
          "safeguard_id": "3.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Specify concurrent decisions, partial success, compensating transactions, repeated requests, stale policy, dependency outage, and recovery from an interrupted state transition.",
          "zh": "定义并发决策、部分成功、补偿事务、重复请求、陈旧策略、依赖中断和中途状态转换恢复。"
        },
        {
          "code": "CIS-3.1-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "3.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (annually); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（annually）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-3.1-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "3.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-3.1-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "3.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-3.1-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "3.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-3.1-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "3.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in sensitive and business data, replicas, logs, backups, exports, derived data, AI corpora, keys, and data flows; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 敏感与业务数据、副本、日志、备份、导出、派生数据、AI 语料、密钥和数据流 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-3.1-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "3.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for created/collected → classified → approved use and flow → retained/held → disposed with verification; alert before each deadline becomes overdue.",
          "zh": "为“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-3.1-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "3.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for draft → reviewed → approved → effective → exception/withdrawn → superseded; alert before each deadline becomes overdue.",
          "zh": "为“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-3.1-TIM-08",
          "local_code": "TIM-08",
          "display_code": "T08",
          "safeguard_id": "3.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Allocate an end-to-end SLO budget across discovery, collection, processing, approval, enforcement, verification, and closure; prioritize overdue work by consequence and exposure.",
          "zh": "把端到端 SLO 预算分配到发现、采集、处理、审批、执行、验证和关闭，并按后果与暴露排列逾期工作。"
        },
        {
          "code": "CIS-3.1-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "3.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “Unknown data starts at a conservative classification.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“未知数据先按保守等级处理。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-3.1-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "3.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-3.1-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "3.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-3.1-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "3.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-3.1-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "3.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat unknown classification, encrypted or tokenized copies, cross-region replicas, immutable backups, derived data, litigation holds, and provider deletion limits as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 未知分类、加密或令牌化副本、跨地域副本、不可变备份、派生数据、诉讼保全及提供商删除限制 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-3.1-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "3.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Treat unstructured and derived data, logs, caches, backups, exports, client-side copies, cross-region processing, AI corpora, holds, and provider residues as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 非结构化与派生数据、日志、缓存、备份、导出、客户端副本、跨地域处理、AI 语料、保全和提供商残留 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-3.1-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "3.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Treat missing policy clauses, conflicting authorities, local deviations, obsolete documentation, and decisions made outside the governed workflow as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 策略条款缺失、权限冲突、本地偏离、文档过期及绕过治理流程的决策 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-3.1-EXC-08",
          "local_code": "EXC-08",
          "display_code": "X08",
          "safeguard_id": "3.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Exercise compound failures where an exception, stale source, provider outage, unavailable owner, and degraded control overlap; define one safe command and one accountable decision.",
          "zh": "演练例外、陈旧来源、提供商中断、责任人不可用和控制降级同时出现的复合故障，明确一条安全指令和一个责任决策。"
        },
        {
          "code": "CIS-3.1-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "3.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Choose representative data types and trace each rule into a real system configuration and lifecycle event.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“挑选代表数据类型，把每条规则追到真实系统配置和生命周期事件，检查责任人确认、保留/删除任务、传输限制与例外决定。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-3.1-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "3.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-3.1-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "3.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 12 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、12 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-3.1-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "3.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-3.1-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "3.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the data inventory, classification, ownership, and lifecycle authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以数据清单、分类、所有权与生命周期权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-3.1-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "3.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Publish known, unknown, classified, ownerless, over-retained, prematurely deleted, unapproved copy, blocked flow, held, and disposal-verified data sets with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已知、未知、已分类、无责任人、超期保留、过早删除、未批准副本、被阻断流、保全及销毁已验证数据集，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-3.1-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "3.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Publish clause coverage, owner and reviewer completeness, approval age, triggered reviews, deviations, overdue actions, and superseded versions still in use with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 条款覆盖、责任人与复核人完整性、批准年龄、触发式复核、偏离、逾期行动及仍在使用的旧版本，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-3.1-EVD-08",
          "local_code": "EVD-08",
          "display_code": "E08",
          "safeguard_id": "3.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Require an independent party to reconstruct the decision from source receipts and reproduce the population, state transition, calculation, test result, exception, and final closure.",
          "zh": "要求独立人员使用来源回执重建决策，并复现总体、状态转换、计算、测试结果、例外和最终关闭。"
        },
        {
          "code": "CIS-3.1-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "3.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-3.1-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "3.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-3.1-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "3.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-3.1-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "3.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-3.1-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "3.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the data inventory, classification, ownership, and lifecycle authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护数据清单、分类、所有权与生命周期权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-3.1-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "3.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Restrict authority to change created/collected → classified → approved use and flow → retained/held → disposed with verification; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-3.1-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "3.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Restrict authority to change draft → reviewed → approved → effective → exception/withdrawn → superseded; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-3.1-SEC-08",
          "local_code": "SEC-08",
          "display_code": "S08",
          "safeguard_id": "3.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Threat-model the implementation system itself: forged evidence, poisoned inventory, privilege abuse, cross-tenant confusion, policy rollback, audit deletion, denial of service, and recovery compromise.",
          "zh": "威胁建模实施系统自身：伪造证据、污染清单、权限滥用、跨租户混淆、策略回滚、审计删除、拒绝服务和恢复失陷。"
        },
        {
          "code": "CIS-3.1-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "3.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-3.1-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "3.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-3.1-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "3.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-3.1-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "3.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-3.1-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "3.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise approved and unapproved copies, allowed and denied readers, retention boundaries, deletion verification, key loss, and cross-boundary transfers through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 获批与未批准副本、允许与拒绝读取、保留边界、删除验证、密钥丢失和跨边界传输，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-3.1-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "3.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Run the positive control an approved data set following its declared use, access, transfer, retention, and disposal path; exercise negative, stale, duplicate, bypass, and outage controls including an unknown or misclassified copy, forbidden reader or flow, early deletion, expired retention, failed disposal, and provider residue.",
          "zh": "运行正向控制“按声明用途、访问、传输、保留和销毁路径流转的获批数据集”，并执行包含“未知或误分类副本、禁止读取者或流向、过早删除、保留过期、销毁失败和提供商残留”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-3.1-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "3.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Run the positive control an approved current process used for a representative decision; exercise negative, stale, duplicate, bypass, and outage controls including an obsolete version, missing approver, undocumented deviation, overdue review, and bypassed workflow.",
          "zh": "运行正向控制“使用当前获批流程完成一项代表性决策”，并执行包含“旧版本、审批人缺失、未记录偏离、逾期复核和绕过流程”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-3.1-TST-08",
          "local_code": "TST-08",
          "display_code": "V08",
          "safeguard_id": "3.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Build a pairwise platform-and-failure matrix, then add high-consequence multi-factor cases, historical regression, source substitution, red-team challenge, and assessor replay.",
          "zh": "建立平台—故障两两组合矩阵，再加入高后果多因素案例、历史回归、来源替换、红队挑战和评估方重放。"
        },
        {
          "code": "CIS-3.1-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "3.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-3.1-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "3.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-3.1-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "3.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-3.1-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "3.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-3.1-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "3.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever data catalogs, schemas, DLP discovery, cloud/SaaS APIs, owner attestations, flow records, backup catalogs, and legal/privacy schedules change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 数据目录、模式、DLP 发现、云/SaaS API、责任人确认、流向记录、备份目录及法律与隐私期限 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-3.1-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "3.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Use known, unknown, classified, ownerless, over-retained, prematurely deleted, unapproved copy, blocked flow, held, and disposal-verified data sets to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已知、未知、已分类、无责任人、超期保留、过早删除、未批准副本、被阻断流、保全及销毁已验证数据集 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-3.1-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "3.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Use clause coverage, owner and reviewer completeness, approval age, triggered reviews, deviations, overdue actions, and superseded versions still in use to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 条款覆盖、责任人与复核人完整性、批准年龄、触发式复核、偏离、逾期行动及仍在使用的旧版本 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-3.1-OPS-08",
          "local_code": "OPS-08",
          "display_code": "R08",
          "safeguard_id": "3.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Use canary deployment, kill criteria, rollback, backlog burn-down, exception reduction, source-quality targets, quarterly design review, and a measurable retirement plan.",
          "zh": "采用金丝雀、停止标准、回滚、积压燃尽、例外缩减、来源质量目标、季度设计复核和可量化退役计划。"
        }
      ]
    },
    {
      "id": "3.2",
      "control": 3,
      "title_en": "Establish and Maintain a Data Inventory",
      "title_zh": "数据清单",
      "first_ig": 1,
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Data",
      "security_function": "Identify",
      "patterns": [
        "data_lifecycle",
        "inventory"
      ],
      "expanded_complexity": true,
      "cas_context": {
        "dependencies": [
          "1.1"
        ],
        "variables": [
          "GV1",
          "GV11",
          "GV12",
          "M1",
          "M2",
          "M3",
          "M4",
          "M5",
          "M6",
          "M7",
          "M8",
          "M9"
        ],
        "metric_branches": 2,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [
        "annually"
      ],
      "implementation_contract": {
        "en": {
          "scope": "Inventory sensitive data sets and stores, their owners, purposes, classification, systems, regions, flows, processors, retention and deletion state; use a stable data-set or processing-activity identity as the counting unit, with individual rows and files retained as subordinate evidence.",
          "build": "Combine owner attestations with database/catalog scans, cloud and SaaS APIs, DLP discovery, schemas and data-flow records.",
          "proof": "Seed labelled sensitive data into an approved store and an unapproved copy, then prove discovery, correct classification, owner routing and cleanup.",
          "boundary": "Encrypted or tokenized data remains in scope because keys, re-identification or use may preserve sensitivity."
        },
        "zh": {
          "scope": "清点敏感数据集和存储位置、责任人、目的、分类、系统、地区、流向、处理方、保留与删除状态；用稳定的数据集或处理活动身份，不逐行逐文件凑数。",
          "build": "把责任人声明与数据库/目录扫描、云和 SaaS API、DLP、Schema 和数据流记录结合，关联资产/服务台账与管理流程，优先敏感数据；创建、移动时更新，至少每年全量对账。",
          "proof": "在批准存储和未批准副本各放一份有标签的敏感测试数据，验证发现、分类、路由责任人和清理。",
          "boundary": "加密或 Token 化后，只要能用密钥、关联或业务用途重新识别，仍在范围。"
        }
      },
      "category_counts": {
        "outcome": 8,
        "scope": 8,
        "ownership": 8,
        "data": 8,
        "integration": 8,
        "control": 8,
        "timing": 8,
        "exception": 8,
        "evidence": 8,
        "security": 8,
        "testing": 8,
        "operations": 8
      },
      "requirement_count": 96,
      "requirements": [
        {
          "code": "CIS-3.2-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "3.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Establish and Maintain a Data Inventory; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“数据清单”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-3.2-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "3.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 3.2, official Asset Class Data, Security Function Identify, and IG1 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 3.2、官方资产类别“数据”、安全功能“识别”和首次出现的 IG1，并保存来源抓取日期。"
        },
        {
          "code": "CIS-3.2-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "3.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Inventory sensitive data sets and stores, their owners, purposes, classification, systems, regions, flows, processors, retention and deletion state; use a stable data-set or processing-activity identity as the counting unit, with individual rows and files retained as subordinate evidence.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“清点敏感数据集和存储位置、责任人、目的、分类、系统、地区、流向、处理方、保留与删除状态；用稳定的数据集或处理活动身份，不逐行逐文件凑数。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-3.2-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "3.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-3.2-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "3.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Establish and Maintain a Data Inventory to its operating object—sensitive and business data, replicas, logs, backups, exports, derived data, AI corpora, keys, and data flows—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“数据清单”连接到其运营对象——敏感与业务数据、副本、日志、备份、导出、派生数据、AI 语料、密钥和数据流——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-3.2-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "3.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "For Establish and Maintain a Data Inventory, express success as an observable decision over data identity, sensitivity, owner, purpose, location, flow, access, retention, copy, derivation, and disposal state; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“数据清单”，以 数据身份、敏感度、责任人、目的、位置、流向、访问、保留、副本、派生与销毁状态 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-3.2-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "3.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "For Establish and Maintain a Data Inventory, express success as an observable decision over observed, approved, unapproved, ownerless, stale, duplicate, and retired object identity; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“数据清单”，以 已观测、已批准、未批准、无责任人、陈旧、重复和已退役对象身份 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-3.2-OUT-08",
          "local_code": "OUT-08",
          "display_code": "O08",
          "safeguard_id": "3.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "For the expanded Establish and Maintain a Data Inventory scope, resolve conflicts among security, safety, privacy, legal, availability, customer, and operational objectives through an explicit risk decision.",
          "zh": "对“数据清单”的扩展范围，通过显式风险决策解决安全、安全生产、隐私、法律、可用性、客户和运营目标冲突。"
        },
        {
          "code": "CIS-3.2-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "3.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-3.2-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "3.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-3.2-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "3.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-3.2-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "3.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-3.2-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "3.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across unknown classification, encrypted or tokenized copies, cross-region replicas, immutable backups, derived data, litigation holds, and provider deletion limits; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 未知分类、加密或令牌化副本、跨地域副本、不可变备份、派生数据、诉讼保全及提供商删除限制 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-3.2-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "3.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Include unstructured and derived data, logs, caches, backups, exports, client-side copies, cross-region processing, AI corpora, holds, and provider residues in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 非结构化与派生数据、日志、缓存、备份、导出、客户端副本、跨地域处理、AI 语料、保全和提供商残留 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-3.2-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "3.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Include dormant, ephemeral, disconnected, externally managed, provider-held, aliased, cloned, and cross-tenant objects in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 休眠、短生、离线、外部托管、提供商持有、别名、克隆和跨租户对象 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-3.2-SCP-08",
          "local_code": "SCP-08",
          "display_code": "P08",
          "safeguard_id": "3.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Define nested scope at enterprise, business service, tenant, environment, platform, object, identity, data set, and transaction levels; prohibit a parent result from hiding a failing child.",
          "zh": "按企业、业务服务、租户、环境、平台、对象、身份、数据集和交易定义嵌套范围，禁止父级结果遮蔽失败子级。"
        },
        {
          "code": "CIS-3.2-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "3.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-3.2-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "3.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-3.2-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "3.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-3.2-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "3.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-3.2-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "3.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind data owners and custodians, product teams, privacy, legal, security, records management, and providers to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 数据责任人与托管方、产品团队、隐私、法务、安全、档案管理和服务提供商 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-3.2-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "3.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Name who may transition created/collected → classified → approved use and flow → retained/held → disposed with verification, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-3.2-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "3.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Name who may transition discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-3.2-OWN-08",
          "local_code": "OWN-08",
          "display_code": "W08",
          "safeguard_id": "3.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Model delegated authority, quorum or dual approval where warranted, escalation deadlines, provider handoffs, conflict resolution, and executive risk acceptance.",
          "zh": "建模委派权限、必要时的双人或法定人数审批、升级期限、提供商交接、冲突解决和管理层风险接受。"
        },
        {
          "code": "CIS-3.2-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "3.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-3.2-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "3.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-3.2-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "3.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV1, GV11, GV12, M1, M2, M3, M4, M5, M6, M7, M8, M9) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV1, GV11, GV12, M1, M2, M3, M4, M5, M6, M7, M8, M9）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-3.2-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "3.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-3.2-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "3.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the data inventory, classification, ownership, and lifecycle authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把数据清单、分类、所有权与生命周期权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-3.2-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "3.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle created/collected → classified → approved use and flow → retained/held → disposed with verification.",
          "zh": "对生命周期“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-3.2-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "3.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence.",
          "zh": "对生命周期“发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-3.2-DAT-08",
          "local_code": "DAT-08",
          "display_code": "D08",
          "safeguard_id": "3.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Version schemas and state transitions with migration, backfill, deduplication, lineage, historical denominator, deletion, and rollback semantics.",
          "zh": "对模式和状态转换做版本管理，定义迁移、回填、去重、血缘、历史分母、删除和回滚语义。"
        },
        {
          "code": "CIS-3.2-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "3.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 1.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 1.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-3.2-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "3.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-3.2-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "3.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-3.2-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "3.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-3.2-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "3.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile data catalogs, schemas, DLP discovery, cloud/SaaS APIs, owner attestations, flow records, backup catalogs, and legal/privacy schedules and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 数据目录、模式、DLP 发现、云/SaaS API、责任人确认、流向记录、备份目录及法律与隐私期限，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-3.2-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "3.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Require every connector carrying data identity, sensitivity, owner, purpose, location, flow, access, retention, copy, derivation, and disposal state to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 数据身份、敏感度、责任人、目的、位置、流向、访问、保留、副本、派生与销毁状态 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-3.2-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "3.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Require every connector carrying observed, approved, unapproved, ownerless, stale, duplicate, and retired object identity to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 已观测、已批准、未批准、无责任人、陈旧、重复和已退役对象身份 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-3.2-INT-08",
          "local_code": "INT-08",
          "display_code": "I08",
          "safeguard_id": "3.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Define consistency rules across disagreeing sources, source precedence, confidence, reconciliation queues, dead-letter handling, reprocessing, and end-to-end trace identity.",
          "zh": "定义冲突来源的一致性、优先级、置信度、对账队列、死信、重处理和端到端追踪身份。"
        },
        {
          "code": "CIS-3.2-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "3.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Combine owner attestations with database/catalog scans, cloud and SaaS APIs, DLP discovery, schemas and data-flow records.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“把责任人声明与数据库/目录扫描、云和 SaaS API、DLP、Schema 和数据流记录结合，关联资产/服务台账与管理流程，优先敏感数据；创建、移动时更新，至少每年全量对账。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-3.2-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "3.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-3.2-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "3.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-3.2-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "3.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-3.2-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "3.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the data inventory, classification, ownership, and lifecycle authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在数据清单、分类、所有权与生命周期权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-3.2-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "3.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Implement the explicit state machine created/collected → classified → approved use and flow → retained/held → disposed with verification; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-3.2-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "3.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Implement the explicit state machine discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-3.2-CTL-08",
          "local_code": "CTL-08",
          "display_code": "C08",
          "safeguard_id": "3.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Specify concurrent decisions, partial success, compensating transactions, repeated requests, stale policy, dependency outage, and recovery from an interrupted state transition.",
          "zh": "定义并发决策、部分成功、补偿事务、重复请求、陈旧策略、依赖中断和中途状态转换恢复。"
        },
        {
          "code": "CIS-3.2-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "3.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (annually); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（annually）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-3.2-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "3.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-3.2-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "3.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-3.2-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "3.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-3.2-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "3.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in sensitive and business data, replicas, logs, backups, exports, derived data, AI corpora, keys, and data flows; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 敏感与业务数据、副本、日志、备份、导出、派生数据、AI 语料、密钥和数据流 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-3.2-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "3.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for created/collected → classified → approved use and flow → retained/held → disposed with verification; alert before each deadline becomes overdue.",
          "zh": "为“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-3.2-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "3.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence; alert before each deadline becomes overdue.",
          "zh": "为“发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-3.2-TIM-08",
          "local_code": "TIM-08",
          "display_code": "T08",
          "safeguard_id": "3.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Allocate an end-to-end SLO budget across discovery, collection, processing, approval, enforcement, verification, and closure; prioritize overdue work by consequence and exposure.",
          "zh": "把端到端 SLO 预算分配到发现、采集、处理、审批、执行、验证和关闭，并按后果与暴露排列逾期工作。"
        },
        {
          "code": "CIS-3.2-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "3.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “Encrypted or tokenized data remains in scope because keys, re-identification or use may preserve sensitivity.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“加密或 Token 化后，只要能用密钥、关联或业务用途重新识别，仍在范围。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-3.2-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "3.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-3.2-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "3.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-3.2-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "3.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-3.2-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "3.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat unknown classification, encrypted or tokenized copies, cross-region replicas, immutable backups, derived data, litigation holds, and provider deletion limits as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 未知分类、加密或令牌化副本、跨地域副本、不可变备份、派生数据、诉讼保全及提供商删除限制 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-3.2-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "3.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Treat unstructured and derived data, logs, caches, backups, exports, client-side copies, cross-region processing, AI corpora, holds, and provider residues as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 非结构化与派生数据、日志、缓存、备份、导出、客户端副本、跨地域处理、AI 语料、保全和提供商残留 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-3.2-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "3.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Treat dormant, ephemeral, disconnected, externally managed, provider-held, aliased, cloned, and cross-tenant objects as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 休眠、短生、离线、外部托管、提供商持有、别名、克隆和跨租户对象 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-3.2-EXC-08",
          "local_code": "EXC-08",
          "display_code": "X08",
          "safeguard_id": "3.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Exercise compound failures where an exception, stale source, provider outage, unavailable owner, and degraded control overlap; define one safe command and one accountable decision.",
          "zh": "演练例外、陈旧来源、提供商中断、责任人不可用和控制降级同时出现的复合故障，明确一条安全指令和一个责任决策。"
        },
        {
          "code": "CIS-3.2-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "3.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Seed labelled sensitive data into an approved store and an unapproved copy, then prove discovery, correct classification, owner routing and cleanup.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“在批准存储和未批准副本各放一份有标签的敏感测试数据，验证发现、分类、路由责任人和清理。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-3.2-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "3.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-3.2-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "3.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 2 pinned CAS metric branch(es), 12 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 2 个指标分支、12 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-3.2-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "3.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-3.2-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "3.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the data inventory, classification, ownership, and lifecycle authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以数据清单、分类、所有权与生命周期权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-3.2-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "3.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Publish known, unknown, classified, ownerless, over-retained, prematurely deleted, unapproved copy, blocked flow, held, and disposal-verified data sets with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已知、未知、已分类、无责任人、超期保留、过早删除、未批准副本、被阻断流、保全及销毁已验证数据集，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-3.2-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "3.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Publish matched, missing, duplicate, stale, ownerless, unapproved, unevaluable, and retired-without-proof counts with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 匹配、缺失、重复、陈旧、无责任人、未批准、不可评估及无证明退役数量，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-3.2-EVD-08",
          "local_code": "EVD-08",
          "display_code": "E08",
          "safeguard_id": "3.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Require an independent party to reconstruct the decision from source receipts and reproduce the population, state transition, calculation, test result, exception, and final closure.",
          "zh": "要求独立人员使用来源回执重建决策，并复现总体、状态转换、计算、测试结果、例外和最终关闭。"
        },
        {
          "code": "CIS-3.2-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "3.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-3.2-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "3.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-3.2-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "3.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-3.2-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "3.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-3.2-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "3.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the data inventory, classification, ownership, and lifecycle authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护数据清单、分类、所有权与生命周期权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-3.2-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "3.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Restrict authority to change created/collected → classified → approved use and flow → retained/held → disposed with verification; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-3.2-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "3.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Restrict authority to change discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-3.2-SEC-08",
          "local_code": "SEC-08",
          "display_code": "S08",
          "safeguard_id": "3.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Threat-model the implementation system itself: forged evidence, poisoned inventory, privilege abuse, cross-tenant confusion, policy rollback, audit deletion, denial of service, and recovery compromise.",
          "zh": "威胁建模实施系统自身：伪造证据、污染清单、权限滥用、跨租户混淆、策略回滚、审计删除、拒绝服务和恢复失陷。"
        },
        {
          "code": "CIS-3.2-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "3.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-3.2-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "3.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-3.2-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "3.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-3.2-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "3.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-3.2-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "3.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise approved and unapproved copies, allowed and denied readers, retention boundaries, deletion verification, key loss, and cross-boundary transfers through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 获批与未批准副本、允许与拒绝读取、保留边界、删除验证、密钥丢失和跨边界传输，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-3.2-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "3.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Run the positive control an approved data set following its declared use, access, transfer, retention, and disposal path; exercise negative, stale, duplicate, bypass, and outage controls including an unknown or misclassified copy, forbidden reader or flow, early deletion, expired retention, failed disposal, and provider residue.",
          "zh": "运行正向控制“按声明用途、访问、传输、保留和销毁路径流转的获批数据集”，并执行包含“未知或误分类副本、禁止读取者或流向、过早删除、保留过期、销毁失败和提供商残留”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-3.2-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "3.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Run the positive control a seeded approved object reconciled from two independent sources; exercise negative, stale, duplicate, bypass, and outage controls including an unknown object, duplicate identity, stale record, vanished object, failed source, and cross-tenant collision.",
          "zh": "运行正向控制“从两个独立来源对账的一项植入已批准对象”，并执行包含“未知对象、重复身份、陈旧记录、突然消失对象、失效来源和跨租户碰撞”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-3.2-TST-08",
          "local_code": "TST-08",
          "display_code": "V08",
          "safeguard_id": "3.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Build a pairwise platform-and-failure matrix, then add high-consequence multi-factor cases, historical regression, source substitution, red-team challenge, and assessor replay.",
          "zh": "建立平台—故障两两组合矩阵，再加入高后果多因素案例、历史回归、来源替换、红队挑战和评估方重放。"
        },
        {
          "code": "CIS-3.2-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "3.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-3.2-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "3.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-3.2-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "3.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-3.2-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "3.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-3.2-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "3.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever data catalogs, schemas, DLP discovery, cloud/SaaS APIs, owner attestations, flow records, backup catalogs, and legal/privacy schedules change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 数据目录、模式、DLP 发现、云/SaaS API、责任人确认、流向记录、备份目录及法律与隐私期限 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-3.2-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "3.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Use known, unknown, classified, ownerless, over-retained, prematurely deleted, unapproved copy, blocked flow, held, and disposal-verified data sets to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已知、未知、已分类、无责任人、超期保留、过早删除、未批准副本、被阻断流、保全及销毁已验证数据集 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-3.2-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "3.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Use matched, missing, duplicate, stale, ownerless, unapproved, unevaluable, and retired-without-proof counts to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 匹配、缺失、重复、陈旧、无责任人、未批准、不可评估及无证明退役数量 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-3.2-OPS-08",
          "local_code": "OPS-08",
          "display_code": "R08",
          "safeguard_id": "3.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Use canary deployment, kill criteria, rollback, backlog burn-down, exception reduction, source-quality targets, quarterly design review, and a measurable retirement plan.",
          "zh": "采用金丝雀、停止标准、回滚、积压燃尽、例外缩减、来源质量目标、季度设计复核和可量化退役计划。"
        }
      ]
    },
    {
      "id": "3.3",
      "control": 3,
      "title_en": "Configure Data Access Control Lists",
      "title_zh": "数据访问权限",
      "first_ig": 1,
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Data",
      "security_function": "Protect",
      "patterns": [
        "data_lifecycle",
        "identity",
        "enforcement"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "3.2",
          "4.1",
          "5.1"
        ],
        "variables": [
          "GV1",
          "GV3",
          "GV12",
          "GV13",
          "GV14",
          "GV17",
          "GV22",
          "M1",
          "M2",
          "M3",
          "M4",
          "M5",
          "M6",
          "M7",
          "M8"
        ],
        "metric_branches": 2,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "The access population includes human, service, workload, support and provider identities reaching sensitive data through files, databases, APIs, applications, analytics, backups and administrative planes.",
          "build": "Translate owner-approved need-to-know into group, role, ACL, row/column, object and key policies at the authoritative control points.",
          "proof": "For sampled data sets, enumerate effective permissions and reconcile them to approved identities.",
          "boundary": "Counts of mapped data and account types are not interchangeable, despite the CAS formula."
        },
        "zh": {
          "scope": "访问总体包含通过文件、数据库、API、应用、分析、备份和管理面接触敏感数据的人、服务、工作负载、支持和服务商身份。",
          "build": "把数据所有者批准的知情需要，落实为组、角色、ACL、行列、对象和密钥策略；清除直接授权，分开系统管理与数据使用，审查继承/公开访问，使入转离与应急访问同步更新每一层。",
          "proof": "对抽样数据集枚举有效权限，并与批准身份对账。",
          "boundary": "CAS 把“映射数据数”和“账户类型数”相除，量纲不同。"
        }
      },
      "category_counts": {
        "outcome": 8,
        "scope": 8,
        "ownership": 8,
        "data": 8,
        "integration": 8,
        "control": 8,
        "timing": 8,
        "exception": 8,
        "evidence": 8,
        "security": 8,
        "testing": 8,
        "operations": 8
      },
      "requirement_count": 96,
      "requirements": [
        {
          "code": "CIS-3.3-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "3.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Configure Data Access Control Lists; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“数据访问权限”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-3.3-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "3.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 3.3, official Asset Class Data, Security Function Protect, and IG1 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 3.3、官方资产类别“数据”、安全功能“保护”和首次出现的 IG1，并保存来源抓取日期。"
        },
        {
          "code": "CIS-3.3-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "3.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “The access population includes human, service, workload, support and provider identities reaching sensitive data through files, databases, APIs, applications, analytics, backups and administrative planes.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“访问总体包含通过文件、数据库、API、应用、分析、备份和管理面接触敏感数据的人、服务、工作负载、支持和服务商身份。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-3.3-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "3.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-3.3-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "3.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Configure Data Access Control Lists to its operating object—sensitive and business data, replicas, logs, backups, exports, derived data, AI corpora, keys, and data flows—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“数据访问权限”连接到其运营对象——敏感与业务数据、副本、日志、备份、导出、派生数据、AI 语料、密钥和数据流——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-3.3-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "3.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "For Configure Data Access Control Lists, express success as an observable decision over data identity, sensitivity, owner, purpose, location, flow, access, retention, copy, derivation, and disposal state; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“数据访问权限”，以 数据身份、敏感度、责任人、目的、位置、流向、访问、保留、副本、派生与销毁状态 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-3.3-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "3.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "For Configure Data Access Control Lists, express success as an observable decision over effective identity, authentication, authorization, privilege, session, and revocation state across every access path; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“数据访问权限”，以 所有访问路径上的实际身份、认证、授权、权限、会话和撤销状态 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-3.3-OUT-08",
          "local_code": "OUT-08",
          "display_code": "O08",
          "safeguard_id": "3.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "For Configure Data Access Control Lists, express success as an observable decision over an enforceable allow, deny, contain, quarantine, require, remove, or transform decision at the closest reliable control point; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“数据访问权限”，以 在最近可靠控制点执行允许、拒绝、遏制、隔离、强制、移除或转换决策 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-3.3-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "3.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-3.3-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "3.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-3.3-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "3.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-3.3-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "3.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-3.3-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "3.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across unknown classification, encrypted or tokenized copies, cross-region replicas, immutable backups, derived data, litigation holds, and provider deletion limits; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 未知分类、加密或令牌化副本、跨地域副本、不可变备份、派生数据、诉讼保全及提供商删除限制 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-3.3-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "3.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Include unstructured and derived data, logs, caches, backups, exports, client-side copies, cross-region processing, AI corpora, holds, and provider residues in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 非结构化与派生数据、日志、缓存、备份、导出、客户端副本、跨地域处理、AI 语料、保全和提供商残留 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-3.3-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "3.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Include shared and service identities, nested groups, direct grants, cached sessions, federation gaps, recovery channels, API keys, emergency access, and provider support in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 共享与服务身份、嵌套组、直接授权、缓存会话、联邦缺口、恢复通道、API 密钥、紧急访问和提供商支持 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-3.3-SCP-08",
          "local_code": "SCP-08",
          "display_code": "P08",
          "safeguard_id": "3.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Include audit-only mode, unsupported platforms, local overrides, race conditions, cached state, alternate paths, fail-open behavior, and emergency bypass in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 仅审计模式、不支持平台、本地覆盖、竞态、缓存状态、替代路径、故障开放和紧急绕过 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-3.3-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "3.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-3.3-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "3.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-3.3-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "3.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-3.3-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "3.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-3.3-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "3.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind data owners and custodians, product teams, privacy, legal, security, records management, and providers to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 数据责任人与托管方、产品团队、隐私、法务、安全、档案管理和服务提供商 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-3.3-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "3.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Name who may transition created/collected → classified → approved use and flow → retained/held → disposed with verification, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-3.3-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "3.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Name who may transition requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-3.3-OWN-08",
          "local_code": "OWN-08",
          "display_code": "W08",
          "safeguard_id": "3.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Name who may transition observe → evaluate → decide → enforce → verify outcome → rollback/close, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-3.3-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "3.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-3.3-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "3.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-3.3-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "3.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV1, GV3, GV12, GV13, GV14, GV17, GV22, M1, M2, M3, M4, M5, and 3 more) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV1, GV3, GV12, GV13, GV14, GV17, GV22, M1, M2, M3, M4, M5, and 3 more）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-3.3-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "3.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-3.3-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "3.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the data inventory, classification, ownership, and lifecycle authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把数据清单、分类、所有权与生命周期权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-3.3-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "3.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle created/collected → classified → approved use and flow → retained/held → disposed with verification.",
          "zh": "对生命周期“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-3.3-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "3.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated.",
          "zh": "对生命周期“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-3.3-DAT-08",
          "local_code": "DAT-08",
          "display_code": "D08",
          "safeguard_id": "3.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle observe → evaluate → decide → enforce → verify outcome → rollback/close.",
          "zh": "对生命周期“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-3.3-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "3.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 3.2, Safeguard 4.1, Safeguard 5.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 3.2、Safeguard 4.1、Safeguard 5.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-3.3-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "3.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-3.3-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "3.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-3.3-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "3.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-3.3-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "3.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile data catalogs, schemas, DLP discovery, cloud/SaaS APIs, owner attestations, flow records, backup catalogs, and legal/privacy schedules and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 数据目录、模式、DLP 发现、云/SaaS API、责任人确认、流向记录、备份目录及法律与隐私期限，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-3.3-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "3.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Require every connector carrying data identity, sensitivity, owner, purpose, location, flow, access, retention, copy, derivation, and disposal state to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 数据身份、敏感度、责任人、目的、位置、流向、访问、保留、副本、派生与销毁状态 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-3.3-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "3.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Require every connector carrying effective identity, authentication, authorization, privilege, session, and revocation state across every access path to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 所有访问路径上的实际身份、认证、授权、权限、会话和撤销状态 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-3.3-INT-08",
          "local_code": "INT-08",
          "display_code": "I08",
          "safeguard_id": "3.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Require every connector carrying an enforceable allow, deny, contain, quarantine, require, remove, or transform decision at the closest reliable control point to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 在最近可靠控制点执行允许、拒绝、遏制、隔离、强制、移除或转换决策 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-3.3-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "3.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Translate owner-approved need-to-know into group, role, ACL, row/column, object and key policies at the authoritative control points.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“把数据所有者批准的知情需要，落实为组、角色、ACL、行列、对象和密钥策略；清除直接授权，分开系统管理与数据使用，审查继承/公开访问，使入转离与应急访问同步更新每一层。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-3.3-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "3.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-3.3-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "3.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-3.3-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "3.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-3.3-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "3.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the data inventory, classification, ownership, and lifecycle authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在数据清单、分类、所有权与生命周期权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-3.3-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "3.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Implement the explicit state machine created/collected → classified → approved use and flow → retained/held → disposed with verification; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-3.3-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "3.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Implement the explicit state machine requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-3.3-CTL-08",
          "local_code": "CTL-08",
          "display_code": "C08",
          "safeguard_id": "3.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Implement the explicit state machine observe → evaluate → decide → enforce → verify outcome → rollback/close; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-3.3-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "3.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-3.3-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "3.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-3.3-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "3.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-3.3-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "3.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-3.3-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "3.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in sensitive and business data, replicas, logs, backups, exports, derived data, AI corpora, keys, and data flows; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 敏感与业务数据、副本、日志、备份、导出、派生数据、AI 语料、密钥和数据流 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-3.3-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "3.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for created/collected → classified → approved use and flow → retained/held → disposed with verification; alert before each deadline becomes overdue.",
          "zh": "为“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-3.3-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "3.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated; alert before each deadline becomes overdue.",
          "zh": "为“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-3.3-TIM-08",
          "local_code": "TIM-08",
          "display_code": "T08",
          "safeguard_id": "3.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for observe → evaluate → decide → enforce → verify outcome → rollback/close; alert before each deadline becomes overdue.",
          "zh": "为“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-3.3-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "3.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “Counts of mapped data and account types are not interchangeable, despite the CAS formula.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“CAS 把“映射数据数”和“账户类型数”相除，量纲不同。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-3.3-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "3.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-3.3-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "3.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-3.3-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "3.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-3.3-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "3.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat unknown classification, encrypted or tokenized copies, cross-region replicas, immutable backups, derived data, litigation holds, and provider deletion limits as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 未知分类、加密或令牌化副本、跨地域副本、不可变备份、派生数据、诉讼保全及提供商删除限制 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-3.3-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "3.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Treat unstructured and derived data, logs, caches, backups, exports, client-side copies, cross-region processing, AI corpora, holds, and provider residues as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 非结构化与派生数据、日志、缓存、备份、导出、客户端副本、跨地域处理、AI 语料、保全和提供商残留 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-3.3-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "3.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Treat shared and service identities, nested groups, direct grants, cached sessions, federation gaps, recovery channels, API keys, emergency access, and provider support as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 共享与服务身份、嵌套组、直接授权、缓存会话、联邦缺口、恢复通道、API 密钥、紧急访问和提供商支持 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-3.3-EXC-08",
          "local_code": "EXC-08",
          "display_code": "X08",
          "safeguard_id": "3.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Treat audit-only mode, unsupported platforms, local overrides, race conditions, cached state, alternate paths, fail-open behavior, and emergency bypass as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 仅审计模式、不支持平台、本地覆盖、竞态、缓存状态、替代路径、故障开放和紧急绕过 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-3.3-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "3.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “For sampled data sets, enumerate effective permissions and reconcile them to approved identities.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“对抽样数据集枚举有效权限，并与批准身份对账。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-3.3-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "3.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-3.3-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "3.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 2 pinned CAS metric branch(es), 15 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 2 个指标分支、15 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-3.3-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "3.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-3.3-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "3.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the data inventory, classification, ownership, and lifecycle authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以数据清单、分类、所有权与生命周期权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-3.3-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "3.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Publish known, unknown, classified, ownerless, over-retained, prematurely deleted, unapproved copy, blocked flow, held, and disposal-verified data sets with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已知、未知、已分类、无责任人、超期保留、过早删除、未批准副本、被阻断流、保全及销毁已验证数据集，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-3.3-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "3.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Publish requested, approved, effective, excessive, orphaned, stale, emergency, revoked-but-active, and independently reviewed rights with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 申请、批准、实际、过度、孤儿、陈旧、紧急、已撤销仍活跃及独立复核权限，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-3.3-EVD-08",
          "local_code": "EVD-08",
          "display_code": "E08",
          "safeguard_id": "3.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Publish eligible, enforcing, audit-only, failed, bypassed, excepted, rolled-back, and outcome-verified populations with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 适用、已执行、仅审计、失败、被绕过、例外、已回滚和结果已验证总体，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-3.3-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "3.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-3.3-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "3.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-3.3-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "3.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-3.3-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "3.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-3.3-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "3.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the data inventory, classification, ownership, and lifecycle authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护数据清单、分类、所有权与生命周期权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-3.3-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "3.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Restrict authority to change created/collected → classified → approved use and flow → retained/held → disposed with verification; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-3.3-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "3.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Restrict authority to change requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-3.3-SEC-08",
          "local_code": "SEC-08",
          "display_code": "S08",
          "safeguard_id": "3.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Restrict authority to change observe → evaluate → decide → enforce → verify outcome → rollback/close; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-3.3-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "3.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-3.3-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "3.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-3.3-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "3.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-3.3-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "3.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-3.3-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "3.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise approved and unapproved copies, allowed and denied readers, retention boundaries, deletion verification, key loss, and cross-boundary transfers through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 获批与未批准副本、允许与拒绝读取、保留边界、删除验证、密钥丢失和跨边界传输，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-3.3-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "3.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Run the positive control an approved data set following its declared use, access, transfer, retention, and disposal path; exercise negative, stale, duplicate, bypass, and outage controls including an unknown or misclassified copy, forbidden reader or flow, early deletion, expired retention, failed disposal, and provider residue.",
          "zh": "运行正向控制“按声明用途、访问、传输、保留和销毁路径流转的获批数据集”，并执行包含“未知或误分类副本、禁止读取者或流向、过早删除、保留过期、销毁失败和提供商残留”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-3.3-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "3.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Run the positive control an authorized identity using the required assurance and least privilege; exercise negative, stale, duplicate, bypass, and outage controls including an unauthorized identity, missing factor, stale session, direct grant, inherited excess, revoked token, and recovery bypass.",
          "zh": "运行正向控制“使用所需保证级别和最小权限的授权身份”，并执行包含“未授权身份、缺失认证因子、陈旧会话、直接授权、继承过权、已撤销令牌和恢复绕过”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-3.3-TST-08",
          "local_code": "TST-08",
          "display_code": "V08",
          "safeguard_id": "3.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Run the positive control an approved business action that completes through the enforced path; exercise negative, stale, duplicate, bypass, and outage controls including a prohibited action, alternate path, local override, stale policy, control outage, emergency bypass, and rollback failure.",
          "zh": "运行正向控制“通过受控路径完成的一项获批业务动作”，并执行包含“禁止动作、替代路径、本地覆盖、陈旧策略、控制中断、紧急绕过和回滚失败”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-3.3-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "3.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-3.3-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "3.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-3.3-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "3.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-3.3-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "3.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-3.3-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "3.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever data catalogs, schemas, DLP discovery, cloud/SaaS APIs, owner attestations, flow records, backup catalogs, and legal/privacy schedules change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 数据目录、模式、DLP 发现、云/SaaS API、责任人确认、流向记录、备份目录及法律与隐私期限 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-3.3-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "3.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Use known, unknown, classified, ownerless, over-retained, prematurely deleted, unapproved copy, blocked flow, held, and disposal-verified data sets to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已知、未知、已分类、无责任人、超期保留、过早删除、未批准副本、被阻断流、保全及销毁已验证数据集 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-3.3-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "3.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Use requested, approved, effective, excessive, orphaned, stale, emergency, revoked-but-active, and independently reviewed rights to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 申请、批准、实际、过度、孤儿、陈旧、紧急、已撤销仍活跃及独立复核权限 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-3.3-OPS-08",
          "local_code": "OPS-08",
          "display_code": "R08",
          "safeguard_id": "3.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Use eligible, enforcing, audit-only, failed, bypassed, excepted, rolled-back, and outcome-verified populations to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 适用、已执行、仅审计、失败、被绕过、例外、已回滚和结果已验证总体 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "3.4",
      "control": 3,
      "title_en": "Enforce Data Retention",
      "title_zh": "保留期限执行",
      "first_ig": 1,
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Data",
      "security_function": "Protect",
      "patterns": [
        "data_lifecycle",
        "enforcement"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "3.1",
          "3.2"
        ],
        "variables": [
          "GV11",
          "GV12",
          "GV15",
          "GV17",
          "M1",
          "M2",
          "M3",
          "M4",
          "M5",
          "M6"
        ],
        "metric_branches": 2,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "The boundary includes primary stores, replicas, queues, logs, search indexes, endpoints, exports, backups and provider copies.",
          "build": "Map rules to deletion, archival, legal-hold and backup-expiry jobs owned by data and platform teams.",
          "proof": "Create test records with short expiry and hold states, advance time, then verify preservation before minimum, deletion after maximum, replica/index/cache propagation and auditable hold release.",
          "boundary": "Immutable backups may defer physical deletion until media expiry, so access isolation and documented maximum cycle define the compensating boundary."
        },
        "zh": {
          "scope": "范围包括主存储、副本、队列、日志、搜索索引、终端、导出、备份和服务商副本。",
          "build": "把规则落实为删除、归档、诉讼保全和备份到期任务，由数据与平台团队负责；把触发事件、司法辖区、政策版本和保全状态与记录或数据集绑定，监控失败/延迟并向下游传播删除。",
          "proof": "创建短到期和被保全的测试记录，推进时间，验证最短期前保留、最长期后删除、对副本/索引/缓存传播以及保全释放可审计。",
          "boundary": "不可变备份可把物理删除推迟到介质到期，此时隔离访问和明确最长周期构成补偿边界。"
        }
      },
      "category_counts": {
        "outcome": 7,
        "scope": 7,
        "ownership": 7,
        "data": 7,
        "integration": 7,
        "control": 7,
        "timing": 7,
        "exception": 7,
        "evidence": 7,
        "security": 7,
        "testing": 7,
        "operations": 7
      },
      "requirement_count": 84,
      "requirements": [
        {
          "code": "CIS-3.4-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "3.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Enforce Data Retention; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“保留期限执行”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-3.4-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "3.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 3.4, official Asset Class Data, Security Function Protect, and IG1 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 3.4、官方资产类别“数据”、安全功能“保护”和首次出现的 IG1，并保存来源抓取日期。"
        },
        {
          "code": "CIS-3.4-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "3.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “The boundary includes primary stores, replicas, queues, logs, search indexes, endpoints, exports, backups and provider copies.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“范围包括主存储、副本、队列、日志、搜索索引、终端、导出、备份和服务商副本。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-3.4-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "3.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-3.4-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "3.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Enforce Data Retention to its operating object—sensitive and business data, replicas, logs, backups, exports, derived data, AI corpora, keys, and data flows—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“保留期限执行”连接到其运营对象——敏感与业务数据、副本、日志、备份、导出、派生数据、AI 语料、密钥和数据流——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-3.4-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "3.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "For Enforce Data Retention, express success as an observable decision over data identity, sensitivity, owner, purpose, location, flow, access, retention, copy, derivation, and disposal state; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“保留期限执行”，以 数据身份、敏感度、责任人、目的、位置、流向、访问、保留、副本、派生与销毁状态 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-3.4-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "3.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "For Enforce Data Retention, express success as an observable decision over an enforceable allow, deny, contain, quarantine, require, remove, or transform decision at the closest reliable control point; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“保留期限执行”，以 在最近可靠控制点执行允许、拒绝、遏制、隔离、强制、移除或转换决策 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-3.4-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "3.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-3.4-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "3.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-3.4-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "3.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-3.4-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "3.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-3.4-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "3.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across unknown classification, encrypted or tokenized copies, cross-region replicas, immutable backups, derived data, litigation holds, and provider deletion limits; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 未知分类、加密或令牌化副本、跨地域副本、不可变备份、派生数据、诉讼保全及提供商删除限制 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-3.4-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "3.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Include unstructured and derived data, logs, caches, backups, exports, client-side copies, cross-region processing, AI corpora, holds, and provider residues in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 非结构化与派生数据、日志、缓存、备份、导出、客户端副本、跨地域处理、AI 语料、保全和提供商残留 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-3.4-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "3.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Include audit-only mode, unsupported platforms, local overrides, race conditions, cached state, alternate paths, fail-open behavior, and emergency bypass in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 仅审计模式、不支持平台、本地覆盖、竞态、缓存状态、替代路径、故障开放和紧急绕过 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-3.4-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "3.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-3.4-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "3.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-3.4-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "3.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-3.4-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "3.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-3.4-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "3.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind data owners and custodians, product teams, privacy, legal, security, records management, and providers to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 数据责任人与托管方、产品团队、隐私、法务、安全、档案管理和服务提供商 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-3.4-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "3.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Name who may transition created/collected → classified → approved use and flow → retained/held → disposed with verification, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-3.4-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "3.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Name who may transition observe → evaluate → decide → enforce → verify outcome → rollback/close, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-3.4-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "3.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-3.4-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "3.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-3.4-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "3.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV11, GV12, GV15, GV17, M1, M2, M3, M4, M5, M6) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV11, GV12, GV15, GV17, M1, M2, M3, M4, M5, M6）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-3.4-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "3.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-3.4-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "3.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the data inventory, classification, ownership, and lifecycle authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把数据清单、分类、所有权与生命周期权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-3.4-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "3.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle created/collected → classified → approved use and flow → retained/held → disposed with verification.",
          "zh": "对生命周期“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-3.4-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "3.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle observe → evaluate → decide → enforce → verify outcome → rollback/close.",
          "zh": "对生命周期“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-3.4-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "3.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 3.1, Safeguard 3.2; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 3.1、Safeguard 3.2 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-3.4-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "3.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-3.4-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "3.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-3.4-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "3.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-3.4-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "3.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile data catalogs, schemas, DLP discovery, cloud/SaaS APIs, owner attestations, flow records, backup catalogs, and legal/privacy schedules and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 数据目录、模式、DLP 发现、云/SaaS API、责任人确认、流向记录、备份目录及法律与隐私期限，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-3.4-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "3.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Require every connector carrying data identity, sensitivity, owner, purpose, location, flow, access, retention, copy, derivation, and disposal state to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 数据身份、敏感度、责任人、目的、位置、流向、访问、保留、副本、派生与销毁状态 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-3.4-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "3.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Require every connector carrying an enforceable allow, deny, contain, quarantine, require, remove, or transform decision at the closest reliable control point to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 在最近可靠控制点执行允许、拒绝、遏制、隔离、强制、移除或转换决策 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-3.4-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "3.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Map rules to deletion, archival, legal-hold and backup-expiry jobs owned by data and platform teams.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“把规则落实为删除、归档、诉讼保全和备份到期任务，由数据与平台团队负责；把触发事件、司法辖区、政策版本和保全状态与记录或数据集绑定，监控失败/延迟并向下游传播删除。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-3.4-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "3.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-3.4-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "3.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-3.4-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "3.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-3.4-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "3.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the data inventory, classification, ownership, and lifecycle authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在数据清单、分类、所有权与生命周期权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-3.4-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "3.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Implement the explicit state machine created/collected → classified → approved use and flow → retained/held → disposed with verification; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-3.4-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "3.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Implement the explicit state machine observe → evaluate → decide → enforce → verify outcome → rollback/close; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-3.4-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "3.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-3.4-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "3.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-3.4-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "3.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-3.4-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "3.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-3.4-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "3.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in sensitive and business data, replicas, logs, backups, exports, derived data, AI corpora, keys, and data flows; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 敏感与业务数据、副本、日志、备份、导出、派生数据、AI 语料、密钥和数据流 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-3.4-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "3.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for created/collected → classified → approved use and flow → retained/held → disposed with verification; alert before each deadline becomes overdue.",
          "zh": "为“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-3.4-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "3.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for observe → evaluate → decide → enforce → verify outcome → rollback/close; alert before each deadline becomes overdue.",
          "zh": "为“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-3.4-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "3.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “Immutable backups may defer physical deletion until media expiry, so access isolation and documented maximum cycle define the compensating boundary.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“不可变备份可把物理删除推迟到介质到期，此时隔离访问和明确最长周期构成补偿边界。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-3.4-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "3.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-3.4-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "3.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-3.4-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "3.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-3.4-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "3.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat unknown classification, encrypted or tokenized copies, cross-region replicas, immutable backups, derived data, litigation holds, and provider deletion limits as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 未知分类、加密或令牌化副本、跨地域副本、不可变备份、派生数据、诉讼保全及提供商删除限制 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-3.4-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "3.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Treat unstructured and derived data, logs, caches, backups, exports, client-side copies, cross-region processing, AI corpora, holds, and provider residues as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 非结构化与派生数据、日志、缓存、备份、导出、客户端副本、跨地域处理、AI 语料、保全和提供商残留 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-3.4-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "3.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Treat audit-only mode, unsupported platforms, local overrides, race conditions, cached state, alternate paths, fail-open behavior, and emergency bypass as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 仅审计模式、不支持平台、本地覆盖、竞态、缓存状态、替代路径、故障开放和紧急绕过 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-3.4-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "3.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Create test records with short expiry and hold states, advance time, then verify preservation before minimum, deletion after maximum, replica/index/cache propagation and auditable hold release.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“创建短到期和被保全的测试记录，推进时间，验证最短期前保留、最长期后删除、对副本/索引/缓存传播以及保全释放可审计。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-3.4-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "3.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-3.4-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "3.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 2 pinned CAS metric branch(es), 10 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 2 个指标分支、10 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-3.4-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "3.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-3.4-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "3.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the data inventory, classification, ownership, and lifecycle authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以数据清单、分类、所有权与生命周期权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-3.4-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "3.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Publish known, unknown, classified, ownerless, over-retained, prematurely deleted, unapproved copy, blocked flow, held, and disposal-verified data sets with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已知、未知、已分类、无责任人、超期保留、过早删除、未批准副本、被阻断流、保全及销毁已验证数据集，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-3.4-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "3.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Publish eligible, enforcing, audit-only, failed, bypassed, excepted, rolled-back, and outcome-verified populations with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 适用、已执行、仅审计、失败、被绕过、例外、已回滚和结果已验证总体，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-3.4-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "3.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-3.4-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "3.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-3.4-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "3.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-3.4-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "3.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-3.4-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "3.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the data inventory, classification, ownership, and lifecycle authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护数据清单、分类、所有权与生命周期权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-3.4-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "3.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Restrict authority to change created/collected → classified → approved use and flow → retained/held → disposed with verification; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-3.4-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "3.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Restrict authority to change observe → evaluate → decide → enforce → verify outcome → rollback/close; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-3.4-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "3.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-3.4-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "3.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-3.4-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "3.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-3.4-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "3.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-3.4-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "3.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise approved and unapproved copies, allowed and denied readers, retention boundaries, deletion verification, key loss, and cross-boundary transfers through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 获批与未批准副本、允许与拒绝读取、保留边界、删除验证、密钥丢失和跨边界传输，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-3.4-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "3.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Run the positive control an approved data set following its declared use, access, transfer, retention, and disposal path; exercise negative, stale, duplicate, bypass, and outage controls including an unknown or misclassified copy, forbidden reader or flow, early deletion, expired retention, failed disposal, and provider residue.",
          "zh": "运行正向控制“按声明用途、访问、传输、保留和销毁路径流转的获批数据集”，并执行包含“未知或误分类副本、禁止读取者或流向、过早删除、保留过期、销毁失败和提供商残留”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-3.4-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "3.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Run the positive control an approved business action that completes through the enforced path; exercise negative, stale, duplicate, bypass, and outage controls including a prohibited action, alternate path, local override, stale policy, control outage, emergency bypass, and rollback failure.",
          "zh": "运行正向控制“通过受控路径完成的一项获批业务动作”，并执行包含“禁止动作、替代路径、本地覆盖、陈旧策略、控制中断、紧急绕过和回滚失败”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-3.4-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "3.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-3.4-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "3.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-3.4-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "3.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-3.4-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "3.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-3.4-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "3.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever data catalogs, schemas, DLP discovery, cloud/SaaS APIs, owner attestations, flow records, backup catalogs, and legal/privacy schedules change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 数据目录、模式、DLP 发现、云/SaaS API、责任人确认、流向记录、备份目录及法律与隐私期限 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-3.4-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "3.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Use known, unknown, classified, ownerless, over-retained, prematurely deleted, unapproved copy, blocked flow, held, and disposal-verified data sets to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已知、未知、已分类、无责任人、超期保留、过早删除、未批准副本、被阻断流、保全及销毁已验证数据集 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-3.4-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "3.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Use eligible, enforcing, audit-only, failed, bypassed, excepted, rolled-back, and outcome-verified populations to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 适用、已执行、仅审计、失败、被绕过、例外、已回滚和结果已验证总体 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "3.5",
      "control": 3,
      "title_en": "Securely Dispose of Data",
      "title_zh": "安全处置",
      "first_ig": 1,
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Data",
      "security_function": "Protect",
      "patterns": [
        "data_lifecycle"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "3.1",
          "3.2"
        ],
        "variables": [
          "GV11",
          "GV12",
          "GV16",
          "GV17",
          "M1",
          "M2",
          "M3",
          "M4",
          "M5",
          "M6"
        ],
        "metric_branches": 2,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "Cover logical records, files, cryptographic keys, removable media, failed drives, cloud volumes, snapshots, backups, paper and provider-held data.",
          "build": "Select deletion, cryptographic erasure, overwrite, media destruction or provider workflow according to sensitivity and medium.",
          "proof": "Run a controlled deletion through each disposal path and verify storage, backup, search, API and recovery behavior after the stated completion time.",
          "boundary": "Flash wear levelling, snapshots, immutable storage and SaaS deletion windows limit immediate erasure."
        },
        "zh": {
          "scope": "覆盖逻辑记录、文件、加密密钥、可移动介质、故障硬盘、云卷、快照、备份、纸张和服务商持有数据。",
          "build": "按敏感度和介质选择删除、密码擦除、覆写、物理销毁或服务商流程；授权与执行分离，维护保管链，验证销毁供应商，并处理副本、索引、密钥和保留锁。",
          "proof": "每条销毁路径走一份受控数据，在承诺完成时间后检查存储、备份、搜索、API 和恢复行为。",
          "boundary": "闪存磨损均衡、快照、不可变存储和 SaaS 删除窗口会限制即时擦除。"
        }
      },
      "category_counts": {
        "outcome": 6,
        "scope": 6,
        "ownership": 6,
        "data": 6,
        "integration": 6,
        "control": 6,
        "timing": 6,
        "exception": 6,
        "evidence": 6,
        "security": 6,
        "testing": 6,
        "operations": 6
      },
      "requirement_count": 72,
      "requirements": [
        {
          "code": "CIS-3.5-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "3.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Securely Dispose of Data; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“安全处置”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-3.5-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "3.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 3.5, official Asset Class Data, Security Function Protect, and IG1 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 3.5、官方资产类别“数据”、安全功能“保护”和首次出现的 IG1，并保存来源抓取日期。"
        },
        {
          "code": "CIS-3.5-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "3.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Cover logical records, files, cryptographic keys, removable media, failed drives, cloud volumes, snapshots, backups, paper and provider-held data.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“覆盖逻辑记录、文件、加密密钥、可移动介质、故障硬盘、云卷、快照、备份、纸张和服务商持有数据。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-3.5-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "3.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-3.5-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "3.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Securely Dispose of Data to its operating object—sensitive and business data, replicas, logs, backups, exports, derived data, AI corpora, keys, and data flows—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“安全处置”连接到其运营对象——敏感与业务数据、副本、日志、备份、导出、派生数据、AI 语料、密钥和数据流——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-3.5-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "3.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "For Securely Dispose of Data, express success as an observable decision over data identity, sensitivity, owner, purpose, location, flow, access, retention, copy, derivation, and disposal state; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“安全处置”，以 数据身份、敏感度、责任人、目的、位置、流向、访问、保留、副本、派生与销毁状态 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-3.5-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "3.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-3.5-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "3.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-3.5-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "3.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-3.5-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "3.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-3.5-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "3.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across unknown classification, encrypted or tokenized copies, cross-region replicas, immutable backups, derived data, litigation holds, and provider deletion limits; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 未知分类、加密或令牌化副本、跨地域副本、不可变备份、派生数据、诉讼保全及提供商删除限制 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-3.5-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "3.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Include unstructured and derived data, logs, caches, backups, exports, client-side copies, cross-region processing, AI corpora, holds, and provider residues in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 非结构化与派生数据、日志、缓存、备份、导出、客户端副本、跨地域处理、AI 语料、保全和提供商残留 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-3.5-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "3.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-3.5-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "3.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-3.5-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "3.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-3.5-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "3.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-3.5-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "3.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind data owners and custodians, product teams, privacy, legal, security, records management, and providers to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 数据责任人与托管方、产品团队、隐私、法务、安全、档案管理和服务提供商 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-3.5-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "3.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Name who may transition created/collected → classified → approved use and flow → retained/held → disposed with verification, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-3.5-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "3.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-3.5-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "3.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-3.5-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "3.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV11, GV12, GV16, GV17, M1, M2, M3, M4, M5, M6) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV11, GV12, GV16, GV17, M1, M2, M3, M4, M5, M6）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-3.5-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "3.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-3.5-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "3.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the data inventory, classification, ownership, and lifecycle authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把数据清单、分类、所有权与生命周期权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-3.5-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "3.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle created/collected → classified → approved use and flow → retained/held → disposed with verification.",
          "zh": "对生命周期“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-3.5-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "3.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 3.1, Safeguard 3.2; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 3.1、Safeguard 3.2 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-3.5-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "3.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-3.5-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "3.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-3.5-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "3.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-3.5-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "3.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile data catalogs, schemas, DLP discovery, cloud/SaaS APIs, owner attestations, flow records, backup catalogs, and legal/privacy schedules and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 数据目录、模式、DLP 发现、云/SaaS API、责任人确认、流向记录、备份目录及法律与隐私期限，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-3.5-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "3.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Require every connector carrying data identity, sensitivity, owner, purpose, location, flow, access, retention, copy, derivation, and disposal state to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 数据身份、敏感度、责任人、目的、位置、流向、访问、保留、副本、派生与销毁状态 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-3.5-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "3.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Select deletion, cryptographic erasure, overwrite, media destruction or provider workflow according to sensitivity and medium.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“按敏感度和介质选择删除、密码擦除、覆写、物理销毁或服务商流程；授权与执行分离，维护保管链，验证销毁供应商，并处理副本、索引、密钥和保留锁。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-3.5-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "3.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-3.5-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "3.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-3.5-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "3.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-3.5-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "3.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the data inventory, classification, ownership, and lifecycle authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在数据清单、分类、所有权与生命周期权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-3.5-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "3.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Implement the explicit state machine created/collected → classified → approved use and flow → retained/held → disposed with verification; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-3.5-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "3.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-3.5-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "3.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-3.5-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "3.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-3.5-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "3.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-3.5-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "3.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in sensitive and business data, replicas, logs, backups, exports, derived data, AI corpora, keys, and data flows; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 敏感与业务数据、副本、日志、备份、导出、派生数据、AI 语料、密钥和数据流 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-3.5-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "3.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for created/collected → classified → approved use and flow → retained/held → disposed with verification; alert before each deadline becomes overdue.",
          "zh": "为“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-3.5-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "3.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “Flash wear levelling, snapshots, immutable storage and SaaS deletion windows limit immediate erasure.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“闪存磨损均衡、快照、不可变存储和 SaaS 删除窗口会限制即时擦除。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-3.5-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "3.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-3.5-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "3.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-3.5-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "3.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-3.5-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "3.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat unknown classification, encrypted or tokenized copies, cross-region replicas, immutable backups, derived data, litigation holds, and provider deletion limits as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 未知分类、加密或令牌化副本、跨地域副本、不可变备份、派生数据、诉讼保全及提供商删除限制 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-3.5-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "3.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Treat unstructured and derived data, logs, caches, backups, exports, client-side copies, cross-region processing, AI corpora, holds, and provider residues as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 非结构化与派生数据、日志、缓存、备份、导出、客户端副本、跨地域处理、AI 语料、保全和提供商残留 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-3.5-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "3.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Run a controlled deletion through each disposal path and verify storage, backup, search, API and recovery behavior after the stated completion time.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“每条销毁路径走一份受控数据，在承诺完成时间后检查存储、备份、搜索、API 和恢复行为。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-3.5-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "3.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-3.5-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "3.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 2 pinned CAS metric branch(es), 10 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 2 个指标分支、10 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-3.5-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "3.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-3.5-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "3.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the data inventory, classification, ownership, and lifecycle authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以数据清单、分类、所有权与生命周期权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-3.5-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "3.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Publish known, unknown, classified, ownerless, over-retained, prematurely deleted, unapproved copy, blocked flow, held, and disposal-verified data sets with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已知、未知、已分类、无责任人、超期保留、过早删除、未批准副本、被阻断流、保全及销毁已验证数据集，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-3.5-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "3.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-3.5-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "3.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-3.5-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "3.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-3.5-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "3.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-3.5-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "3.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the data inventory, classification, ownership, and lifecycle authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护数据清单、分类、所有权与生命周期权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-3.5-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "3.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Restrict authority to change created/collected → classified → approved use and flow → retained/held → disposed with verification; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-3.5-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "3.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-3.5-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "3.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-3.5-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "3.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-3.5-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "3.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-3.5-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "3.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise approved and unapproved copies, allowed and denied readers, retention boundaries, deletion verification, key loss, and cross-boundary transfers through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 获批与未批准副本、允许与拒绝读取、保留边界、删除验证、密钥丢失和跨边界传输，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-3.5-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "3.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Run the positive control an approved data set following its declared use, access, transfer, retention, and disposal path; exercise negative, stale, duplicate, bypass, and outage controls including an unknown or misclassified copy, forbidden reader or flow, early deletion, expired retention, failed disposal, and provider residue.",
          "zh": "运行正向控制“按声明用途、访问、传输、保留和销毁路径流转的获批数据集”，并执行包含“未知或误分类副本、禁止读取者或流向、过早删除、保留过期、销毁失败和提供商残留”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-3.5-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "3.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-3.5-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "3.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-3.5-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "3.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-3.5-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "3.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-3.5-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "3.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever data catalogs, schemas, DLP discovery, cloud/SaaS APIs, owner attestations, flow records, backup catalogs, and legal/privacy schedules change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 数据目录、模式、DLP 发现、云/SaaS API、责任人确认、流向记录、备份目录及法律与隐私期限 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-3.5-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "3.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Use known, unknown, classified, ownerless, over-retained, prematurely deleted, unapproved copy, blocked flow, held, and disposal-verified data sets to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已知、未知、已分类、无责任人、超期保留、过早删除、未批准副本、被阻断流、保全及销毁已验证数据集 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "3.6",
      "control": 3,
      "title_en": "Encrypt Data on End-User Devices",
      "title_zh": "终端全盘与数据加密",
      "first_ig": 1,
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Data",
      "security_function": "Protect",
      "patterns": [
        "data_lifecycle",
        "encryption"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "1.1",
          "2.1",
          "4.1"
        ],
        "variables": [
          "GV1",
          "GV3",
          "GV5",
          "M1",
          "M2",
          "M3",
          "M4",
          "M5"
        ],
        "metric_branches": 2,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "Include enterprise data on laptops, desktops and managed mobile devices, plus local caches, swap, hibernation, removable storage and offline profiles.",
          "build": "Enforce platform-native encryption through MDM/endpoint configuration, escrow recovery material separately, bind keys to hardware and strong authentication, and block access when encryption is absent, suspended or recovery state is unhealthy.",
          "proof": "Read actual encryption and key-protection state, not installed software.",
          "boundary": "A device reporting “encrypted” while auto-unlocked with an exposed key has weaker protection."
        },
        "zh": {
          "scope": "包括笔记本、台式机和受管移动设备上的企业数据，以及本地缓存、交换区、休眠、可移动存储和离线档案。",
          "build": "通过 MDM/终端策略强制平台原生加密，恢复材料另处托管，密钥绑定硬件和强认证；加密缺失、暂停或恢复状态异常时阻断访问。",
          "proof": "读取真实加密和密钥保护状态，不能只看软件安装。",
          "boundary": "设备显示“已加密”但密钥裸露并自动解锁，保护更弱。"
        }
      },
      "category_counts": {
        "outcome": 7,
        "scope": 7,
        "ownership": 7,
        "data": 7,
        "integration": 7,
        "control": 7,
        "timing": 7,
        "exception": 7,
        "evidence": 7,
        "security": 7,
        "testing": 7,
        "operations": 7
      },
      "requirement_count": 84,
      "requirements": [
        {
          "code": "CIS-3.6-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "3.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Encrypt Data on End-User Devices; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“终端全盘与数据加密”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-3.6-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "3.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 3.6, official Asset Class Data, Security Function Protect, and IG1 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 3.6、官方资产类别“数据”、安全功能“保护”和首次出现的 IG1，并保存来源抓取日期。"
        },
        {
          "code": "CIS-3.6-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "3.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Include enterprise data on laptops, desktops and managed mobile devices, plus local caches, swap, hibernation, removable storage and offline profiles.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“包括笔记本、台式机和受管移动设备上的企业数据，以及本地缓存、交换区、休眠、可移动存储和离线档案。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-3.6-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "3.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-3.6-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "3.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Encrypt Data on End-User Devices to its operating object—sensitive and business data, replicas, logs, backups, exports, derived data, AI corpora, keys, and data flows—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“终端全盘与数据加密”连接到其运营对象——敏感与业务数据、副本、日志、备份、导出、派生数据、AI 语料、密钥和数据流——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-3.6-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "3.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "For Encrypt Data on End-User Devices, express success as an observable decision over data identity, sensitivity, owner, purpose, location, flow, access, retention, copy, derivation, and disposal state; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“终端全盘与数据加密”，以 数据身份、敏感度、责任人、目的、位置、流向、访问、保留、副本、派生与销毁状态 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-3.6-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "3.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original encryption pattern analysis",
          "basis_zh": "SOSEC 原创 encryption 模式分析",
          "en": "For Encrypt Data on End-User Devices, express success as an observable decision over plaintext exposure against a named loss, theft, interception, storage-administrator, provider, or cross-tenant threat; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“终端全盘与数据加密”，以 针对丢失、盗窃、截获、存储管理员、提供商或跨租户威胁的明文暴露 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-3.6-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "3.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-3.6-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "3.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-3.6-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "3.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-3.6-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "3.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-3.6-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "3.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across unknown classification, encrypted or tokenized copies, cross-region replicas, immutable backups, derived data, litigation holds, and provider deletion limits; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 未知分类、加密或令牌化副本、跨地域副本、不可变备份、派生数据、诉讼保全及提供商删除限制 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-3.6-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "3.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Include unstructured and derived data, logs, caches, backups, exports, client-side copies, cross-region processing, AI corpora, holds, and provider residues in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 非结构化与派生数据、日志、缓存、备份、导出、客户端副本、跨地域处理、AI 语料、保全和提供商残留 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-3.6-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "3.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original encryption pattern analysis",
          "basis_zh": "SOSEC 原创 encryption 模式分析",
          "en": "Include unsupported endpoints, boot and unlocked state, alternate protocols, downgrade, copied data, key export, shared keys, backups, logs, and recovery in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 不支持终端、启动与解锁状态、替代协议、降级、数据副本、密钥导出、共享密钥、备份、日志和恢复 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-3.6-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "3.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-3.6-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "3.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-3.6-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "3.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-3.6-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "3.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-3.6-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "3.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind data owners and custodians, product teams, privacy, legal, security, records management, and providers to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 数据责任人与托管方、产品团队、隐私、法务、安全、档案管理和服务提供商 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-3.6-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "3.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Name who may transition created/collected → classified → approved use and flow → retained/held → disposed with verification, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-3.6-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "3.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original encryption pattern analysis",
          "basis_zh": "SOSEC 原创 encryption 模式分析",
          "en": "Name who may transition data identified → policy selected → keys provisioned → encryption enforced → use/decrypt authorized → keys rotated/revoked → data retired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 识别数据 → 选择策略 → 配发密钥 → 强制加密 → 授权使用/解密 → 轮换/撤销密钥 → 退役数据，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-3.6-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "3.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-3.6-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "3.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-3.6-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "3.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV1, GV3, GV5, M1, M2, M3, M4, M5) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV1, GV3, GV5, M1, M2, M3, M4, M5）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-3.6-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "3.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-3.6-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "3.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the data inventory, classification, ownership, and lifecycle authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把数据清单、分类、所有权与生命周期权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-3.6-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "3.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle created/collected → classified → approved use and flow → retained/held → disposed with verification.",
          "zh": "对生命周期“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-3.6-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "3.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original encryption pattern analysis",
          "basis_zh": "SOSEC 原创 encryption 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle data identified → policy selected → keys provisioned → encryption enforced → use/decrypt authorized → keys rotated/revoked → data retired.",
          "zh": "对生命周期“识别数据 → 选择策略 → 配发密钥 → 强制加密 → 授权使用/解密 → 轮换/撤销密钥 → 退役数据”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-3.6-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "3.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 1.1, Safeguard 2.1, Safeguard 4.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 1.1、Safeguard 2.1、Safeguard 4.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-3.6-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "3.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-3.6-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "3.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-3.6-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "3.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-3.6-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "3.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile data catalogs, schemas, DLP discovery, cloud/SaaS APIs, owner attestations, flow records, backup catalogs, and legal/privacy schedules and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 数据目录、模式、DLP 发现、云/SaaS API、责任人确认、流向记录、备份目录及法律与隐私期限，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-3.6-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "3.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Require every connector carrying data identity, sensitivity, owner, purpose, location, flow, access, retention, copy, derivation, and disposal state to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 数据身份、敏感度、责任人、目的、位置、流向、访问、保留、副本、派生与销毁状态 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-3.6-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "3.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original encryption pattern analysis",
          "basis_zh": "SOSEC 原创 encryption 模式分析",
          "en": "Require every connector carrying plaintext exposure against a named loss, theft, interception, storage-administrator, provider, or cross-tenant threat to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 针对丢失、盗窃、截获、存储管理员、提供商或跨租户威胁的明文暴露 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-3.6-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "3.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Enforce platform-native encryption through MDM/endpoint configuration, escrow recovery material separately, bind keys to hardware and strong authentication, and block access when encryption is absent, suspended or recovery state is unhealthy.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“通过 MDM/终端策略强制平台原生加密，恢复材料另处托管，密钥绑定硬件和强认证；加密缺失、暂停或恢复状态异常时阻断访问。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-3.6-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "3.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-3.6-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "3.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-3.6-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "3.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-3.6-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "3.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the data inventory, classification, ownership, and lifecycle authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在数据清单、分类、所有权与生命周期权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-3.6-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "3.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Implement the explicit state machine created/collected → classified → approved use and flow → retained/held → disposed with verification; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-3.6-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "3.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original encryption pattern analysis",
          "basis_zh": "SOSEC 原创 encryption 模式分析",
          "en": "Implement the explicit state machine data identified → policy selected → keys provisioned → encryption enforced → use/decrypt authorized → keys rotated/revoked → data retired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“识别数据 → 选择策略 → 配发密钥 → 强制加密 → 授权使用/解密 → 轮换/撤销密钥 → 退役数据”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-3.6-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "3.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-3.6-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "3.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-3.6-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "3.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-3.6-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "3.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-3.6-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "3.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in sensitive and business data, replicas, logs, backups, exports, derived data, AI corpora, keys, and data flows; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 敏感与业务数据、副本、日志、备份、导出、派生数据、AI 语料、密钥和数据流 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-3.6-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "3.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for created/collected → classified → approved use and flow → retained/held → disposed with verification; alert before each deadline becomes overdue.",
          "zh": "为“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-3.6-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "3.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original encryption pattern analysis",
          "basis_zh": "SOSEC 原创 encryption 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for data identified → policy selected → keys provisioned → encryption enforced → use/decrypt authorized → keys rotated/revoked → data retired; alert before each deadline becomes overdue.",
          "zh": "为“识别数据 → 选择策略 → 配发密钥 → 强制加密 → 授权使用/解密 → 轮换/撤销密钥 → 退役数据”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-3.6-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "3.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “A device reporting “encrypted” while auto-unlocked with an exposed key has weaker protection.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“设备显示“已加密”但密钥裸露并自动解锁，保护更弱。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-3.6-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "3.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-3.6-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "3.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-3.6-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "3.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-3.6-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "3.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat unknown classification, encrypted or tokenized copies, cross-region replicas, immutable backups, derived data, litigation holds, and provider deletion limits as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 未知分类、加密或令牌化副本、跨地域副本、不可变备份、派生数据、诉讼保全及提供商删除限制 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-3.6-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "3.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Treat unstructured and derived data, logs, caches, backups, exports, client-side copies, cross-region processing, AI corpora, holds, and provider residues as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 非结构化与派生数据、日志、缓存、备份、导出、客户端副本、跨地域处理、AI 语料、保全和提供商残留 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-3.6-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "3.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original encryption pattern analysis",
          "basis_zh": "SOSEC 原创 encryption 模式分析",
          "en": "Treat unsupported endpoints, boot and unlocked state, alternate protocols, downgrade, copied data, key export, shared keys, backups, logs, and recovery as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 不支持终端、启动与解锁状态、替代协议、降级、数据副本、密钥导出、共享密钥、备份、日志和恢复 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-3.6-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "3.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Read actual encryption and key-protection state, not installed software.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“读取真实加密和密钥保护状态，不能只看软件安装。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-3.6-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "3.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-3.6-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "3.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 2 pinned CAS metric branch(es), 8 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 2 个指标分支、8 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-3.6-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "3.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-3.6-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "3.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the data inventory, classification, ownership, and lifecycle authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以数据清单、分类、所有权与生命周期权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-3.6-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "3.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Publish known, unknown, classified, ownerless, over-retained, prematurely deleted, unapproved copy, blocked flow, held, and disposal-verified data sets with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已知、未知、已分类、无责任人、超期保留、过早删除、未批准副本、被阻断流、保全及销毁已验证数据集，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-3.6-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "3.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original encryption pattern analysis",
          "basis_zh": "SOSEC 原创 encryption 模式分析",
          "en": "Publish eligible, protected, weak/legacy, keyless, shared-key, decryptable-by-unintended-party, exception, and recovery-tested objects with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 适用、已保护、弱/旧算法、无密钥、共享密钥、非预期主体可解密、例外及恢复已测试对象，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-3.6-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "3.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-3.6-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "3.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-3.6-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "3.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-3.6-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "3.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-3.6-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "3.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the data inventory, classification, ownership, and lifecycle authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护数据清单、分类、所有权与生命周期权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-3.6-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "3.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Restrict authority to change created/collected → classified → approved use and flow → retained/held → disposed with verification; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-3.6-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "3.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original encryption pattern analysis",
          "basis_zh": "SOSEC 原创 encryption 模式分析",
          "en": "Restrict authority to change data identified → policy selected → keys provisioned → encryption enforced → use/decrypt authorized → keys rotated/revoked → data retired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“识别数据 → 选择策略 → 配发密钥 → 强制加密 → 授权使用/解密 → 轮换/撤销密钥 → 退役数据”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-3.6-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "3.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-3.6-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "3.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-3.6-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "3.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-3.6-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "3.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-3.6-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "3.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise approved and unapproved copies, allowed and denied readers, retention boundaries, deletion verification, key loss, and cross-boundary transfers through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 获批与未批准副本、允许与拒绝读取、保留边界、删除验证、密钥丢失和跨边界传输，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-3.6-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "3.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Run the positive control an approved data set following its declared use, access, transfer, retention, and disposal path; exercise negative, stale, duplicate, bypass, and outage controls including an unknown or misclassified copy, forbidden reader or flow, early deletion, expired retention, failed disposal, and provider residue.",
          "zh": "运行正向控制“按声明用途、访问、传输、保留和销毁路径流转的获批数据集”，并执行包含“未知或误分类副本、禁止读取者或流向、过早删除、保留过期、销毁失败和提供商残留”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-3.6-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "3.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original encryption pattern analysis",
          "basis_zh": "SOSEC 原创 encryption 模式分析",
          "en": "Run the positive control authorized encryption, decryption, rotation, and recovery for representative data; exercise negative, stale, duplicate, bypass, and outage controls including plaintext path, protocol downgrade, lost device, copied storage, unauthorized principal, revoked key, failed rotation, and unavailable recovery key.",
          "zh": "运行正向控制“代表性数据的授权加密、解密、轮换和恢复”，并执行包含“明文路径、协议降级、设备丢失、复制存储、未授权主体、撤销密钥、轮换失败和恢复密钥不可用”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-3.6-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "3.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-3.6-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "3.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-3.6-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "3.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-3.6-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "3.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-3.6-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "3.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever data catalogs, schemas, DLP discovery, cloud/SaaS APIs, owner attestations, flow records, backup catalogs, and legal/privacy schedules change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 数据目录、模式、DLP 发现、云/SaaS API、责任人确认、流向记录、备份目录及法律与隐私期限 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-3.6-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "3.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Use known, unknown, classified, ownerless, over-retained, prematurely deleted, unapproved copy, blocked flow, held, and disposal-verified data sets to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已知、未知、已分类、无责任人、超期保留、过早删除、未批准副本、被阻断流、保全及销毁已验证数据集 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-3.6-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "3.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original encryption pattern analysis",
          "basis_zh": "SOSEC 原创 encryption 模式分析",
          "en": "Use eligible, protected, weak/legacy, keyless, shared-key, decryptable-by-unintended-party, exception, and recovery-tested objects to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 适用、已保护、弱/旧算法、无密钥、共享密钥、非预期主体可解密、例外及恢复已测试对象 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "3.7",
      "control": 3,
      "title_en": "Establish and Maintain a Data Classification Scheme",
      "title_zh": "分级体系",
      "first_ig": 2,
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Data",
      "security_function": "Identify",
      "patterns": [
        "data_lifecycle",
        "inventory",
        "governance"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "3.1",
          "3.2"
        ],
        "variables": [
          "GV12",
          "GV17",
          "M1",
          "M2",
          "M3",
          "M4",
          "M5",
          "M6",
          "M7",
          "M8"
        ],
        "metric_branches": 2,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [
        "annually"
      ],
      "implementation_contract": {
        "en": {
          "scope": "Define a small, ordered set of classifications tied to business impact and handling, covering confidentiality and any integrity or availability tiers the enterprise needs.",
          "build": "Publish decision rules, examples, default class, owner and reclassification process, then encode labels in catalogs, repositories, documents and policy engines.",
          "proof": "Give independent reviewers representative and ambiguous samples and measure agreement with the owner-approved answer.",
          "boundary": "“Confidential” with no handling consequence is decorative."
        },
        "zh": {
          "scope": "建立少量、有顺序且直接对应业务影响和处理要求的分类；至少覆盖机密性，并按需要增加完整性/可用性等级。",
          "build": "公布判断规则、示例、默认级别、责任人和重分类流程，在目录、仓库、文档和策略引擎中编码标签；把法规标签映射进体系但保留其独立义务，每年及数据/用途重大变化时复核。",
          "proof": "给独立评审者代表性和模糊样本，测量与责任人批准答案的一致度。",
          "boundary": "没有处理后果的“机密”只是装饰。"
        }
      },
      "category_counts": {
        "outcome": 8,
        "scope": 8,
        "ownership": 8,
        "data": 8,
        "integration": 8,
        "control": 8,
        "timing": 8,
        "exception": 8,
        "evidence": 8,
        "security": 8,
        "testing": 8,
        "operations": 8
      },
      "requirement_count": 96,
      "requirements": [
        {
          "code": "CIS-3.7-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "3.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Establish and Maintain a Data Classification Scheme; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“分级体系”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-3.7-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "3.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 3.7, official Asset Class Data, Security Function Identify, and IG2 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 3.7、官方资产类别“数据”、安全功能“识别”和首次出现的 IG2，并保存来源抓取日期。"
        },
        {
          "code": "CIS-3.7-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "3.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Define a small, ordered set of classifications tied to business impact and handling, covering confidentiality and any integrity or availability tiers the enterprise needs.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“建立少量、有顺序且直接对应业务影响和处理要求的分类；至少覆盖机密性，并按需要增加完整性/可用性等级。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-3.7-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "3.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-3.7-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "3.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Establish and Maintain a Data Classification Scheme to its operating object—sensitive and business data, replicas, logs, backups, exports, derived data, AI corpora, keys, and data flows—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“分级体系”连接到其运营对象——敏感与业务数据、副本、日志、备份、导出、派生数据、AI 语料、密钥和数据流——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-3.7-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "3.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "For Establish and Maintain a Data Classification Scheme, express success as an observable decision over data identity, sensitivity, owner, purpose, location, flow, access, retention, copy, derivation, and disposal state; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“分级体系”，以 数据身份、敏感度、责任人、目的、位置、流向、访问、保留、副本、派生与销毁状态 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-3.7-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "3.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "For Establish and Maintain a Data Classification Scheme, express success as an observable decision over observed, approved, unapproved, ownerless, stale, duplicate, and retired object identity; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“分级体系”，以 已观测、已批准、未批准、无责任人、陈旧、重复和已退役对象身份 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-3.7-OUT-08",
          "local_code": "OUT-08",
          "display_code": "O08",
          "safeguard_id": "3.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "For Establish and Maintain a Data Classification Scheme, express success as an observable decision over a documented decision system with policy, process, procedure, accountable owner, approval, and review; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“分级体系”，以 包含策略、流程、程序、责任人、审批和复核的文档化决策系统 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-3.7-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "3.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-3.7-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "3.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-3.7-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "3.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-3.7-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "3.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-3.7-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "3.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across unknown classification, encrypted or tokenized copies, cross-region replicas, immutable backups, derived data, litigation holds, and provider deletion limits; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 未知分类、加密或令牌化副本、跨地域副本、不可变备份、派生数据、诉讼保全及提供商删除限制 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-3.7-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "3.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Include unstructured and derived data, logs, caches, backups, exports, client-side copies, cross-region processing, AI corpora, holds, and provider residues in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 非结构化与派生数据、日志、缓存、备份、导出、客户端副本、跨地域处理、AI 语料、保全和提供商残留 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-3.7-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "3.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Include dormant, ephemeral, disconnected, externally managed, provider-held, aliased, cloned, and cross-tenant objects in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 休眠、短生、离线、外部托管、提供商持有、别名、克隆和跨租户对象 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-3.7-SCP-08",
          "local_code": "SCP-08",
          "display_code": "P08",
          "safeguard_id": "3.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Include missing policy clauses, conflicting authorities, local deviations, obsolete documentation, and decisions made outside the governed workflow in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 策略条款缺失、权限冲突、本地偏离、文档过期及绕过治理流程的决策 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-3.7-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "3.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-3.7-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "3.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-3.7-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "3.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-3.7-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "3.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-3.7-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "3.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind data owners and custodians, product teams, privacy, legal, security, records management, and providers to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 数据责任人与托管方、产品团队、隐私、法务、安全、档案管理和服务提供商 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-3.7-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "3.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Name who may transition created/collected → classified → approved use and flow → retained/held → disposed with verification, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-3.7-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "3.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Name who may transition discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-3.7-OWN-08",
          "local_code": "OWN-08",
          "display_code": "W08",
          "safeguard_id": "3.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Name who may transition draft → reviewed → approved → effective → exception/withdrawn → superseded, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-3.7-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "3.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-3.7-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "3.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-3.7-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "3.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV12, GV17, M1, M2, M3, M4, M5, M6, M7, M8) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV12, GV17, M1, M2, M3, M4, M5, M6, M7, M8）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-3.7-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "3.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-3.7-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "3.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the data inventory, classification, ownership, and lifecycle authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把数据清单、分类、所有权与生命周期权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-3.7-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "3.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle created/collected → classified → approved use and flow → retained/held → disposed with verification.",
          "zh": "对生命周期“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-3.7-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "3.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence.",
          "zh": "对生命周期“发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-3.7-DAT-08",
          "local_code": "DAT-08",
          "display_code": "D08",
          "safeguard_id": "3.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle draft → reviewed → approved → effective → exception/withdrawn → superseded.",
          "zh": "对生命周期“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-3.7-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "3.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 3.1, Safeguard 3.2; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 3.1、Safeguard 3.2 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-3.7-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "3.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-3.7-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "3.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-3.7-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "3.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-3.7-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "3.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile data catalogs, schemas, DLP discovery, cloud/SaaS APIs, owner attestations, flow records, backup catalogs, and legal/privacy schedules and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 数据目录、模式、DLP 发现、云/SaaS API、责任人确认、流向记录、备份目录及法律与隐私期限，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-3.7-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "3.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Require every connector carrying data identity, sensitivity, owner, purpose, location, flow, access, retention, copy, derivation, and disposal state to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 数据身份、敏感度、责任人、目的、位置、流向、访问、保留、副本、派生与销毁状态 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-3.7-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "3.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Require every connector carrying observed, approved, unapproved, ownerless, stale, duplicate, and retired object identity to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 已观测、已批准、未批准、无责任人、陈旧、重复和已退役对象身份 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-3.7-INT-08",
          "local_code": "INT-08",
          "display_code": "I08",
          "safeguard_id": "3.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Require every connector carrying a documented decision system with policy, process, procedure, accountable owner, approval, and review to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 包含策略、流程、程序、责任人、审批和复核的文档化决策系统 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-3.7-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "3.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Publish decision rules, examples, default class, owner and reclassification process, then encode labels in catalogs, repositories, documents and policy engines.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“公布判断规则、示例、默认级别、责任人和重分类流程，在目录、仓库、文档和策略引擎中编码标签；把法规标签映射进体系但保留其独立义务，每年及数据/用途重大变化时复核。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-3.7-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "3.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-3.7-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "3.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-3.7-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "3.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-3.7-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "3.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the data inventory, classification, ownership, and lifecycle authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在数据清单、分类、所有权与生命周期权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-3.7-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "3.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Implement the explicit state machine created/collected → classified → approved use and flow → retained/held → disposed with verification; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-3.7-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "3.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Implement the explicit state machine discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-3.7-CTL-08",
          "local_code": "CTL-08",
          "display_code": "C08",
          "safeguard_id": "3.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Implement the explicit state machine draft → reviewed → approved → effective → exception/withdrawn → superseded; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-3.7-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "3.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (annually); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（annually）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-3.7-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "3.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-3.7-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "3.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-3.7-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "3.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-3.7-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "3.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in sensitive and business data, replicas, logs, backups, exports, derived data, AI corpora, keys, and data flows; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 敏感与业务数据、副本、日志、备份、导出、派生数据、AI 语料、密钥和数据流 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-3.7-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "3.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for created/collected → classified → approved use and flow → retained/held → disposed with verification; alert before each deadline becomes overdue.",
          "zh": "为“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-3.7-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "3.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence; alert before each deadline becomes overdue.",
          "zh": "为“发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-3.7-TIM-08",
          "local_code": "TIM-08",
          "display_code": "T08",
          "safeguard_id": "3.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for draft → reviewed → approved → effective → exception/withdrawn → superseded; alert before each deadline becomes overdue.",
          "zh": "为“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-3.7-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "3.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: ““Confidential” with no handling consequence is decorative.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“没有处理后果的“机密”只是装饰。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-3.7-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "3.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-3.7-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "3.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-3.7-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "3.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-3.7-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "3.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat unknown classification, encrypted or tokenized copies, cross-region replicas, immutable backups, derived data, litigation holds, and provider deletion limits as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 未知分类、加密或令牌化副本、跨地域副本、不可变备份、派生数据、诉讼保全及提供商删除限制 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-3.7-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "3.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Treat unstructured and derived data, logs, caches, backups, exports, client-side copies, cross-region processing, AI corpora, holds, and provider residues as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 非结构化与派生数据、日志、缓存、备份、导出、客户端副本、跨地域处理、AI 语料、保全和提供商残留 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-3.7-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "3.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Treat dormant, ephemeral, disconnected, externally managed, provider-held, aliased, cloned, and cross-tenant objects as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 休眠、短生、离线、外部托管、提供商持有、别名、克隆和跨租户对象 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-3.7-EXC-08",
          "local_code": "EXC-08",
          "display_code": "X08",
          "safeguard_id": "3.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Treat missing policy clauses, conflicting authorities, local deviations, obsolete documentation, and decisions made outside the governed workflow as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 策略条款缺失、权限冲突、本地偏离、文档过期及绕过治理流程的决策 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-3.7-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "3.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Give independent reviewers representative and ambiguous samples and measure agreement with the owner-approved answer.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“给独立评审者代表性和模糊样本，测量与责任人批准答案的一致度。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-3.7-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "3.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-3.7-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "3.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 2 pinned CAS metric branch(es), 10 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 2 个指标分支、10 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-3.7-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "3.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-3.7-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "3.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the data inventory, classification, ownership, and lifecycle authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以数据清单、分类、所有权与生命周期权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-3.7-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "3.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Publish known, unknown, classified, ownerless, over-retained, prematurely deleted, unapproved copy, blocked flow, held, and disposal-verified data sets with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已知、未知、已分类、无责任人、超期保留、过早删除、未批准副本、被阻断流、保全及销毁已验证数据集，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-3.7-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "3.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Publish matched, missing, duplicate, stale, ownerless, unapproved, unevaluable, and retired-without-proof counts with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 匹配、缺失、重复、陈旧、无责任人、未批准、不可评估及无证明退役数量，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-3.7-EVD-08",
          "local_code": "EVD-08",
          "display_code": "E08",
          "safeguard_id": "3.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Publish clause coverage, owner and reviewer completeness, approval age, triggered reviews, deviations, overdue actions, and superseded versions still in use with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 条款覆盖、责任人与复核人完整性、批准年龄、触发式复核、偏离、逾期行动及仍在使用的旧版本，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-3.7-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "3.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-3.7-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "3.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-3.7-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "3.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-3.7-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "3.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-3.7-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "3.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the data inventory, classification, ownership, and lifecycle authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护数据清单、分类、所有权与生命周期权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-3.7-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "3.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Restrict authority to change created/collected → classified → approved use and flow → retained/held → disposed with verification; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-3.7-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "3.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Restrict authority to change discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-3.7-SEC-08",
          "local_code": "SEC-08",
          "display_code": "S08",
          "safeguard_id": "3.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Restrict authority to change draft → reviewed → approved → effective → exception/withdrawn → superseded; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-3.7-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "3.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-3.7-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "3.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-3.7-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "3.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-3.7-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "3.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-3.7-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "3.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise approved and unapproved copies, allowed and denied readers, retention boundaries, deletion verification, key loss, and cross-boundary transfers through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 获批与未批准副本、允许与拒绝读取、保留边界、删除验证、密钥丢失和跨边界传输，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-3.7-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "3.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Run the positive control an approved data set following its declared use, access, transfer, retention, and disposal path; exercise negative, stale, duplicate, bypass, and outage controls including an unknown or misclassified copy, forbidden reader or flow, early deletion, expired retention, failed disposal, and provider residue.",
          "zh": "运行正向控制“按声明用途、访问、传输、保留和销毁路径流转的获批数据集”，并执行包含“未知或误分类副本、禁止读取者或流向、过早删除、保留过期、销毁失败和提供商残留”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-3.7-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "3.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Run the positive control a seeded approved object reconciled from two independent sources; exercise negative, stale, duplicate, bypass, and outage controls including an unknown object, duplicate identity, stale record, vanished object, failed source, and cross-tenant collision.",
          "zh": "运行正向控制“从两个独立来源对账的一项植入已批准对象”，并执行包含“未知对象、重复身份、陈旧记录、突然消失对象、失效来源和跨租户碰撞”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-3.7-TST-08",
          "local_code": "TST-08",
          "display_code": "V08",
          "safeguard_id": "3.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Run the positive control an approved current process used for a representative decision; exercise negative, stale, duplicate, bypass, and outage controls including an obsolete version, missing approver, undocumented deviation, overdue review, and bypassed workflow.",
          "zh": "运行正向控制“使用当前获批流程完成一项代表性决策”，并执行包含“旧版本、审批人缺失、未记录偏离、逾期复核和绕过流程”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-3.7-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "3.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-3.7-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "3.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-3.7-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "3.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-3.7-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "3.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-3.7-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "3.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever data catalogs, schemas, DLP discovery, cloud/SaaS APIs, owner attestations, flow records, backup catalogs, and legal/privacy schedules change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 数据目录、模式、DLP 发现、云/SaaS API、责任人确认、流向记录、备份目录及法律与隐私期限 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-3.7-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "3.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Use known, unknown, classified, ownerless, over-retained, prematurely deleted, unapproved copy, blocked flow, held, and disposal-verified data sets to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已知、未知、已分类、无责任人、超期保留、过早删除、未批准副本、被阻断流、保全及销毁已验证数据集 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-3.7-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "3.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Use matched, missing, duplicate, stale, ownerless, unapproved, unevaluable, and retired-without-proof counts to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 匹配、缺失、重复、陈旧、无责任人、未批准、不可评估及无证明退役数量 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-3.7-OPS-08",
          "local_code": "OPS-08",
          "display_code": "R08",
          "safeguard_id": "3.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Use clause coverage, owner and reviewer completeness, approval age, triggered reviews, deviations, overdue actions, and superseded versions still in use to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 条款覆盖、责任人与复核人完整性、批准年龄、触发式复核、偏离、逾期行动及仍在使用的旧版本 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "3.8",
      "control": 3,
      "title_en": "Document Data Flows",
      "title_zh": "数据流图",
      "first_ig": 2,
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Data",
      "security_function": "Identify",
      "patterns": [
        "data_lifecycle",
        "inventory"
      ],
      "expanded_complexity": true,
      "cas_context": {
        "dependencies": [
          "3.1",
          "3.2"
        ],
        "variables": [
          "GV12",
          "M1",
          "M2",
          "M3",
          "M4",
          "M5"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [
        "annually"
      ],
      "implementation_contract": {
        "en": {
          "scope": "Document where each material data set originates, moves, is transformed, crosses trust or jurisdiction boundaries and terminates, including APIs, queues, batch exports, email, analytics, backups, telemetry, SaaS/providers and AI retrieval/tool paths.",
          "build": "Generate flows from design records, service catalogs, gateway/mesh/cloud logs and owner interviews; bind source, destination, protocol, data class, purpose, controller/processor, region, protection and retention.",
          "proof": "Select high-risk flows and trace documentation against observed network/application events in both directions.",
          "boundary": "Encrypted traffic still has a flow and destination."
        },
        "zh": {
          "scope": "记录每个重要数据集从哪里产生、向哪里移动、如何转换、跨越哪些信任或司法边界、在哪里终止，覆盖 API、队列、批量导出、邮件、分析、备份、遥测、SaaS/服务商和 AI 检索/工具路径。",
          "build": "从设计记录、服务目录、网关/服务网格/云日志和责任人访谈生成流向，绑定源、目的、协议、数据级别、用途、控制者/处理者、地区、保护和保留。",
          "proof": "挑选高风险数据流，从文档到真实网络/应用事件双向追踪；新增一个测试集成验证台账/变更流程。",
          "boundary": "加密流量仍然有流向与目的。"
        }
      },
      "category_counts": {
        "outcome": 8,
        "scope": 8,
        "ownership": 8,
        "data": 8,
        "integration": 8,
        "control": 8,
        "timing": 8,
        "exception": 8,
        "evidence": 8,
        "security": 8,
        "testing": 8,
        "operations": 8
      },
      "requirement_count": 96,
      "requirements": [
        {
          "code": "CIS-3.8-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "3.8",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Document Data Flows; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“数据流图”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-3.8-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "3.8",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 3.8, official Asset Class Data, Security Function Identify, and IG2 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 3.8、官方资产类别“数据”、安全功能“识别”和首次出现的 IG2，并保存来源抓取日期。"
        },
        {
          "code": "CIS-3.8-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "3.8",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Document where each material data set originates, moves, is transformed, crosses trust or jurisdiction boundaries and terminates, including APIs, queues, batch exports, email, analytics, backups, telemetry, SaaS/providers and AI retrieval/tool paths.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“记录每个重要数据集从哪里产生、向哪里移动、如何转换、跨越哪些信任或司法边界、在哪里终止，覆盖 API、队列、批量导出、邮件、分析、备份、遥测、SaaS/服务商和 AI 检索/工具路径。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-3.8-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "3.8",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-3.8-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "3.8",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Document Data Flows to its operating object—sensitive and business data, replicas, logs, backups, exports, derived data, AI corpora, keys, and data flows—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“数据流图”连接到其运营对象——敏感与业务数据、副本、日志、备份、导出、派生数据、AI 语料、密钥和数据流——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-3.8-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "3.8",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "For Document Data Flows, express success as an observable decision over data identity, sensitivity, owner, purpose, location, flow, access, retention, copy, derivation, and disposal state; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“数据流图”，以 数据身份、敏感度、责任人、目的、位置、流向、访问、保留、副本、派生与销毁状态 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-3.8-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "3.8",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "For Document Data Flows, express success as an observable decision over observed, approved, unapproved, ownerless, stale, duplicate, and retired object identity; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“数据流图”，以 已观测、已批准、未批准、无责任人、陈旧、重复和已退役对象身份 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-3.8-OUT-08",
          "local_code": "OUT-08",
          "display_code": "O08",
          "safeguard_id": "3.8",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "For the expanded Document Data Flows scope, resolve conflicts among security, safety, privacy, legal, availability, customer, and operational objectives through an explicit risk decision.",
          "zh": "对“数据流图”的扩展范围，通过显式风险决策解决安全、安全生产、隐私、法律、可用性、客户和运营目标冲突。"
        },
        {
          "code": "CIS-3.8-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "3.8",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-3.8-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "3.8",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-3.8-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "3.8",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-3.8-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "3.8",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-3.8-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "3.8",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across unknown classification, encrypted or tokenized copies, cross-region replicas, immutable backups, derived data, litigation holds, and provider deletion limits; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 未知分类、加密或令牌化副本、跨地域副本、不可变备份、派生数据、诉讼保全及提供商删除限制 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-3.8-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "3.8",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Include unstructured and derived data, logs, caches, backups, exports, client-side copies, cross-region processing, AI corpora, holds, and provider residues in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 非结构化与派生数据、日志、缓存、备份、导出、客户端副本、跨地域处理、AI 语料、保全和提供商残留 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-3.8-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "3.8",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Include dormant, ephemeral, disconnected, externally managed, provider-held, aliased, cloned, and cross-tenant objects in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 休眠、短生、离线、外部托管、提供商持有、别名、克隆和跨租户对象 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-3.8-SCP-08",
          "local_code": "SCP-08",
          "display_code": "P08",
          "safeguard_id": "3.8",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Define nested scope at enterprise, business service, tenant, environment, platform, object, identity, data set, and transaction levels; prohibit a parent result from hiding a failing child.",
          "zh": "按企业、业务服务、租户、环境、平台、对象、身份、数据集和交易定义嵌套范围，禁止父级结果遮蔽失败子级。"
        },
        {
          "code": "CIS-3.8-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "3.8",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-3.8-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "3.8",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-3.8-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "3.8",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-3.8-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "3.8",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-3.8-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "3.8",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind data owners and custodians, product teams, privacy, legal, security, records management, and providers to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 数据责任人与托管方、产品团队、隐私、法务、安全、档案管理和服务提供商 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-3.8-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "3.8",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Name who may transition created/collected → classified → approved use and flow → retained/held → disposed with verification, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-3.8-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "3.8",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Name who may transition discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-3.8-OWN-08",
          "local_code": "OWN-08",
          "display_code": "W08",
          "safeguard_id": "3.8",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Model delegated authority, quorum or dual approval where warranted, escalation deadlines, provider handoffs, conflict resolution, and executive risk acceptance.",
          "zh": "建模委派权限、必要时的双人或法定人数审批、升级期限、提供商交接、冲突解决和管理层风险接受。"
        },
        {
          "code": "CIS-3.8-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "3.8",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-3.8-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "3.8",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-3.8-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "3.8",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV12, M1, M2, M3, M4, M5) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV12, M1, M2, M3, M4, M5）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-3.8-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "3.8",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-3.8-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "3.8",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the data inventory, classification, ownership, and lifecycle authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把数据清单、分类、所有权与生命周期权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-3.8-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "3.8",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle created/collected → classified → approved use and flow → retained/held → disposed with verification.",
          "zh": "对生命周期“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-3.8-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "3.8",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence.",
          "zh": "对生命周期“发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-3.8-DAT-08",
          "local_code": "DAT-08",
          "display_code": "D08",
          "safeguard_id": "3.8",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Version schemas and state transitions with migration, backfill, deduplication, lineage, historical denominator, deletion, and rollback semantics.",
          "zh": "对模式和状态转换做版本管理，定义迁移、回填、去重、血缘、历史分母、删除和回滚语义。"
        },
        {
          "code": "CIS-3.8-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "3.8",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 3.1, Safeguard 3.2; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 3.1、Safeguard 3.2 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-3.8-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "3.8",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-3.8-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "3.8",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-3.8-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "3.8",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-3.8-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "3.8",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile data catalogs, schemas, DLP discovery, cloud/SaaS APIs, owner attestations, flow records, backup catalogs, and legal/privacy schedules and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 数据目录、模式、DLP 发现、云/SaaS API、责任人确认、流向记录、备份目录及法律与隐私期限，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-3.8-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "3.8",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Require every connector carrying data identity, sensitivity, owner, purpose, location, flow, access, retention, copy, derivation, and disposal state to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 数据身份、敏感度、责任人、目的、位置、流向、访问、保留、副本、派生与销毁状态 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-3.8-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "3.8",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Require every connector carrying observed, approved, unapproved, ownerless, stale, duplicate, and retired object identity to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 已观测、已批准、未批准、无责任人、陈旧、重复和已退役对象身份 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-3.8-INT-08",
          "local_code": "INT-08",
          "display_code": "I08",
          "safeguard_id": "3.8",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Define consistency rules across disagreeing sources, source precedence, confidence, reconciliation queues, dead-letter handling, reprocessing, and end-to-end trace identity.",
          "zh": "定义冲突来源的一致性、优先级、置信度、对账队列、死信、重处理和端到端追踪身份。"
        },
        {
          "code": "CIS-3.8-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "3.8",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Generate flows from design records, service catalogs, gateway/mesh/cloud logs and owner interviews; bind source, destination, protocol, data class, purpose, controller/processor, region, protection and retention.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“从设计记录、服务目录、网关/服务网格/云日志和责任人访谈生成流向，绑定源、目的、协议、数据级别、用途、控制者/处理者、地区、保护和保留。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-3.8-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "3.8",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-3.8-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "3.8",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-3.8-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "3.8",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-3.8-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "3.8",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the data inventory, classification, ownership, and lifecycle authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在数据清单、分类、所有权与生命周期权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-3.8-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "3.8",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Implement the explicit state machine created/collected → classified → approved use and flow → retained/held → disposed with verification; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-3.8-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "3.8",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Implement the explicit state machine discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-3.8-CTL-08",
          "local_code": "CTL-08",
          "display_code": "C08",
          "safeguard_id": "3.8",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Specify concurrent decisions, partial success, compensating transactions, repeated requests, stale policy, dependency outage, and recovery from an interrupted state transition.",
          "zh": "定义并发决策、部分成功、补偿事务、重复请求、陈旧策略、依赖中断和中途状态转换恢复。"
        },
        {
          "code": "CIS-3.8-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "3.8",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (annually); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（annually）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-3.8-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "3.8",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-3.8-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "3.8",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-3.8-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "3.8",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-3.8-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "3.8",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in sensitive and business data, replicas, logs, backups, exports, derived data, AI corpora, keys, and data flows; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 敏感与业务数据、副本、日志、备份、导出、派生数据、AI 语料、密钥和数据流 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-3.8-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "3.8",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for created/collected → classified → approved use and flow → retained/held → disposed with verification; alert before each deadline becomes overdue.",
          "zh": "为“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-3.8-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "3.8",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence; alert before each deadline becomes overdue.",
          "zh": "为“发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-3.8-TIM-08",
          "local_code": "TIM-08",
          "display_code": "T08",
          "safeguard_id": "3.8",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Allocate an end-to-end SLO budget across discovery, collection, processing, approval, enforcement, verification, and closure; prioritize overdue work by consequence and exposure.",
          "zh": "把端到端 SLO 预算分配到发现、采集、处理、审批、执行、验证和关闭，并按后果与暴露排列逾期工作。"
        },
        {
          "code": "CIS-3.8-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "3.8",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “Encrypted traffic still has a flow and destination.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“加密流量仍然有流向与目的。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-3.8-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "3.8",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-3.8-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "3.8",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-3.8-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "3.8",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-3.8-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "3.8",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat unknown classification, encrypted or tokenized copies, cross-region replicas, immutable backups, derived data, litigation holds, and provider deletion limits as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 未知分类、加密或令牌化副本、跨地域副本、不可变备份、派生数据、诉讼保全及提供商删除限制 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-3.8-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "3.8",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Treat unstructured and derived data, logs, caches, backups, exports, client-side copies, cross-region processing, AI corpora, holds, and provider residues as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 非结构化与派生数据、日志、缓存、备份、导出、客户端副本、跨地域处理、AI 语料、保全和提供商残留 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-3.8-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "3.8",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Treat dormant, ephemeral, disconnected, externally managed, provider-held, aliased, cloned, and cross-tenant objects as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 休眠、短生、离线、外部托管、提供商持有、别名、克隆和跨租户对象 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-3.8-EXC-08",
          "local_code": "EXC-08",
          "display_code": "X08",
          "safeguard_id": "3.8",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Exercise compound failures where an exception, stale source, provider outage, unavailable owner, and degraded control overlap; define one safe command and one accountable decision.",
          "zh": "演练例外、陈旧来源、提供商中断、责任人不可用和控制降级同时出现的复合故障，明确一条安全指令和一个责任决策。"
        },
        {
          "code": "CIS-3.8-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "3.8",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Select high-risk flows and trace documentation against observed network/application events in both directions.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“挑选高风险数据流，从文档到真实网络/应用事件双向追踪；新增一个测试集成验证台账/变更流程。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-3.8-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "3.8",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-3.8-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "3.8",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 6 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、6 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-3.8-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "3.8",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-3.8-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "3.8",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the data inventory, classification, ownership, and lifecycle authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以数据清单、分类、所有权与生命周期权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-3.8-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "3.8",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Publish known, unknown, classified, ownerless, over-retained, prematurely deleted, unapproved copy, blocked flow, held, and disposal-verified data sets with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已知、未知、已分类、无责任人、超期保留、过早删除、未批准副本、被阻断流、保全及销毁已验证数据集，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-3.8-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "3.8",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Publish matched, missing, duplicate, stale, ownerless, unapproved, unevaluable, and retired-without-proof counts with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 匹配、缺失、重复、陈旧、无责任人、未批准、不可评估及无证明退役数量，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-3.8-EVD-08",
          "local_code": "EVD-08",
          "display_code": "E08",
          "safeguard_id": "3.8",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Require an independent party to reconstruct the decision from source receipts and reproduce the population, state transition, calculation, test result, exception, and final closure.",
          "zh": "要求独立人员使用来源回执重建决策，并复现总体、状态转换、计算、测试结果、例外和最终关闭。"
        },
        {
          "code": "CIS-3.8-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "3.8",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-3.8-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "3.8",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-3.8-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "3.8",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-3.8-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "3.8",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-3.8-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "3.8",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the data inventory, classification, ownership, and lifecycle authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护数据清单、分类、所有权与生命周期权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-3.8-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "3.8",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Restrict authority to change created/collected → classified → approved use and flow → retained/held → disposed with verification; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-3.8-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "3.8",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Restrict authority to change discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-3.8-SEC-08",
          "local_code": "SEC-08",
          "display_code": "S08",
          "safeguard_id": "3.8",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Threat-model the implementation system itself: forged evidence, poisoned inventory, privilege abuse, cross-tenant confusion, policy rollback, audit deletion, denial of service, and recovery compromise.",
          "zh": "威胁建模实施系统自身：伪造证据、污染清单、权限滥用、跨租户混淆、策略回滚、审计删除、拒绝服务和恢复失陷。"
        },
        {
          "code": "CIS-3.8-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "3.8",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-3.8-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "3.8",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-3.8-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "3.8",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-3.8-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "3.8",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-3.8-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "3.8",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise approved and unapproved copies, allowed and denied readers, retention boundaries, deletion verification, key loss, and cross-boundary transfers through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 获批与未批准副本、允许与拒绝读取、保留边界、删除验证、密钥丢失和跨边界传输，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-3.8-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "3.8",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Run the positive control an approved data set following its declared use, access, transfer, retention, and disposal path; exercise negative, stale, duplicate, bypass, and outage controls including an unknown or misclassified copy, forbidden reader or flow, early deletion, expired retention, failed disposal, and provider residue.",
          "zh": "运行正向控制“按声明用途、访问、传输、保留和销毁路径流转的获批数据集”，并执行包含“未知或误分类副本、禁止读取者或流向、过早删除、保留过期、销毁失败和提供商残留”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-3.8-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "3.8",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Run the positive control a seeded approved object reconciled from two independent sources; exercise negative, stale, duplicate, bypass, and outage controls including an unknown object, duplicate identity, stale record, vanished object, failed source, and cross-tenant collision.",
          "zh": "运行正向控制“从两个独立来源对账的一项植入已批准对象”，并执行包含“未知对象、重复身份、陈旧记录、突然消失对象、失效来源和跨租户碰撞”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-3.8-TST-08",
          "local_code": "TST-08",
          "display_code": "V08",
          "safeguard_id": "3.8",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Build a pairwise platform-and-failure matrix, then add high-consequence multi-factor cases, historical regression, source substitution, red-team challenge, and assessor replay.",
          "zh": "建立平台—故障两两组合矩阵，再加入高后果多因素案例、历史回归、来源替换、红队挑战和评估方重放。"
        },
        {
          "code": "CIS-3.8-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "3.8",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-3.8-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "3.8",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-3.8-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "3.8",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-3.8-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "3.8",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-3.8-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "3.8",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever data catalogs, schemas, DLP discovery, cloud/SaaS APIs, owner attestations, flow records, backup catalogs, and legal/privacy schedules change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 数据目录、模式、DLP 发现、云/SaaS API、责任人确认、流向记录、备份目录及法律与隐私期限 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-3.8-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "3.8",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Use known, unknown, classified, ownerless, over-retained, prematurely deleted, unapproved copy, blocked flow, held, and disposal-verified data sets to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已知、未知、已分类、无责任人、超期保留、过早删除、未批准副本、被阻断流、保全及销毁已验证数据集 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-3.8-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "3.8",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Use matched, missing, duplicate, stale, ownerless, unapproved, unevaluable, and retired-without-proof counts to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 匹配、缺失、重复、陈旧、无责任人、未批准、不可评估及无证明退役数量 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-3.8-OPS-08",
          "local_code": "OPS-08",
          "display_code": "R08",
          "safeguard_id": "3.8",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Use canary deployment, kill criteria, rollback, backlog burn-down, exception reduction, source-quality targets, quarterly design review, and a measurable retirement plan.",
          "zh": "采用金丝雀、停止标准、回滚、积压燃尽、例外缩减、来源质量目标、季度设计复核和可量化退役计划。"
        }
      ]
    },
    {
      "id": "3.9",
      "control": 3,
      "title_en": "Encrypt Data on Removable Media",
      "title_zh": "可移动介质加密",
      "first_ig": 2,
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Data",
      "security_function": "Protect",
      "patterns": [
        "data_lifecycle",
        "encryption"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "1.1",
          "2.1",
          "4.1"
        ],
        "variables": [
          "GV1",
          "GV3",
          "GV5",
          "M1",
          "M2",
          "M3",
          "M4",
          "M5"
        ],
        "metric_branches": 1,
        "has_assumptions": true,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "The population includes authorized USB storage, external drives, memory cards and other removable media carrying enterprise data, plus endpoints allowed to mount them.",
          "build": "Default-deny removable storage, then issue managed encrypted media with hardware or software keys, strong authentication, inventory and custody.",
          "proof": "Insert approved encrypted, approved-but-unlocked, and unapproved/plain media into representative systems; verify mount/write decisions, encryption state, logs, key recovery and data readability off-device.",
          "boundary": "Installed host encryption leaves individual media writes unverified."
        },
        "zh": {
          "scope": "总体包括承载企业数据的授权 U 盘、移动硬盘、存储卡等介质，以及允许挂载它们的终端。",
          "build": "默认拒绝移动存储，只发放有硬件/软件加密、强认证、台账和保管链的受管介质。",
          "proof": "把批准加密介质、批准但未解锁介质和未批准明文介质插入代表系统，验证挂载/写入决定、加密状态、日志、密钥恢复和脱机可读性。",
          "boundary": "主机装了加密软件，不代表每次写入都加密。"
        }
      },
      "category_counts": {
        "outcome": 7,
        "scope": 7,
        "ownership": 7,
        "data": 7,
        "integration": 7,
        "control": 7,
        "timing": 7,
        "exception": 7,
        "evidence": 7,
        "security": 7,
        "testing": 7,
        "operations": 7
      },
      "requirement_count": 84,
      "requirements": [
        {
          "code": "CIS-3.9-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "3.9",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Encrypt Data on Removable Media; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“可移动介质加密”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-3.9-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "3.9",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 3.9, official Asset Class Data, Security Function Protect, and IG2 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 3.9、官方资产类别“数据”、安全功能“保护”和首次出现的 IG2，并保存来源抓取日期。"
        },
        {
          "code": "CIS-3.9-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "3.9",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “The population includes authorized USB storage, external drives, memory cards and other removable media carrying enterprise data, plus endpoints allowed to mount them.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“总体包括承载企业数据的授权 U 盘、移动硬盘、存储卡等介质，以及允许挂载它们的终端。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-3.9-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "3.9",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-3.9-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "3.9",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Encrypt Data on Removable Media to its operating object—sensitive and business data, replicas, logs, backups, exports, derived data, AI corpora, keys, and data flows—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“可移动介质加密”连接到其运营对象——敏感与业务数据、副本、日志、备份、导出、派生数据、AI 语料、密钥和数据流——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-3.9-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "3.9",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "For Encrypt Data on Removable Media, express success as an observable decision over data identity, sensitivity, owner, purpose, location, flow, access, retention, copy, derivation, and disposal state; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“可移动介质加密”，以 数据身份、敏感度、责任人、目的、位置、流向、访问、保留、副本、派生与销毁状态 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-3.9-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "3.9",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original encryption pattern analysis",
          "basis_zh": "SOSEC 原创 encryption 模式分析",
          "en": "For Encrypt Data on Removable Media, express success as an observable decision over plaintext exposure against a named loss, theft, interception, storage-administrator, provider, or cross-tenant threat; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“可移动介质加密”，以 针对丢失、盗窃、截获、存储管理员、提供商或跨租户威胁的明文暴露 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-3.9-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "3.9",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-3.9-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "3.9",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-3.9-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "3.9",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-3.9-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "3.9",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-3.9-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "3.9",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across unknown classification, encrypted or tokenized copies, cross-region replicas, immutable backups, derived data, litigation holds, and provider deletion limits; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 未知分类、加密或令牌化副本、跨地域副本、不可变备份、派生数据、诉讼保全及提供商删除限制 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-3.9-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "3.9",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Include unstructured and derived data, logs, caches, backups, exports, client-side copies, cross-region processing, AI corpora, holds, and provider residues in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 非结构化与派生数据、日志、缓存、备份、导出、客户端副本、跨地域处理、AI 语料、保全和提供商残留 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-3.9-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "3.9",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original encryption pattern analysis",
          "basis_zh": "SOSEC 原创 encryption 模式分析",
          "en": "Include unsupported endpoints, boot and unlocked state, alternate protocols, downgrade, copied data, key export, shared keys, backups, logs, and recovery in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 不支持终端、启动与解锁状态、替代协议、降级、数据副本、密钥导出、共享密钥、备份、日志和恢复 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-3.9-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "3.9",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-3.9-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "3.9",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-3.9-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "3.9",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-3.9-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "3.9",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-3.9-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "3.9",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind data owners and custodians, product teams, privacy, legal, security, records management, and providers to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 数据责任人与托管方、产品团队、隐私、法务、安全、档案管理和服务提供商 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-3.9-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "3.9",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Name who may transition created/collected → classified → approved use and flow → retained/held → disposed with verification, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-3.9-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "3.9",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original encryption pattern analysis",
          "basis_zh": "SOSEC 原创 encryption 模式分析",
          "en": "Name who may transition data identified → policy selected → keys provisioned → encryption enforced → use/decrypt authorized → keys rotated/revoked → data retired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 识别数据 → 选择策略 → 配发密钥 → 强制加密 → 授权使用/解密 → 轮换/撤销密钥 → 退役数据，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-3.9-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "3.9",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-3.9-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "3.9",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-3.9-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "3.9",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV1, GV3, GV5, M1, M2, M3, M4, M5) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV1, GV3, GV5, M1, M2, M3, M4, M5）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-3.9-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "3.9",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-3.9-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "3.9",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the data inventory, classification, ownership, and lifecycle authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把数据清单、分类、所有权与生命周期权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-3.9-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "3.9",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle created/collected → classified → approved use and flow → retained/held → disposed with verification.",
          "zh": "对生命周期“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-3.9-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "3.9",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original encryption pattern analysis",
          "basis_zh": "SOSEC 原创 encryption 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle data identified → policy selected → keys provisioned → encryption enforced → use/decrypt authorized → keys rotated/revoked → data retired.",
          "zh": "对生命周期“识别数据 → 选择策略 → 配发密钥 → 强制加密 → 授权使用/解密 → 轮换/撤销密钥 → 退役数据”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-3.9-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "3.9",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 1.1, Safeguard 2.1, Safeguard 4.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 1.1、Safeguard 2.1、Safeguard 4.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-3.9-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "3.9",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-3.9-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "3.9",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-3.9-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "3.9",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-3.9-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "3.9",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile data catalogs, schemas, DLP discovery, cloud/SaaS APIs, owner attestations, flow records, backup catalogs, and legal/privacy schedules and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 数据目录、模式、DLP 发现、云/SaaS API、责任人确认、流向记录、备份目录及法律与隐私期限，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-3.9-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "3.9",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Require every connector carrying data identity, sensitivity, owner, purpose, location, flow, access, retention, copy, derivation, and disposal state to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 数据身份、敏感度、责任人、目的、位置、流向、访问、保留、副本、派生与销毁状态 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-3.9-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "3.9",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original encryption pattern analysis",
          "basis_zh": "SOSEC 原创 encryption 模式分析",
          "en": "Require every connector carrying plaintext exposure against a named loss, theft, interception, storage-administrator, provider, or cross-tenant threat to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 针对丢失、盗窃、截获、存储管理员、提供商或跨租户威胁的明文暴露 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-3.9-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "3.9",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Default-deny removable storage, then issue managed encrypted media with hardware or software keys, strong authentication, inventory and custody.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“默认拒绝移动存储，只发放有硬件/软件加密、强认证、台账和保管链的受管介质。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-3.9-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "3.9",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-3.9-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "3.9",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-3.9-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "3.9",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-3.9-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "3.9",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the data inventory, classification, ownership, and lifecycle authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在数据清单、分类、所有权与生命周期权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-3.9-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "3.9",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Implement the explicit state machine created/collected → classified → approved use and flow → retained/held → disposed with verification; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-3.9-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "3.9",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original encryption pattern analysis",
          "basis_zh": "SOSEC 原创 encryption 模式分析",
          "en": "Implement the explicit state machine data identified → policy selected → keys provisioned → encryption enforced → use/decrypt authorized → keys rotated/revoked → data retired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“识别数据 → 选择策略 → 配发密钥 → 强制加密 → 授权使用/解密 → 轮换/撤销密钥 → 退役数据”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-3.9-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "3.9",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-3.9-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "3.9",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-3.9-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "3.9",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-3.9-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "3.9",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-3.9-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "3.9",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in sensitive and business data, replicas, logs, backups, exports, derived data, AI corpora, keys, and data flows; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 敏感与业务数据、副本、日志、备份、导出、派生数据、AI 语料、密钥和数据流 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-3.9-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "3.9",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for created/collected → classified → approved use and flow → retained/held → disposed with verification; alert before each deadline becomes overdue.",
          "zh": "为“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-3.9-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "3.9",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original encryption pattern analysis",
          "basis_zh": "SOSEC 原创 encryption 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for data identified → policy selected → keys provisioned → encryption enforced → use/decrypt authorized → keys rotated/revoked → data retired; alert before each deadline becomes overdue.",
          "zh": "为“识别数据 → 选择策略 → 配发密钥 → 强制加密 → 授权使用/解密 → 轮换/撤销密钥 → 退役数据”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-3.9-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "3.9",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “Installed host encryption leaves individual media writes unverified.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“主机装了加密软件，不代表每次写入都加密。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-3.9-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "3.9",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-3.9-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "3.9",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-3.9-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "3.9",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-3.9-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "3.9",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat unknown classification, encrypted or tokenized copies, cross-region replicas, immutable backups, derived data, litigation holds, and provider deletion limits as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 未知分类、加密或令牌化副本、跨地域副本、不可变备份、派生数据、诉讼保全及提供商删除限制 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-3.9-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "3.9",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Treat unstructured and derived data, logs, caches, backups, exports, client-side copies, cross-region processing, AI corpora, holds, and provider residues as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 非结构化与派生数据、日志、缓存、备份、导出、客户端副本、跨地域处理、AI 语料、保全和提供商残留 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-3.9-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "3.9",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original encryption pattern analysis",
          "basis_zh": "SOSEC 原创 encryption 模式分析",
          "en": "Treat unsupported endpoints, boot and unlocked state, alternate protocols, downgrade, copied data, key export, shared keys, backups, logs, and recovery as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 不支持终端、启动与解锁状态、替代协议、降级、数据副本、密钥导出、共享密钥、备份、日志和恢复 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-3.9-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "3.9",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Insert approved encrypted, approved-but-unlocked, and unapproved/plain media into representative systems; verify mount/write decisions, encryption state, logs, key recovery and data readability off-device.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“把批准加密介质、批准但未解锁介质和未批准明文介质插入代表系统，验证挂载/写入决定、加密状态、日志、密钥恢复和脱机可读性。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-3.9-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "3.9",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-3.9-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "3.9",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 8 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、8 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-3.9-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "3.9",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-3.9-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "3.9",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the data inventory, classification, ownership, and lifecycle authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以数据清单、分类、所有权与生命周期权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-3.9-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "3.9",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Publish known, unknown, classified, ownerless, over-retained, prematurely deleted, unapproved copy, blocked flow, held, and disposal-verified data sets with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已知、未知、已分类、无责任人、超期保留、过早删除、未批准副本、被阻断流、保全及销毁已验证数据集，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-3.9-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "3.9",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original encryption pattern analysis",
          "basis_zh": "SOSEC 原创 encryption 模式分析",
          "en": "Publish eligible, protected, weak/legacy, keyless, shared-key, decryptable-by-unintended-party, exception, and recovery-tested objects with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 适用、已保护、弱/旧算法、无密钥、共享密钥、非预期主体可解密、例外及恢复已测试对象，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-3.9-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "3.9",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-3.9-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "3.9",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-3.9-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "3.9",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-3.9-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "3.9",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-3.9-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "3.9",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the data inventory, classification, ownership, and lifecycle authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护数据清单、分类、所有权与生命周期权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-3.9-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "3.9",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Restrict authority to change created/collected → classified → approved use and flow → retained/held → disposed with verification; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-3.9-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "3.9",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original encryption pattern analysis",
          "basis_zh": "SOSEC 原创 encryption 模式分析",
          "en": "Restrict authority to change data identified → policy selected → keys provisioned → encryption enforced → use/decrypt authorized → keys rotated/revoked → data retired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“识别数据 → 选择策略 → 配发密钥 → 强制加密 → 授权使用/解密 → 轮换/撤销密钥 → 退役数据”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-3.9-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "3.9",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-3.9-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "3.9",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-3.9-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "3.9",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-3.9-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "3.9",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-3.9-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "3.9",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise approved and unapproved copies, allowed and denied readers, retention boundaries, deletion verification, key loss, and cross-boundary transfers through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 获批与未批准副本、允许与拒绝读取、保留边界、删除验证、密钥丢失和跨边界传输，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-3.9-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "3.9",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Run the positive control an approved data set following its declared use, access, transfer, retention, and disposal path; exercise negative, stale, duplicate, bypass, and outage controls including an unknown or misclassified copy, forbidden reader or flow, early deletion, expired retention, failed disposal, and provider residue.",
          "zh": "运行正向控制“按声明用途、访问、传输、保留和销毁路径流转的获批数据集”，并执行包含“未知或误分类副本、禁止读取者或流向、过早删除、保留过期、销毁失败和提供商残留”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-3.9-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "3.9",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original encryption pattern analysis",
          "basis_zh": "SOSEC 原创 encryption 模式分析",
          "en": "Run the positive control authorized encryption, decryption, rotation, and recovery for representative data; exercise negative, stale, duplicate, bypass, and outage controls including plaintext path, protocol downgrade, lost device, copied storage, unauthorized principal, revoked key, failed rotation, and unavailable recovery key.",
          "zh": "运行正向控制“代表性数据的授权加密、解密、轮换和恢复”，并执行包含“明文路径、协议降级、设备丢失、复制存储、未授权主体、撤销密钥、轮换失败和恢复密钥不可用”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-3.9-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "3.9",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-3.9-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "3.9",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-3.9-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "3.9",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-3.9-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "3.9",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-3.9-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "3.9",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever data catalogs, schemas, DLP discovery, cloud/SaaS APIs, owner attestations, flow records, backup catalogs, and legal/privacy schedules change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 数据目录、模式、DLP 发现、云/SaaS API、责任人确认、流向记录、备份目录及法律与隐私期限 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-3.9-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "3.9",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Use known, unknown, classified, ownerless, over-retained, prematurely deleted, unapproved copy, blocked flow, held, and disposal-verified data sets to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已知、未知、已分类、无责任人、超期保留、过早删除、未批准副本、被阻断流、保全及销毁已验证数据集 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-3.9-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "3.9",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original encryption pattern analysis",
          "basis_zh": "SOSEC 原创 encryption 模式分析",
          "en": "Use eligible, protected, weak/legacy, keyless, shared-key, decryptable-by-unintended-party, exception, and recovery-tested objects to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 适用、已保护、弱/旧算法、无密钥、共享密钥、非预期主体可解密、例外及恢复已测试对象 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "3.10",
      "control": 3,
      "title_en": "Encrypt Sensitive Data in Transit",
      "title_zh": "传输中敏感数据加密",
      "first_ig": 2,
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Data",
      "security_function": "Protect",
      "patterns": [
        "data_lifecycle",
        "encryption"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "3.2",
          "4.1"
        ],
        "variables": [
          "GV3",
          "GV12",
          "M1",
          "M2",
          "M3"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "Include sensitive data crossing process, host, network, account, provider and physical trust boundaries through web, API, messaging, database, file transfer, email, remote administration and service-to-service traffic.",
          "build": "Define approved protocols, versions, cipher/key and certificate trust for each flow; enforce at clients and services, disable downgrade and plaintext listeners, authenticate both ends where risk requires, and manage private keys, renewal and revocation.",
          "proof": "Probe every representative endpoint and alternate route for plaintext, downgrade, expired/untrusted certificates, hostname failure and mutual-auth bypass.",
          "boundary": "TLS termination changes the boundary: traffic behind the terminator needs a new decision."
        },
        "zh": {
          "scope": "包括敏感数据通过 Web、API、消息、数据库、文件传输、邮件、远程管理和服务间通信，跨越进程、主机、网络、账号、服务商或物理信任边界的所有路径。",
          "build": "逐条数据流规定协议、版本、算法/密钥和证书信任，在客户端与服务端强制，关闭降级和明文监听；风险需要时做双向认证，管理私钥、续期和撤销。",
          "proof": "探测各代表端点和替代路由的明文、降级、证书过期/不可信、主机名失败与双向认证绕过；记录协商保护和应用授权。",
          "boundary": "TLS 终止会产生新边界，终止器后的链路需重新决策。"
        }
      },
      "category_counts": {
        "outcome": 7,
        "scope": 7,
        "ownership": 7,
        "data": 7,
        "integration": 7,
        "control": 7,
        "timing": 7,
        "exception": 7,
        "evidence": 7,
        "security": 7,
        "testing": 7,
        "operations": 7
      },
      "requirement_count": 84,
      "requirements": [
        {
          "code": "CIS-3.10-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "3.10",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Encrypt Sensitive Data in Transit; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“传输中敏感数据加密”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-3.10-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "3.10",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 3.10, official Asset Class Data, Security Function Protect, and IG2 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 3.10、官方资产类别“数据”、安全功能“保护”和首次出现的 IG2，并保存来源抓取日期。"
        },
        {
          "code": "CIS-3.10-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "3.10",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Include sensitive data crossing process, host, network, account, provider and physical trust boundaries through web, API, messaging, database, file transfer, email, remote administration and service-to-service traffic.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“包括敏感数据通过 Web、API、消息、数据库、文件传输、邮件、远程管理和服务间通信，跨越进程、主机、网络、账号、服务商或物理信任边界的所有路径。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-3.10-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "3.10",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-3.10-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "3.10",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Encrypt Sensitive Data in Transit to its operating object—sensitive and business data, replicas, logs, backups, exports, derived data, AI corpora, keys, and data flows—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“传输中敏感数据加密”连接到其运营对象——敏感与业务数据、副本、日志、备份、导出、派生数据、AI 语料、密钥和数据流——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-3.10-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "3.10",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "For Encrypt Sensitive Data in Transit, express success as an observable decision over data identity, sensitivity, owner, purpose, location, flow, access, retention, copy, derivation, and disposal state; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“传输中敏感数据加密”，以 数据身份、敏感度、责任人、目的、位置、流向、访问、保留、副本、派生与销毁状态 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-3.10-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "3.10",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original encryption pattern analysis",
          "basis_zh": "SOSEC 原创 encryption 模式分析",
          "en": "For Encrypt Sensitive Data in Transit, express success as an observable decision over plaintext exposure against a named loss, theft, interception, storage-administrator, provider, or cross-tenant threat; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“传输中敏感数据加密”，以 针对丢失、盗窃、截获、存储管理员、提供商或跨租户威胁的明文暴露 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-3.10-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "3.10",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-3.10-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "3.10",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-3.10-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "3.10",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-3.10-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "3.10",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-3.10-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "3.10",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across unknown classification, encrypted or tokenized copies, cross-region replicas, immutable backups, derived data, litigation holds, and provider deletion limits; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 未知分类、加密或令牌化副本、跨地域副本、不可变备份、派生数据、诉讼保全及提供商删除限制 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-3.10-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "3.10",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Include unstructured and derived data, logs, caches, backups, exports, client-side copies, cross-region processing, AI corpora, holds, and provider residues in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 非结构化与派生数据、日志、缓存、备份、导出、客户端副本、跨地域处理、AI 语料、保全和提供商残留 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-3.10-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "3.10",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original encryption pattern analysis",
          "basis_zh": "SOSEC 原创 encryption 模式分析",
          "en": "Include unsupported endpoints, boot and unlocked state, alternate protocols, downgrade, copied data, key export, shared keys, backups, logs, and recovery in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 不支持终端、启动与解锁状态、替代协议、降级、数据副本、密钥导出、共享密钥、备份、日志和恢复 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-3.10-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "3.10",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-3.10-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "3.10",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-3.10-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "3.10",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-3.10-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "3.10",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-3.10-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "3.10",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind data owners and custodians, product teams, privacy, legal, security, records management, and providers to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 数据责任人与托管方、产品团队、隐私、法务、安全、档案管理和服务提供商 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-3.10-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "3.10",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Name who may transition created/collected → classified → approved use and flow → retained/held → disposed with verification, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-3.10-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "3.10",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original encryption pattern analysis",
          "basis_zh": "SOSEC 原创 encryption 模式分析",
          "en": "Name who may transition data identified → policy selected → keys provisioned → encryption enforced → use/decrypt authorized → keys rotated/revoked → data retired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 识别数据 → 选择策略 → 配发密钥 → 强制加密 → 授权使用/解密 → 轮换/撤销密钥 → 退役数据，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-3.10-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "3.10",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-3.10-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "3.10",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-3.10-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "3.10",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV3, GV12, M1, M2, M3) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV3, GV12, M1, M2, M3）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-3.10-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "3.10",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-3.10-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "3.10",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the data inventory, classification, ownership, and lifecycle authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把数据清单、分类、所有权与生命周期权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-3.10-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "3.10",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle created/collected → classified → approved use and flow → retained/held → disposed with verification.",
          "zh": "对生命周期“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-3.10-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "3.10",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original encryption pattern analysis",
          "basis_zh": "SOSEC 原创 encryption 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle data identified → policy selected → keys provisioned → encryption enforced → use/decrypt authorized → keys rotated/revoked → data retired.",
          "zh": "对生命周期“识别数据 → 选择策略 → 配发密钥 → 强制加密 → 授权使用/解密 → 轮换/撤销密钥 → 退役数据”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-3.10-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "3.10",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 3.2, Safeguard 4.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 3.2、Safeguard 4.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-3.10-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "3.10",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-3.10-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "3.10",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-3.10-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "3.10",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-3.10-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "3.10",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile data catalogs, schemas, DLP discovery, cloud/SaaS APIs, owner attestations, flow records, backup catalogs, and legal/privacy schedules and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 数据目录、模式、DLP 发现、云/SaaS API、责任人确认、流向记录、备份目录及法律与隐私期限，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-3.10-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "3.10",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Require every connector carrying data identity, sensitivity, owner, purpose, location, flow, access, retention, copy, derivation, and disposal state to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 数据身份、敏感度、责任人、目的、位置、流向、访问、保留、副本、派生与销毁状态 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-3.10-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "3.10",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original encryption pattern analysis",
          "basis_zh": "SOSEC 原创 encryption 模式分析",
          "en": "Require every connector carrying plaintext exposure against a named loss, theft, interception, storage-administrator, provider, or cross-tenant threat to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 针对丢失、盗窃、截获、存储管理员、提供商或跨租户威胁的明文暴露 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-3.10-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "3.10",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Define approved protocols, versions, cipher/key and certificate trust for each flow; enforce at clients and services, disable downgrade and plaintext listeners, authenticate both ends where risk requires, and manage private keys, renewal and revocation.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“逐条数据流规定协议、版本、算法/密钥和证书信任，在客户端与服务端强制，关闭降级和明文监听；风险需要时做双向认证，管理私钥、续期和撤销。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-3.10-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "3.10",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-3.10-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "3.10",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-3.10-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "3.10",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-3.10-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "3.10",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the data inventory, classification, ownership, and lifecycle authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在数据清单、分类、所有权与生命周期权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-3.10-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "3.10",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Implement the explicit state machine created/collected → classified → approved use and flow → retained/held → disposed with verification; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-3.10-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "3.10",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original encryption pattern analysis",
          "basis_zh": "SOSEC 原创 encryption 模式分析",
          "en": "Implement the explicit state machine data identified → policy selected → keys provisioned → encryption enforced → use/decrypt authorized → keys rotated/revoked → data retired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“识别数据 → 选择策略 → 配发密钥 → 强制加密 → 授权使用/解密 → 轮换/撤销密钥 → 退役数据”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-3.10-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "3.10",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-3.10-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "3.10",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-3.10-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "3.10",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-3.10-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "3.10",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-3.10-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "3.10",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in sensitive and business data, replicas, logs, backups, exports, derived data, AI corpora, keys, and data flows; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 敏感与业务数据、副本、日志、备份、导出、派生数据、AI 语料、密钥和数据流 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-3.10-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "3.10",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for created/collected → classified → approved use and flow → retained/held → disposed with verification; alert before each deadline becomes overdue.",
          "zh": "为“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-3.10-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "3.10",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original encryption pattern analysis",
          "basis_zh": "SOSEC 原创 encryption 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for data identified → policy selected → keys provisioned → encryption enforced → use/decrypt authorized → keys rotated/revoked → data retired; alert before each deadline becomes overdue.",
          "zh": "为“识别数据 → 选择策略 → 配发密钥 → 强制加密 → 授权使用/解密 → 轮换/撤销密钥 → 退役数据”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-3.10-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "3.10",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “TLS termination changes the boundary: traffic behind the terminator needs a new decision.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“TLS 终止会产生新边界，终止器后的链路需重新决策。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-3.10-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "3.10",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-3.10-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "3.10",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-3.10-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "3.10",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-3.10-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "3.10",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat unknown classification, encrypted or tokenized copies, cross-region replicas, immutable backups, derived data, litigation holds, and provider deletion limits as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 未知分类、加密或令牌化副本、跨地域副本、不可变备份、派生数据、诉讼保全及提供商删除限制 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-3.10-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "3.10",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Treat unstructured and derived data, logs, caches, backups, exports, client-side copies, cross-region processing, AI corpora, holds, and provider residues as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 非结构化与派生数据、日志、缓存、备份、导出、客户端副本、跨地域处理、AI 语料、保全和提供商残留 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-3.10-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "3.10",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original encryption pattern analysis",
          "basis_zh": "SOSEC 原创 encryption 模式分析",
          "en": "Treat unsupported endpoints, boot and unlocked state, alternate protocols, downgrade, copied data, key export, shared keys, backups, logs, and recovery as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 不支持终端、启动与解锁状态、替代协议、降级、数据副本、密钥导出、共享密钥、备份、日志和恢复 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-3.10-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "3.10",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Probe every representative endpoint and alternate route for plaintext, downgrade, expired/untrusted certificates, hostname failure and mutual-auth bypass.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“探测各代表端点和替代路由的明文、降级、证书过期/不可信、主机名失败与双向认证绕过；记录协商保护和应用授权。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-3.10-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "3.10",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-3.10-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "3.10",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 5 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、5 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-3.10-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "3.10",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-3.10-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "3.10",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the data inventory, classification, ownership, and lifecycle authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以数据清单、分类、所有权与生命周期权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-3.10-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "3.10",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Publish known, unknown, classified, ownerless, over-retained, prematurely deleted, unapproved copy, blocked flow, held, and disposal-verified data sets with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已知、未知、已分类、无责任人、超期保留、过早删除、未批准副本、被阻断流、保全及销毁已验证数据集，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-3.10-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "3.10",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original encryption pattern analysis",
          "basis_zh": "SOSEC 原创 encryption 模式分析",
          "en": "Publish eligible, protected, weak/legacy, keyless, shared-key, decryptable-by-unintended-party, exception, and recovery-tested objects with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 适用、已保护、弱/旧算法、无密钥、共享密钥、非预期主体可解密、例外及恢复已测试对象，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-3.10-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "3.10",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-3.10-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "3.10",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-3.10-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "3.10",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-3.10-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "3.10",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-3.10-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "3.10",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the data inventory, classification, ownership, and lifecycle authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护数据清单、分类、所有权与生命周期权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-3.10-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "3.10",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Restrict authority to change created/collected → classified → approved use and flow → retained/held → disposed with verification; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-3.10-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "3.10",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original encryption pattern analysis",
          "basis_zh": "SOSEC 原创 encryption 模式分析",
          "en": "Restrict authority to change data identified → policy selected → keys provisioned → encryption enforced → use/decrypt authorized → keys rotated/revoked → data retired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“识别数据 → 选择策略 → 配发密钥 → 强制加密 → 授权使用/解密 → 轮换/撤销密钥 → 退役数据”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-3.10-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "3.10",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-3.10-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "3.10",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-3.10-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "3.10",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-3.10-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "3.10",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-3.10-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "3.10",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise approved and unapproved copies, allowed and denied readers, retention boundaries, deletion verification, key loss, and cross-boundary transfers through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 获批与未批准副本、允许与拒绝读取、保留边界、删除验证、密钥丢失和跨边界传输，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-3.10-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "3.10",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Run the positive control an approved data set following its declared use, access, transfer, retention, and disposal path; exercise negative, stale, duplicate, bypass, and outage controls including an unknown or misclassified copy, forbidden reader or flow, early deletion, expired retention, failed disposal, and provider residue.",
          "zh": "运行正向控制“按声明用途、访问、传输、保留和销毁路径流转的获批数据集”，并执行包含“未知或误分类副本、禁止读取者或流向、过早删除、保留过期、销毁失败和提供商残留”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-3.10-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "3.10",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original encryption pattern analysis",
          "basis_zh": "SOSEC 原创 encryption 模式分析",
          "en": "Run the positive control authorized encryption, decryption, rotation, and recovery for representative data; exercise negative, stale, duplicate, bypass, and outage controls including plaintext path, protocol downgrade, lost device, copied storage, unauthorized principal, revoked key, failed rotation, and unavailable recovery key.",
          "zh": "运行正向控制“代表性数据的授权加密、解密、轮换和恢复”，并执行包含“明文路径、协议降级、设备丢失、复制存储、未授权主体、撤销密钥、轮换失败和恢复密钥不可用”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-3.10-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "3.10",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-3.10-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "3.10",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-3.10-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "3.10",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-3.10-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "3.10",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-3.10-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "3.10",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever data catalogs, schemas, DLP discovery, cloud/SaaS APIs, owner attestations, flow records, backup catalogs, and legal/privacy schedules change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 数据目录、模式、DLP 发现、云/SaaS API、责任人确认、流向记录、备份目录及法律与隐私期限 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-3.10-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "3.10",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Use known, unknown, classified, ownerless, over-retained, prematurely deleted, unapproved copy, blocked flow, held, and disposal-verified data sets to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已知、未知、已分类、无责任人、超期保留、过早删除、未批准副本、被阻断流、保全及销毁已验证数据集 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-3.10-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "3.10",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original encryption pattern analysis",
          "basis_zh": "SOSEC 原创 encryption 模式分析",
          "en": "Use eligible, protected, weak/legacy, keyless, shared-key, decryptable-by-unintended-party, exception, and recovery-tested objects to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 适用、已保护、弱/旧算法、无密钥、共享密钥、非预期主体可解密、例外及恢复已测试对象 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "3.11",
      "control": 3,
      "title_en": "Encrypt Sensitive Data at Rest",
      "title_zh": "静态敏感数据加密",
      "first_ig": 2,
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Data",
      "security_function": "Protect",
      "patterns": [
        "data_lifecycle",
        "encryption"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "1.1",
          "2.1"
        ],
        "variables": [
          "GV1",
          "GV4",
          "GV5",
          "GV12",
          "GV19",
          "M1",
          "M2",
          "M3",
          "M4",
          "M5"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "Cover sensitive data in databases, object/block/file stores, application state, snapshots, replicas, search indexes, caches and backups on servers and providers.",
          "build": "Enable encryption at each storage service, separate key administration from data administration where needed, set rotation/revocation and recovery, restrict plaintext exports, and bind key policy to data classification and tenant/account.",
          "proof": "Inspect live storage and key policies, then test authorized read, unauthorized identity, direct-media or snapshot access, key disablement and restore.",
          "boundary": "The current CAS inputs and M3/M4/M5 references are internally inconsistent; do not automate them verbatim."
        },
        "zh": {
          "scope": "覆盖服务器和服务商上数据库、对象/块/文件存储、应用状态、快照、副本、搜索索引、缓存和备份中的敏感数据。",
          "build": "在每种存储启用加密，必要时分离密钥管理员与数据管理员，设置轮换、撤销、恢复，限制明文导出，并把密钥政策绑定数据分级与租户/账号；逐份记录是哪一层保护哪一副本。",
          "proof": "检查运行中的存储与密钥策略，测试授权读取、未授权身份、直接介质/快照访问、禁用密钥和恢复；以已发现存储为分母算加密覆盖，另报“数据与密钥由同一管理员控制”的比例。",
          "boundary": "CAS 的输入和 M3/M4/M5 引用互相矛盾，不能照抄自动化。"
        }
      },
      "category_counts": {
        "outcome": 7,
        "scope": 7,
        "ownership": 7,
        "data": 7,
        "integration": 7,
        "control": 7,
        "timing": 7,
        "exception": 7,
        "evidence": 7,
        "security": 7,
        "testing": 7,
        "operations": 7
      },
      "requirement_count": 84,
      "requirements": [
        {
          "code": "CIS-3.11-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "3.11",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Encrypt Sensitive Data at Rest; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“静态敏感数据加密”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-3.11-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "3.11",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 3.11, official Asset Class Data, Security Function Protect, and IG2 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 3.11、官方资产类别“数据”、安全功能“保护”和首次出现的 IG2，并保存来源抓取日期。"
        },
        {
          "code": "CIS-3.11-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "3.11",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Cover sensitive data in databases, object/block/file stores, application state, snapshots, replicas, search indexes, caches and backups on servers and providers.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“覆盖服务器和服务商上数据库、对象/块/文件存储、应用状态、快照、副本、搜索索引、缓存和备份中的敏感数据。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-3.11-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "3.11",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-3.11-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "3.11",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Encrypt Sensitive Data at Rest to its operating object—sensitive and business data, replicas, logs, backups, exports, derived data, AI corpora, keys, and data flows—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“静态敏感数据加密”连接到其运营对象——敏感与业务数据、副本、日志、备份、导出、派生数据、AI 语料、密钥和数据流——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-3.11-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "3.11",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "For Encrypt Sensitive Data at Rest, express success as an observable decision over data identity, sensitivity, owner, purpose, location, flow, access, retention, copy, derivation, and disposal state; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“静态敏感数据加密”，以 数据身份、敏感度、责任人、目的、位置、流向、访问、保留、副本、派生与销毁状态 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-3.11-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "3.11",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original encryption pattern analysis",
          "basis_zh": "SOSEC 原创 encryption 模式分析",
          "en": "For Encrypt Sensitive Data at Rest, express success as an observable decision over plaintext exposure against a named loss, theft, interception, storage-administrator, provider, or cross-tenant threat; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“静态敏感数据加密”，以 针对丢失、盗窃、截获、存储管理员、提供商或跨租户威胁的明文暴露 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-3.11-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "3.11",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-3.11-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "3.11",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-3.11-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "3.11",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-3.11-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "3.11",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-3.11-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "3.11",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across unknown classification, encrypted or tokenized copies, cross-region replicas, immutable backups, derived data, litigation holds, and provider deletion limits; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 未知分类、加密或令牌化副本、跨地域副本、不可变备份、派生数据、诉讼保全及提供商删除限制 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-3.11-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "3.11",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Include unstructured and derived data, logs, caches, backups, exports, client-side copies, cross-region processing, AI corpora, holds, and provider residues in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 非结构化与派生数据、日志、缓存、备份、导出、客户端副本、跨地域处理、AI 语料、保全和提供商残留 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-3.11-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "3.11",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original encryption pattern analysis",
          "basis_zh": "SOSEC 原创 encryption 模式分析",
          "en": "Include unsupported endpoints, boot and unlocked state, alternate protocols, downgrade, copied data, key export, shared keys, backups, logs, and recovery in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 不支持终端、启动与解锁状态、替代协议、降级、数据副本、密钥导出、共享密钥、备份、日志和恢复 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-3.11-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "3.11",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-3.11-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "3.11",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-3.11-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "3.11",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-3.11-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "3.11",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-3.11-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "3.11",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind data owners and custodians, product teams, privacy, legal, security, records management, and providers to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 数据责任人与托管方、产品团队、隐私、法务、安全、档案管理和服务提供商 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-3.11-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "3.11",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Name who may transition created/collected → classified → approved use and flow → retained/held → disposed with verification, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-3.11-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "3.11",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original encryption pattern analysis",
          "basis_zh": "SOSEC 原创 encryption 模式分析",
          "en": "Name who may transition data identified → policy selected → keys provisioned → encryption enforced → use/decrypt authorized → keys rotated/revoked → data retired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 识别数据 → 选择策略 → 配发密钥 → 强制加密 → 授权使用/解密 → 轮换/撤销密钥 → 退役数据，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-3.11-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "3.11",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-3.11-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "3.11",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-3.11-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "3.11",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV1, GV4, GV5, GV12, GV19, M1, M2, M3, M4, M5) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV1, GV4, GV5, GV12, GV19, M1, M2, M3, M4, M5）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-3.11-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "3.11",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-3.11-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "3.11",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the data inventory, classification, ownership, and lifecycle authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把数据清单、分类、所有权与生命周期权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-3.11-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "3.11",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle created/collected → classified → approved use and flow → retained/held → disposed with verification.",
          "zh": "对生命周期“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-3.11-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "3.11",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original encryption pattern analysis",
          "basis_zh": "SOSEC 原创 encryption 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle data identified → policy selected → keys provisioned → encryption enforced → use/decrypt authorized → keys rotated/revoked → data retired.",
          "zh": "对生命周期“识别数据 → 选择策略 → 配发密钥 → 强制加密 → 授权使用/解密 → 轮换/撤销密钥 → 退役数据”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-3.11-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "3.11",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 1.1, Safeguard 2.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 1.1、Safeguard 2.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-3.11-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "3.11",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-3.11-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "3.11",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-3.11-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "3.11",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-3.11-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "3.11",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile data catalogs, schemas, DLP discovery, cloud/SaaS APIs, owner attestations, flow records, backup catalogs, and legal/privacy schedules and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 数据目录、模式、DLP 发现、云/SaaS API、责任人确认、流向记录、备份目录及法律与隐私期限，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-3.11-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "3.11",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Require every connector carrying data identity, sensitivity, owner, purpose, location, flow, access, retention, copy, derivation, and disposal state to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 数据身份、敏感度、责任人、目的、位置、流向、访问、保留、副本、派生与销毁状态 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-3.11-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "3.11",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original encryption pattern analysis",
          "basis_zh": "SOSEC 原创 encryption 模式分析",
          "en": "Require every connector carrying plaintext exposure against a named loss, theft, interception, storage-administrator, provider, or cross-tenant threat to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 针对丢失、盗窃、截获、存储管理员、提供商或跨租户威胁的明文暴露 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-3.11-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "3.11",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Enable encryption at each storage service, separate key administration from data administration where needed, set rotation/revocation and recovery, restrict plaintext exports, and bind key policy to data classification and tenant/account.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“在每种存储启用加密，必要时分离密钥管理员与数据管理员，设置轮换、撤销、恢复，限制明文导出，并把密钥政策绑定数据分级与租户/账号；逐份记录是哪一层保护哪一副本。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-3.11-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "3.11",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-3.11-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "3.11",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-3.11-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "3.11",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-3.11-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "3.11",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the data inventory, classification, ownership, and lifecycle authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在数据清单、分类、所有权与生命周期权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-3.11-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "3.11",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Implement the explicit state machine created/collected → classified → approved use and flow → retained/held → disposed with verification; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-3.11-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "3.11",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original encryption pattern analysis",
          "basis_zh": "SOSEC 原创 encryption 模式分析",
          "en": "Implement the explicit state machine data identified → policy selected → keys provisioned → encryption enforced → use/decrypt authorized → keys rotated/revoked → data retired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“识别数据 → 选择策略 → 配发密钥 → 强制加密 → 授权使用/解密 → 轮换/撤销密钥 → 退役数据”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-3.11-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "3.11",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-3.11-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "3.11",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-3.11-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "3.11",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-3.11-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "3.11",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-3.11-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "3.11",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in sensitive and business data, replicas, logs, backups, exports, derived data, AI corpora, keys, and data flows; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 敏感与业务数据、副本、日志、备份、导出、派生数据、AI 语料、密钥和数据流 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-3.11-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "3.11",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for created/collected → classified → approved use and flow → retained/held → disposed with verification; alert before each deadline becomes overdue.",
          "zh": "为“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-3.11-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "3.11",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original encryption pattern analysis",
          "basis_zh": "SOSEC 原创 encryption 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for data identified → policy selected → keys provisioned → encryption enforced → use/decrypt authorized → keys rotated/revoked → data retired; alert before each deadline becomes overdue.",
          "zh": "为“识别数据 → 选择策略 → 配发密钥 → 强制加密 → 授权使用/解密 → 轮换/撤销密钥 → 退役数据”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-3.11-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "3.11",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “The current CAS inputs and M3/M4/M5 references are internally inconsistent; do not automate them verbatim.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“CAS 的输入和 M3/M4/M5 引用互相矛盾，不能照抄自动化。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-3.11-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "3.11",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-3.11-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "3.11",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-3.11-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "3.11",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-3.11-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "3.11",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat unknown classification, encrypted or tokenized copies, cross-region replicas, immutable backups, derived data, litigation holds, and provider deletion limits as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 未知分类、加密或令牌化副本、跨地域副本、不可变备份、派生数据、诉讼保全及提供商删除限制 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-3.11-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "3.11",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Treat unstructured and derived data, logs, caches, backups, exports, client-side copies, cross-region processing, AI corpora, holds, and provider residues as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 非结构化与派生数据、日志、缓存、备份、导出、客户端副本、跨地域处理、AI 语料、保全和提供商残留 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-3.11-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "3.11",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original encryption pattern analysis",
          "basis_zh": "SOSEC 原创 encryption 模式分析",
          "en": "Treat unsupported endpoints, boot and unlocked state, alternate protocols, downgrade, copied data, key export, shared keys, backups, logs, and recovery as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 不支持终端、启动与解锁状态、替代协议、降级、数据副本、密钥导出、共享密钥、备份、日志和恢复 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-3.11-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "3.11",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Inspect live storage and key policies, then test authorized read, unauthorized identity, direct-media or snapshot access, key disablement and restore.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“检查运行中的存储与密钥策略，测试授权读取、未授权身份、直接介质/快照访问、禁用密钥和恢复；以已发现存储为分母算加密覆盖，另报“数据与密钥由同一管理员控制”的比例。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-3.11-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "3.11",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-3.11-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "3.11",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 10 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、10 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-3.11-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "3.11",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-3.11-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "3.11",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the data inventory, classification, ownership, and lifecycle authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以数据清单、分类、所有权与生命周期权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-3.11-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "3.11",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Publish known, unknown, classified, ownerless, over-retained, prematurely deleted, unapproved copy, blocked flow, held, and disposal-verified data sets with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已知、未知、已分类、无责任人、超期保留、过早删除、未批准副本、被阻断流、保全及销毁已验证数据集，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-3.11-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "3.11",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original encryption pattern analysis",
          "basis_zh": "SOSEC 原创 encryption 模式分析",
          "en": "Publish eligible, protected, weak/legacy, keyless, shared-key, decryptable-by-unintended-party, exception, and recovery-tested objects with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 适用、已保护、弱/旧算法、无密钥、共享密钥、非预期主体可解密、例外及恢复已测试对象，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-3.11-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "3.11",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-3.11-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "3.11",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-3.11-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "3.11",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-3.11-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "3.11",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-3.11-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "3.11",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the data inventory, classification, ownership, and lifecycle authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护数据清单、分类、所有权与生命周期权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-3.11-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "3.11",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Restrict authority to change created/collected → classified → approved use and flow → retained/held → disposed with verification; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-3.11-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "3.11",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original encryption pattern analysis",
          "basis_zh": "SOSEC 原创 encryption 模式分析",
          "en": "Restrict authority to change data identified → policy selected → keys provisioned → encryption enforced → use/decrypt authorized → keys rotated/revoked → data retired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“识别数据 → 选择策略 → 配发密钥 → 强制加密 → 授权使用/解密 → 轮换/撤销密钥 → 退役数据”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-3.11-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "3.11",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-3.11-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "3.11",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-3.11-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "3.11",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-3.11-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "3.11",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-3.11-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "3.11",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise approved and unapproved copies, allowed and denied readers, retention boundaries, deletion verification, key loss, and cross-boundary transfers through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 获批与未批准副本、允许与拒绝读取、保留边界、删除验证、密钥丢失和跨边界传输，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-3.11-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "3.11",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Run the positive control an approved data set following its declared use, access, transfer, retention, and disposal path; exercise negative, stale, duplicate, bypass, and outage controls including an unknown or misclassified copy, forbidden reader or flow, early deletion, expired retention, failed disposal, and provider residue.",
          "zh": "运行正向控制“按声明用途、访问、传输、保留和销毁路径流转的获批数据集”，并执行包含“未知或误分类副本、禁止读取者或流向、过早删除、保留过期、销毁失败和提供商残留”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-3.11-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "3.11",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original encryption pattern analysis",
          "basis_zh": "SOSEC 原创 encryption 模式分析",
          "en": "Run the positive control authorized encryption, decryption, rotation, and recovery for representative data; exercise negative, stale, duplicate, bypass, and outage controls including plaintext path, protocol downgrade, lost device, copied storage, unauthorized principal, revoked key, failed rotation, and unavailable recovery key.",
          "zh": "运行正向控制“代表性数据的授权加密、解密、轮换和恢复”，并执行包含“明文路径、协议降级、设备丢失、复制存储、未授权主体、撤销密钥、轮换失败和恢复密钥不可用”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-3.11-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "3.11",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-3.11-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "3.11",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-3.11-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "3.11",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-3.11-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "3.11",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-3.11-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "3.11",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever data catalogs, schemas, DLP discovery, cloud/SaaS APIs, owner attestations, flow records, backup catalogs, and legal/privacy schedules change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 数据目录、模式、DLP 发现、云/SaaS API、责任人确认、流向记录、备份目录及法律与隐私期限 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-3.11-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "3.11",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Use known, unknown, classified, ownerless, over-retained, prematurely deleted, unapproved copy, blocked flow, held, and disposal-verified data sets to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已知、未知、已分类、无责任人、超期保留、过早删除、未批准副本、被阻断流、保全及销毁已验证数据集 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-3.11-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "3.11",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original encryption pattern analysis",
          "basis_zh": "SOSEC 原创 encryption 模式分析",
          "en": "Use eligible, protected, weak/legacy, keyless, shared-key, decryptable-by-unintended-party, exception, and recovery-tested objects to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 适用、已保护、弱/旧算法、无密钥、共享密钥、非预期主体可解密、例外及恢复已测试对象 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "3.12",
      "control": 3,
      "title_en": "Segment Data Processing and Storage Based on Sensitivity",
      "title_zh": "按敏感度隔离处理与存储",
      "first_ig": 2,
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Data",
      "security_function": "Protect",
      "patterns": [
        "data_lifecycle",
        "enforcement",
        "governance"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "3.2",
          "12.4"
        ],
        "variables": [
          "GV4",
          "GV12",
          "GV18",
          "M1",
          "M2",
          "M3"
        ],
        "metric_branches": 1,
        "has_assumptions": true,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "The boundary follows data and workloads across network segments, cloud accounts/projects, clusters, databases, analytics and administration.",
          "build": "Place high-sensitivity workloads in dedicated trust zones with explicit identity, network, storage and management-plane policy; restrict ingress, egress, replication and operator paths.",
          "proof": "Attempt access from lower-trust workloads, identities, networks and management planes; verify denial and alerting while approved flows still work.",
          "boundary": "Shared control planes, CI/CD, backup systems, observability, jump hosts and keys can bridge otherwise separate networks."
        },
        "zh": {
          "scope": "边界随数据与工作负载跨网络区、云账号/项目、集群、数据库、分析和管理面移动。",
          "build": "把高敏工作负载置于专属信任区，在身份、网络、存储和管理面设显式策略，限制入口、出口、复制和运维路径。",
          "proof": "从低信任工作负载、身份、网络和管理面尝试访问，验证拒绝和告警，同时批准流仍正常。",
          "boundary": "共享控制面、CI/CD、备份、可观测、跳板和密钥会跨过看似分离的网络。"
        }
      },
      "category_counts": {
        "outcome": 8,
        "scope": 8,
        "ownership": 8,
        "data": 8,
        "integration": 8,
        "control": 8,
        "timing": 8,
        "exception": 8,
        "evidence": 8,
        "security": 8,
        "testing": 8,
        "operations": 8
      },
      "requirement_count": 96,
      "requirements": [
        {
          "code": "CIS-3.12-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "3.12",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Segment Data Processing and Storage Based on Sensitivity; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“按敏感度隔离处理与存储”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-3.12-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "3.12",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 3.12, official Asset Class Data, Security Function Protect, and IG2 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 3.12、官方资产类别“数据”、安全功能“保护”和首次出现的 IG2，并保存来源抓取日期。"
        },
        {
          "code": "CIS-3.12-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "3.12",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “The boundary follows data and workloads across network segments, cloud accounts/projects, clusters, databases, analytics and administration.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“边界随数据与工作负载跨网络区、云账号/项目、集群、数据库、分析和管理面移动。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-3.12-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "3.12",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-3.12-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "3.12",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Segment Data Processing and Storage Based on Sensitivity to its operating object—sensitive and business data, replicas, logs, backups, exports, derived data, AI corpora, keys, and data flows—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“按敏感度隔离处理与存储”连接到其运营对象——敏感与业务数据、副本、日志、备份、导出、派生数据、AI 语料、密钥和数据流——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-3.12-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "3.12",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "For Segment Data Processing and Storage Based on Sensitivity, express success as an observable decision over data identity, sensitivity, owner, purpose, location, flow, access, retention, copy, derivation, and disposal state; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“按敏感度隔离处理与存储”，以 数据身份、敏感度、责任人、目的、位置、流向、访问、保留、副本、派生与销毁状态 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-3.12-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "3.12",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "For Segment Data Processing and Storage Based on Sensitivity, express success as an observable decision over an enforceable allow, deny, contain, quarantine, require, remove, or transform decision at the closest reliable control point; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“按敏感度隔离处理与存储”，以 在最近可靠控制点执行允许、拒绝、遏制、隔离、强制、移除或转换决策 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-3.12-OUT-08",
          "local_code": "OUT-08",
          "display_code": "O08",
          "safeguard_id": "3.12",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "For Segment Data Processing and Storage Based on Sensitivity, express success as an observable decision over a documented decision system with policy, process, procedure, accountable owner, approval, and review; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“按敏感度隔离处理与存储”，以 包含策略、流程、程序、责任人、审批和复核的文档化决策系统 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-3.12-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "3.12",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-3.12-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "3.12",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-3.12-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "3.12",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-3.12-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "3.12",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-3.12-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "3.12",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across unknown classification, encrypted or tokenized copies, cross-region replicas, immutable backups, derived data, litigation holds, and provider deletion limits; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 未知分类、加密或令牌化副本、跨地域副本、不可变备份、派生数据、诉讼保全及提供商删除限制 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-3.12-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "3.12",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Include unstructured and derived data, logs, caches, backups, exports, client-side copies, cross-region processing, AI corpora, holds, and provider residues in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 非结构化与派生数据、日志、缓存、备份、导出、客户端副本、跨地域处理、AI 语料、保全和提供商残留 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-3.12-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "3.12",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Include audit-only mode, unsupported platforms, local overrides, race conditions, cached state, alternate paths, fail-open behavior, and emergency bypass in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 仅审计模式、不支持平台、本地覆盖、竞态、缓存状态、替代路径、故障开放和紧急绕过 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-3.12-SCP-08",
          "local_code": "SCP-08",
          "display_code": "P08",
          "safeguard_id": "3.12",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Include missing policy clauses, conflicting authorities, local deviations, obsolete documentation, and decisions made outside the governed workflow in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 策略条款缺失、权限冲突、本地偏离、文档过期及绕过治理流程的决策 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-3.12-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "3.12",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-3.12-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "3.12",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-3.12-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "3.12",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-3.12-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "3.12",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-3.12-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "3.12",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind data owners and custodians, product teams, privacy, legal, security, records management, and providers to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 数据责任人与托管方、产品团队、隐私、法务、安全、档案管理和服务提供商 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-3.12-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "3.12",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Name who may transition created/collected → classified → approved use and flow → retained/held → disposed with verification, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-3.12-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "3.12",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Name who may transition observe → evaluate → decide → enforce → verify outcome → rollback/close, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-3.12-OWN-08",
          "local_code": "OWN-08",
          "display_code": "W08",
          "safeguard_id": "3.12",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Name who may transition draft → reviewed → approved → effective → exception/withdrawn → superseded, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-3.12-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "3.12",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-3.12-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "3.12",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-3.12-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "3.12",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV4, GV12, GV18, M1, M2, M3) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV4, GV12, GV18, M1, M2, M3）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-3.12-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "3.12",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-3.12-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "3.12",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the data inventory, classification, ownership, and lifecycle authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把数据清单、分类、所有权与生命周期权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-3.12-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "3.12",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle created/collected → classified → approved use and flow → retained/held → disposed with verification.",
          "zh": "对生命周期“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-3.12-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "3.12",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle observe → evaluate → decide → enforce → verify outcome → rollback/close.",
          "zh": "对生命周期“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-3.12-DAT-08",
          "local_code": "DAT-08",
          "display_code": "D08",
          "safeguard_id": "3.12",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle draft → reviewed → approved → effective → exception/withdrawn → superseded.",
          "zh": "对生命周期“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-3.12-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "3.12",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 3.2, Safeguard 12.4; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 3.2、Safeguard 12.4 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-3.12-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "3.12",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-3.12-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "3.12",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-3.12-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "3.12",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-3.12-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "3.12",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile data catalogs, schemas, DLP discovery, cloud/SaaS APIs, owner attestations, flow records, backup catalogs, and legal/privacy schedules and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 数据目录、模式、DLP 发现、云/SaaS API、责任人确认、流向记录、备份目录及法律与隐私期限，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-3.12-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "3.12",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Require every connector carrying data identity, sensitivity, owner, purpose, location, flow, access, retention, copy, derivation, and disposal state to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 数据身份、敏感度、责任人、目的、位置、流向、访问、保留、副本、派生与销毁状态 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-3.12-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "3.12",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Require every connector carrying an enforceable allow, deny, contain, quarantine, require, remove, or transform decision at the closest reliable control point to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 在最近可靠控制点执行允许、拒绝、遏制、隔离、强制、移除或转换决策 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-3.12-INT-08",
          "local_code": "INT-08",
          "display_code": "I08",
          "safeguard_id": "3.12",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Require every connector carrying a documented decision system with policy, process, procedure, accountable owner, approval, and review to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 包含策略、流程、程序、责任人、审批和复核的文档化决策系统 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-3.12-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "3.12",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Place high-sensitivity workloads in dedicated trust zones with explicit identity, network, storage and management-plane policy; restrict ingress, egress, replication and operator paths.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“把高敏工作负载置于专属信任区，在身份、网络、存储和管理面设显式策略，限制入口、出口、复制和运维路径。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-3.12-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "3.12",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-3.12-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "3.12",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-3.12-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "3.12",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-3.12-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "3.12",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the data inventory, classification, ownership, and lifecycle authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在数据清单、分类、所有权与生命周期权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-3.12-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "3.12",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Implement the explicit state machine created/collected → classified → approved use and flow → retained/held → disposed with verification; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-3.12-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "3.12",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Implement the explicit state machine observe → evaluate → decide → enforce → verify outcome → rollback/close; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-3.12-CTL-08",
          "local_code": "CTL-08",
          "display_code": "C08",
          "safeguard_id": "3.12",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Implement the explicit state machine draft → reviewed → approved → effective → exception/withdrawn → superseded; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-3.12-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "3.12",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-3.12-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "3.12",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-3.12-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "3.12",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-3.12-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "3.12",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-3.12-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "3.12",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in sensitive and business data, replicas, logs, backups, exports, derived data, AI corpora, keys, and data flows; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 敏感与业务数据、副本、日志、备份、导出、派生数据、AI 语料、密钥和数据流 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-3.12-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "3.12",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for created/collected → classified → approved use and flow → retained/held → disposed with verification; alert before each deadline becomes overdue.",
          "zh": "为“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-3.12-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "3.12",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for observe → evaluate → decide → enforce → verify outcome → rollback/close; alert before each deadline becomes overdue.",
          "zh": "为“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-3.12-TIM-08",
          "local_code": "TIM-08",
          "display_code": "T08",
          "safeguard_id": "3.12",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for draft → reviewed → approved → effective → exception/withdrawn → superseded; alert before each deadline becomes overdue.",
          "zh": "为“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-3.12-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "3.12",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “Shared control planes, CI/CD, backup systems, observability, jump hosts and keys can bridge otherwise separate networks.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“共享控制面、CI/CD、备份、可观测、跳板和密钥会跨过看似分离的网络。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-3.12-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "3.12",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-3.12-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "3.12",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-3.12-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "3.12",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-3.12-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "3.12",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat unknown classification, encrypted or tokenized copies, cross-region replicas, immutable backups, derived data, litigation holds, and provider deletion limits as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 未知分类、加密或令牌化副本、跨地域副本、不可变备份、派生数据、诉讼保全及提供商删除限制 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-3.12-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "3.12",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Treat unstructured and derived data, logs, caches, backups, exports, client-side copies, cross-region processing, AI corpora, holds, and provider residues as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 非结构化与派生数据、日志、缓存、备份、导出、客户端副本、跨地域处理、AI 语料、保全和提供商残留 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-3.12-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "3.12",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Treat audit-only mode, unsupported platforms, local overrides, race conditions, cached state, alternate paths, fail-open behavior, and emergency bypass as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 仅审计模式、不支持平台、本地覆盖、竞态、缓存状态、替代路径、故障开放和紧急绕过 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-3.12-EXC-08",
          "local_code": "EXC-08",
          "display_code": "X08",
          "safeguard_id": "3.12",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Treat missing policy clauses, conflicting authorities, local deviations, obsolete documentation, and decisions made outside the governed workflow as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 策略条款缺失、权限冲突、本地偏离、文档过期及绕过治理流程的决策 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-3.12-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "3.12",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Attempt access from lower-trust workloads, identities, networks and management planes; verify denial and alerting while approved flows still work.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“从低信任工作负载、身份、网络和管理面尝试访问，验证拒绝和告警，同时批准流仍正常。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-3.12-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "3.12",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-3.12-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "3.12",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 6 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、6 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-3.12-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "3.12",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-3.12-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "3.12",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the data inventory, classification, ownership, and lifecycle authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以数据清单、分类、所有权与生命周期权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-3.12-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "3.12",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Publish known, unknown, classified, ownerless, over-retained, prematurely deleted, unapproved copy, blocked flow, held, and disposal-verified data sets with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已知、未知、已分类、无责任人、超期保留、过早删除、未批准副本、被阻断流、保全及销毁已验证数据集，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-3.12-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "3.12",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Publish eligible, enforcing, audit-only, failed, bypassed, excepted, rolled-back, and outcome-verified populations with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 适用、已执行、仅审计、失败、被绕过、例外、已回滚和结果已验证总体，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-3.12-EVD-08",
          "local_code": "EVD-08",
          "display_code": "E08",
          "safeguard_id": "3.12",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Publish clause coverage, owner and reviewer completeness, approval age, triggered reviews, deviations, overdue actions, and superseded versions still in use with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 条款覆盖、责任人与复核人完整性、批准年龄、触发式复核、偏离、逾期行动及仍在使用的旧版本，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-3.12-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "3.12",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-3.12-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "3.12",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-3.12-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "3.12",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-3.12-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "3.12",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-3.12-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "3.12",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the data inventory, classification, ownership, and lifecycle authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护数据清单、分类、所有权与生命周期权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-3.12-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "3.12",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Restrict authority to change created/collected → classified → approved use and flow → retained/held → disposed with verification; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-3.12-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "3.12",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Restrict authority to change observe → evaluate → decide → enforce → verify outcome → rollback/close; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-3.12-SEC-08",
          "local_code": "SEC-08",
          "display_code": "S08",
          "safeguard_id": "3.12",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Restrict authority to change draft → reviewed → approved → effective → exception/withdrawn → superseded; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-3.12-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "3.12",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-3.12-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "3.12",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-3.12-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "3.12",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-3.12-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "3.12",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-3.12-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "3.12",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise approved and unapproved copies, allowed and denied readers, retention boundaries, deletion verification, key loss, and cross-boundary transfers through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 获批与未批准副本、允许与拒绝读取、保留边界、删除验证、密钥丢失和跨边界传输，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-3.12-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "3.12",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Run the positive control an approved data set following its declared use, access, transfer, retention, and disposal path; exercise negative, stale, duplicate, bypass, and outage controls including an unknown or misclassified copy, forbidden reader or flow, early deletion, expired retention, failed disposal, and provider residue.",
          "zh": "运行正向控制“按声明用途、访问、传输、保留和销毁路径流转的获批数据集”，并执行包含“未知或误分类副本、禁止读取者或流向、过早删除、保留过期、销毁失败和提供商残留”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-3.12-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "3.12",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Run the positive control an approved business action that completes through the enforced path; exercise negative, stale, duplicate, bypass, and outage controls including a prohibited action, alternate path, local override, stale policy, control outage, emergency bypass, and rollback failure.",
          "zh": "运行正向控制“通过受控路径完成的一项获批业务动作”，并执行包含“禁止动作、替代路径、本地覆盖、陈旧策略、控制中断、紧急绕过和回滚失败”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-3.12-TST-08",
          "local_code": "TST-08",
          "display_code": "V08",
          "safeguard_id": "3.12",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Run the positive control an approved current process used for a representative decision; exercise negative, stale, duplicate, bypass, and outage controls including an obsolete version, missing approver, undocumented deviation, overdue review, and bypassed workflow.",
          "zh": "运行正向控制“使用当前获批流程完成一项代表性决策”，并执行包含“旧版本、审批人缺失、未记录偏离、逾期复核和绕过流程”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-3.12-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "3.12",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-3.12-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "3.12",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-3.12-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "3.12",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-3.12-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "3.12",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-3.12-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "3.12",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever data catalogs, schemas, DLP discovery, cloud/SaaS APIs, owner attestations, flow records, backup catalogs, and legal/privacy schedules change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 数据目录、模式、DLP 发现、云/SaaS API、责任人确认、流向记录、备份目录及法律与隐私期限 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-3.12-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "3.12",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Use known, unknown, classified, ownerless, over-retained, prematurely deleted, unapproved copy, blocked flow, held, and disposal-verified data sets to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已知、未知、已分类、无责任人、超期保留、过早删除、未批准副本、被阻断流、保全及销毁已验证数据集 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-3.12-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "3.12",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Use eligible, enforcing, audit-only, failed, bypassed, excepted, rolled-back, and outcome-verified populations to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 适用、已执行、仅审计、失败、被绕过、例外、已回滚和结果已验证总体 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-3.12-OPS-08",
          "local_code": "OPS-08",
          "display_code": "R08",
          "safeguard_id": "3.12",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Use clause coverage, owner and reviewer completeness, approval age, triggered reviews, deviations, overdue actions, and superseded versions still in use to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 条款覆盖、责任人与复核人完整性、批准年龄、触发式复核、偏离、逾期行动及仍在使用的旧版本 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "3.13",
      "control": 3,
      "title_en": "Deploy a Data Loss Prevention Solution",
      "title_zh": "数据防泄漏",
      "first_ig": 3,
      "implementation_groups": [
        3
      ],
      "asset_class": "Data",
      "security_function": "Protect",
      "patterns": [
        "data_lifecycle",
        "enforcement"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "2.1",
          "3.2"
        ],
        "variables": [
          "GV3",
          "GV5",
          "GV18",
          "M1",
          "M2",
          "M3",
          "M4",
          "M5"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "DLP scope spans endpoints, email, web, cloud storage, SaaS, collaboration, databases and sanctioned transfer paths where sensitive data can be identified or controlled.",
          "build": "Start from the data inventory and highest-consequence exfiltration paths, deploy classifiers and exact-data or fingerprint rules, route incidents to owners, tune with labelled samples and feed confirmed discoveries back to the inventory.",
          "proof": "Use true-positive, benign look-alike, obfuscated, compressed, encrypted and high-volume test data across each declared channel.",
          "boundary": "DLP cannot see end-to-end encrypted, unmanaged or unsupported paths and can harm privacy."
        },
        "zh": {
          "scope": "DLP 范围横跨终端、邮件、Web、云存储、SaaS、协作、数据库和所有能识别或控制敏感数据的批准传输路径。",
          "build": "从数据台账与后果最高的外泄路径开始，部署分类器、精确数据或指纹规则，告警路由给责任人，用有标签样本调优，并把确认发现回写台账；分开策略管理、例外批准和调查职责。",
          "proof": "在每条声明渠道发送真阳性、相似无害、混淆、压缩、加密和大批量测试数据。",
          "boundary": "DLP 看不到端到端加密、非受管或不支持路径，也可能侵害隐私。"
        }
      },
      "category_counts": {
        "outcome": 7,
        "scope": 7,
        "ownership": 7,
        "data": 7,
        "integration": 7,
        "control": 7,
        "timing": 7,
        "exception": 7,
        "evidence": 7,
        "security": 7,
        "testing": 7,
        "operations": 7
      },
      "requirement_count": 84,
      "requirements": [
        {
          "code": "CIS-3.13-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "3.13",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Deploy a Data Loss Prevention Solution; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“数据防泄漏”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-3.13-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "3.13",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 3.13, official Asset Class Data, Security Function Protect, and IG3 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 3.13、官方资产类别“数据”、安全功能“保护”和首次出现的 IG3，并保存来源抓取日期。"
        },
        {
          "code": "CIS-3.13-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "3.13",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “DLP scope spans endpoints, email, web, cloud storage, SaaS, collaboration, databases and sanctioned transfer paths where sensitive data can be identified or controlled.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“DLP 范围横跨终端、邮件、Web、云存储、SaaS、协作、数据库和所有能识别或控制敏感数据的批准传输路径。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-3.13-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "3.13",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-3.13-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "3.13",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Deploy a Data Loss Prevention Solution to its operating object—sensitive and business data, replicas, logs, backups, exports, derived data, AI corpora, keys, and data flows—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“数据防泄漏”连接到其运营对象——敏感与业务数据、副本、日志、备份、导出、派生数据、AI 语料、密钥和数据流——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-3.13-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "3.13",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "For Deploy a Data Loss Prevention Solution, express success as an observable decision over data identity, sensitivity, owner, purpose, location, flow, access, retention, copy, derivation, and disposal state; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“数据防泄漏”，以 数据身份、敏感度、责任人、目的、位置、流向、访问、保留、副本、派生与销毁状态 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-3.13-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "3.13",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "For Deploy a Data Loss Prevention Solution, express success as an observable decision over an enforceable allow, deny, contain, quarantine, require, remove, or transform decision at the closest reliable control point; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“数据防泄漏”，以 在最近可靠控制点执行允许、拒绝、遏制、隔离、强制、移除或转换决策 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-3.13-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "3.13",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-3.13-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "3.13",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-3.13-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "3.13",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-3.13-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "3.13",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-3.13-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "3.13",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across unknown classification, encrypted or tokenized copies, cross-region replicas, immutable backups, derived data, litigation holds, and provider deletion limits; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 未知分类、加密或令牌化副本、跨地域副本、不可变备份、派生数据、诉讼保全及提供商删除限制 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-3.13-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "3.13",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Include unstructured and derived data, logs, caches, backups, exports, client-side copies, cross-region processing, AI corpora, holds, and provider residues in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 非结构化与派生数据、日志、缓存、备份、导出、客户端副本、跨地域处理、AI 语料、保全和提供商残留 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-3.13-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "3.13",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Include audit-only mode, unsupported platforms, local overrides, race conditions, cached state, alternate paths, fail-open behavior, and emergency bypass in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 仅审计模式、不支持平台、本地覆盖、竞态、缓存状态、替代路径、故障开放和紧急绕过 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-3.13-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "3.13",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-3.13-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "3.13",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-3.13-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "3.13",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-3.13-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "3.13",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-3.13-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "3.13",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind data owners and custodians, product teams, privacy, legal, security, records management, and providers to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 数据责任人与托管方、产品团队、隐私、法务、安全、档案管理和服务提供商 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-3.13-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "3.13",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Name who may transition created/collected → classified → approved use and flow → retained/held → disposed with verification, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-3.13-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "3.13",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Name who may transition observe → evaluate → decide → enforce → verify outcome → rollback/close, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-3.13-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "3.13",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-3.13-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "3.13",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-3.13-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "3.13",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV3, GV5, GV18, M1, M2, M3, M4, M5) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV3, GV5, GV18, M1, M2, M3, M4, M5）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-3.13-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "3.13",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-3.13-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "3.13",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the data inventory, classification, ownership, and lifecycle authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把数据清单、分类、所有权与生命周期权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-3.13-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "3.13",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle created/collected → classified → approved use and flow → retained/held → disposed with verification.",
          "zh": "对生命周期“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-3.13-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "3.13",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle observe → evaluate → decide → enforce → verify outcome → rollback/close.",
          "zh": "对生命周期“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-3.13-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "3.13",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 2.1, Safeguard 3.2; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 2.1、Safeguard 3.2 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-3.13-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "3.13",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-3.13-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "3.13",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-3.13-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "3.13",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-3.13-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "3.13",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile data catalogs, schemas, DLP discovery, cloud/SaaS APIs, owner attestations, flow records, backup catalogs, and legal/privacy schedules and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 数据目录、模式、DLP 发现、云/SaaS API、责任人确认、流向记录、备份目录及法律与隐私期限，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-3.13-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "3.13",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Require every connector carrying data identity, sensitivity, owner, purpose, location, flow, access, retention, copy, derivation, and disposal state to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 数据身份、敏感度、责任人、目的、位置、流向、访问、保留、副本、派生与销毁状态 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-3.13-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "3.13",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Require every connector carrying an enforceable allow, deny, contain, quarantine, require, remove, or transform decision at the closest reliable control point to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 在最近可靠控制点执行允许、拒绝、遏制、隔离、强制、移除或转换决策 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-3.13-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "3.13",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Start from the data inventory and highest-consequence exfiltration paths, deploy classifiers and exact-data or fingerprint rules, route incidents to owners, tune with labelled samples and feed confirmed discoveries back to the inventory.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“从数据台账与后果最高的外泄路径开始，部署分类器、精确数据或指纹规则，告警路由给责任人，用有标签样本调优，并把确认发现回写台账；分开策略管理、例外批准和调查职责。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-3.13-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "3.13",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-3.13-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "3.13",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-3.13-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "3.13",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-3.13-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "3.13",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the data inventory, classification, ownership, and lifecycle authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在数据清单、分类、所有权与生命周期权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-3.13-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "3.13",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Implement the explicit state machine created/collected → classified → approved use and flow → retained/held → disposed with verification; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-3.13-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "3.13",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Implement the explicit state machine observe → evaluate → decide → enforce → verify outcome → rollback/close; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-3.13-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "3.13",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-3.13-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "3.13",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-3.13-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "3.13",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-3.13-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "3.13",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-3.13-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "3.13",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in sensitive and business data, replicas, logs, backups, exports, derived data, AI corpora, keys, and data flows; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 敏感与业务数据、副本、日志、备份、导出、派生数据、AI 语料、密钥和数据流 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-3.13-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "3.13",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for created/collected → classified → approved use and flow → retained/held → disposed with verification; alert before each deadline becomes overdue.",
          "zh": "为“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-3.13-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "3.13",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for observe → evaluate → decide → enforce → verify outcome → rollback/close; alert before each deadline becomes overdue.",
          "zh": "为“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-3.13-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "3.13",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “DLP cannot see end-to-end encrypted, unmanaged or unsupported paths and can harm privacy.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“DLP 看不到端到端加密、非受管或不支持路径，也可能侵害隐私。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-3.13-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "3.13",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-3.13-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "3.13",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-3.13-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "3.13",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-3.13-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "3.13",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat unknown classification, encrypted or tokenized copies, cross-region replicas, immutable backups, derived data, litigation holds, and provider deletion limits as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 未知分类、加密或令牌化副本、跨地域副本、不可变备份、派生数据、诉讼保全及提供商删除限制 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-3.13-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "3.13",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Treat unstructured and derived data, logs, caches, backups, exports, client-side copies, cross-region processing, AI corpora, holds, and provider residues as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 非结构化与派生数据、日志、缓存、备份、导出、客户端副本、跨地域处理、AI 语料、保全和提供商残留 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-3.13-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "3.13",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Treat audit-only mode, unsupported platforms, local overrides, race conditions, cached state, alternate paths, fail-open behavior, and emergency bypass as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 仅审计模式、不支持平台、本地覆盖、竞态、缓存状态、替代路径、故障开放和紧急绕过 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-3.13-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "3.13",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Use true-positive, benign look-alike, obfuscated, compressed, encrypted and high-volume test data across each declared channel.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“在每条声明渠道发送真阳性、相似无害、混淆、压缩、加密和大批量测试数据。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-3.13-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "3.13",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-3.13-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "3.13",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 8 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、8 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-3.13-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "3.13",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-3.13-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "3.13",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the data inventory, classification, ownership, and lifecycle authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以数据清单、分类、所有权与生命周期权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-3.13-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "3.13",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Publish known, unknown, classified, ownerless, over-retained, prematurely deleted, unapproved copy, blocked flow, held, and disposal-verified data sets with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已知、未知、已分类、无责任人、超期保留、过早删除、未批准副本、被阻断流、保全及销毁已验证数据集，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-3.13-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "3.13",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Publish eligible, enforcing, audit-only, failed, bypassed, excepted, rolled-back, and outcome-verified populations with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 适用、已执行、仅审计、失败、被绕过、例外、已回滚和结果已验证总体，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-3.13-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "3.13",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-3.13-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "3.13",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-3.13-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "3.13",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-3.13-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "3.13",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-3.13-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "3.13",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the data inventory, classification, ownership, and lifecycle authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护数据清单、分类、所有权与生命周期权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-3.13-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "3.13",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Restrict authority to change created/collected → classified → approved use and flow → retained/held → disposed with verification; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-3.13-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "3.13",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Restrict authority to change observe → evaluate → decide → enforce → verify outcome → rollback/close; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-3.13-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "3.13",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-3.13-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "3.13",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-3.13-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "3.13",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-3.13-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "3.13",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-3.13-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "3.13",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise approved and unapproved copies, allowed and denied readers, retention boundaries, deletion verification, key loss, and cross-boundary transfers through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 获批与未批准副本、允许与拒绝读取、保留边界、删除验证、密钥丢失和跨边界传输，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-3.13-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "3.13",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Run the positive control an approved data set following its declared use, access, transfer, retention, and disposal path; exercise negative, stale, duplicate, bypass, and outage controls including an unknown or misclassified copy, forbidden reader or flow, early deletion, expired retention, failed disposal, and provider residue.",
          "zh": "运行正向控制“按声明用途、访问、传输、保留和销毁路径流转的获批数据集”，并执行包含“未知或误分类副本、禁止读取者或流向、过早删除、保留过期、销毁失败和提供商残留”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-3.13-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "3.13",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Run the positive control an approved business action that completes through the enforced path; exercise negative, stale, duplicate, bypass, and outage controls including a prohibited action, alternate path, local override, stale policy, control outage, emergency bypass, and rollback failure.",
          "zh": "运行正向控制“通过受控路径完成的一项获批业务动作”，并执行包含“禁止动作、替代路径、本地覆盖、陈旧策略、控制中断、紧急绕过和回滚失败”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-3.13-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "3.13",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-3.13-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "3.13",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-3.13-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "3.13",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-3.13-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "3.13",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-3.13-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "3.13",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever data catalogs, schemas, DLP discovery, cloud/SaaS APIs, owner attestations, flow records, backup catalogs, and legal/privacy schedules change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 数据目录、模式、DLP 发现、云/SaaS API、责任人确认、流向记录、备份目录及法律与隐私期限 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-3.13-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "3.13",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Use known, unknown, classified, ownerless, over-retained, prematurely deleted, unapproved copy, blocked flow, held, and disposal-verified data sets to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已知、未知、已分类、无责任人、超期保留、过早删除、未批准副本、被阻断流、保全及销毁已验证数据集 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-3.13-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "3.13",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Use eligible, enforcing, audit-only, failed, bypassed, excepted, rolled-back, and outcome-verified populations to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 适用、已执行、仅审计、失败、被绕过、例外、已回滚和结果已验证总体 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "3.14",
      "control": 3,
      "title_en": "Log Sensitive Data Access",
      "title_zh": "敏感数据访问日志",
      "first_ig": 3,
      "implementation_groups": [
        3
      ],
      "asset_class": "Data",
      "security_function": "Detect",
      "patterns": [
        "data_lifecycle",
        "identity",
        "telemetry"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "1.1",
          "2.1",
          "4.1"
        ],
        "variables": [
          "GV3",
          "GV5",
          "GV18",
          "M1",
          "M2",
          "M3",
          "M4",
          "M5"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "Log reads, queries, exports, modification, deletion and permission/key changes for sensitive data, including human, service, provider-support and administrative paths.",
          "build": "Enable native database, storage, application and key audit events; preserve actor, effective identity, action, object/data set, result, time, source, volume and correlation context.",
          "proof": "Perform allowed read/update/delete/export and denied attempts with human and service identities, then trace complete events through collection, parsing, retention and review.",
          "boundary": "Bulk analytics, break-glass, support access, backups and application connection pools can obscure the real actor."
        },
        "zh": {
          "scope": "记录敏感数据的读取、查询、导出、修改、删除以及权限/密钥变化，覆盖人、服务、服务商支持和管理员路径。",
          "build": "启用数据库、存储、应用和密钥原生日志，保留行为人、有效身份、动作、对象/数据集、结果、时间、来源、数量与关联上下文；集中到受保护存储，少记不必要的敏感载荷，并把检测关联责任人。",
          "proof": "用人和服务身份执行允许的读改删导出以及拒绝尝试，沿采集、解析、保留、复核全链路核验事件。",
          "boundary": "批量分析、破窗、支持访问、备份和连接池会遮蔽真实行为人。"
        }
      },
      "category_counts": {
        "outcome": 8,
        "scope": 8,
        "ownership": 8,
        "data": 8,
        "integration": 8,
        "control": 8,
        "timing": 8,
        "exception": 8,
        "evidence": 8,
        "security": 8,
        "testing": 8,
        "operations": 8
      },
      "requirement_count": 96,
      "requirements": [
        {
          "code": "CIS-3.14-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "3.14",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Log Sensitive Data Access; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“敏感数据访问日志”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-3.14-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "3.14",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 3.14, official Asset Class Data, Security Function Detect, and IG3 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 3.14、官方资产类别“数据”、安全功能“检测”和首次出现的 IG3，并保存来源抓取日期。"
        },
        {
          "code": "CIS-3.14-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "3.14",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Log reads, queries, exports, modification, deletion and permission/key changes for sensitive data, including human, service, provider-support and administrative paths.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“记录敏感数据的读取、查询、导出、修改、删除以及权限/密钥变化，覆盖人、服务、服务商支持和管理员路径。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-3.14-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "3.14",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-3.14-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "3.14",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Log Sensitive Data Access to its operating object—sensitive and business data, replicas, logs, backups, exports, derived data, AI corpora, keys, and data flows—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“敏感数据访问日志”连接到其运营对象——敏感与业务数据、副本、日志、备份、导出、派生数据、AI 语料、密钥和数据流——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-3.14-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "3.14",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "For Log Sensitive Data Access, express success as an observable decision over data identity, sensitivity, owner, purpose, location, flow, access, retention, copy, derivation, and disposal state; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“敏感数据访问日志”，以 数据身份、敏感度、责任人、目的、位置、流向、访问、保留、副本、派生与销毁状态 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-3.14-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "3.14",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "For Log Sensitive Data Access, express success as an observable decision over effective identity, authentication, authorization, privilege, session, and revocation state across every access path; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“敏感数据访问日志”，以 所有访问路径上的实际身份、认证、授权、权限、会话和撤销状态 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-3.14-OUT-08",
          "local_code": "OUT-08",
          "display_code": "O08",
          "safeguard_id": "3.14",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "For Log Sensitive Data Access, express success as an observable decision over complete, attributable, timely, protected, searchable, and actionable security telemetry plus source health; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“敏感数据访问日志”，以 完整、可归因、及时、受保护、可检索、可行动的安全遥测及来源健康 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-3.14-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "3.14",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-3.14-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "3.14",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-3.14-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "3.14",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-3.14-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "3.14",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-3.14-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "3.14",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across unknown classification, encrypted or tokenized copies, cross-region replicas, immutable backups, derived data, litigation holds, and provider deletion limits; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 未知分类、加密或令牌化副本、跨地域副本、不可变备份、派生数据、诉讼保全及提供商删除限制 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-3.14-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "3.14",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Include unstructured and derived data, logs, caches, backups, exports, client-side copies, cross-region processing, AI corpora, holds, and provider residues in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 非结构化与派生数据、日志、缓存、备份、导出、客户端副本、跨地域处理、AI 语料、保全和提供商残留 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-3.14-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "3.14",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Include shared and service identities, nested groups, direct grants, cached sessions, federation gaps, recovery channels, API keys, emergency access, and provider support in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 共享与服务身份、嵌套组、直接授权、缓存会话、联邦缺口、恢复通道、API 密钥、紧急访问和提供商支持 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-3.14-SCP-08",
          "local_code": "SCP-08",
          "display_code": "P08",
          "safeguard_id": "3.14",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Include clock skew, actor loss, field truncation, parser drift, dropped or duplicate events, privacy redaction, provider gaps, encrypted paths, quota, and archive failure in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 时钟偏移、行为者丢失、字段截断、解析漂移、事件丢失或重复、隐私脱敏、提供商缺口、加密路径、配额和归档故障 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-3.14-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "3.14",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-3.14-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "3.14",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-3.14-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "3.14",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-3.14-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "3.14",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-3.14-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "3.14",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind data owners and custodians, product teams, privacy, legal, security, records management, and providers to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 数据责任人与托管方、产品团队、隐私、法务、安全、档案管理和服务提供商 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-3.14-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "3.14",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Name who may transition created/collected → classified → approved use and flow → retained/held → disposed with verification, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-3.14-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "3.14",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Name who may transition requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-3.14-OWN-08",
          "local_code": "OWN-08",
          "display_code": "W08",
          "safeguard_id": "3.14",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Name who may transition event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-3.14-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "3.14",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-3.14-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "3.14",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-3.14-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "3.14",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV3, GV5, GV18, M1, M2, M3, M4, M5) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV3, GV5, GV18, M1, M2, M3, M4, M5）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-3.14-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "3.14",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-3.14-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "3.14",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the data inventory, classification, ownership, and lifecycle authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把数据清单、分类、所有权与生命周期权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-3.14-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "3.14",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle created/collected → classified → approved use and flow → retained/held → disposed with verification.",
          "zh": "对生命周期“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-3.14-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "3.14",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated.",
          "zh": "对生命周期“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-3.14-DAT-08",
          "local_code": "DAT-08",
          "display_code": "D08",
          "safeguard_id": "3.14",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired.",
          "zh": "对生命周期“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-3.14-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "3.14",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 1.1, Safeguard 2.1, Safeguard 4.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 1.1、Safeguard 2.1、Safeguard 4.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-3.14-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "3.14",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-3.14-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "3.14",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-3.14-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "3.14",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-3.14-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "3.14",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile data catalogs, schemas, DLP discovery, cloud/SaaS APIs, owner attestations, flow records, backup catalogs, and legal/privacy schedules and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 数据目录、模式、DLP 发现、云/SaaS API、责任人确认、流向记录、备份目录及法律与隐私期限，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-3.14-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "3.14",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Require every connector carrying data identity, sensitivity, owner, purpose, location, flow, access, retention, copy, derivation, and disposal state to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 数据身份、敏感度、责任人、目的、位置、流向、访问、保留、副本、派生与销毁状态 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-3.14-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "3.14",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Require every connector carrying effective identity, authentication, authorization, privilege, session, and revocation state across every access path to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 所有访问路径上的实际身份、认证、授权、权限、会话和撤销状态 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-3.14-INT-08",
          "local_code": "INT-08",
          "display_code": "I08",
          "safeguard_id": "3.14",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Require every connector carrying complete, attributable, timely, protected, searchable, and actionable security telemetry plus source health to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 完整、可归因、及时、受保护、可检索、可行动的安全遥测及来源健康 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-3.14-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "3.14",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Enable native database, storage, application and key audit events; preserve actor, effective identity, action, object/data set, result, time, source, volume and correlation context.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“启用数据库、存储、应用和密钥原生日志，保留行为人、有效身份、动作、对象/数据集、结果、时间、来源、数量与关联上下文；集中到受保护存储，少记不必要的敏感载荷，并把检测关联责任人。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-3.14-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "3.14",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-3.14-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "3.14",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-3.14-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "3.14",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-3.14-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "3.14",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the data inventory, classification, ownership, and lifecycle authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在数据清单、分类、所有权与生命周期权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-3.14-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "3.14",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Implement the explicit state machine created/collected → classified → approved use and flow → retained/held → disposed with verification; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-3.14-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "3.14",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Implement the explicit state machine requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-3.14-CTL-08",
          "local_code": "CTL-08",
          "display_code": "C08",
          "safeguard_id": "3.14",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Implement the explicit state machine event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-3.14-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "3.14",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-3.14-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "3.14",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-3.14-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "3.14",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-3.14-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "3.14",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-3.14-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "3.14",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in sensitive and business data, replicas, logs, backups, exports, derived data, AI corpora, keys, and data flows; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 敏感与业务数据、副本、日志、备份、导出、派生数据、AI 语料、密钥和数据流 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-3.14-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "3.14",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for created/collected → classified → approved use and flow → retained/held → disposed with verification; alert before each deadline becomes overdue.",
          "zh": "为“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-3.14-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "3.14",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated; alert before each deadline becomes overdue.",
          "zh": "为“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-3.14-TIM-08",
          "local_code": "TIM-08",
          "display_code": "T08",
          "safeguard_id": "3.14",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired; alert before each deadline becomes overdue.",
          "zh": "为“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-3.14-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "3.14",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “Bulk analytics, break-glass, support access, backups and application connection pools can obscure the real actor.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“批量分析、破窗、支持访问、备份和连接池会遮蔽真实行为人。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-3.14-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "3.14",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-3.14-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "3.14",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-3.14-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "3.14",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-3.14-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "3.14",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat unknown classification, encrypted or tokenized copies, cross-region replicas, immutable backups, derived data, litigation holds, and provider deletion limits as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 未知分类、加密或令牌化副本、跨地域副本、不可变备份、派生数据、诉讼保全及提供商删除限制 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-3.14-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "3.14",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Treat unstructured and derived data, logs, caches, backups, exports, client-side copies, cross-region processing, AI corpora, holds, and provider residues as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 非结构化与派生数据、日志、缓存、备份、导出、客户端副本、跨地域处理、AI 语料、保全和提供商残留 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-3.14-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "3.14",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Treat shared and service identities, nested groups, direct grants, cached sessions, federation gaps, recovery channels, API keys, emergency access, and provider support as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 共享与服务身份、嵌套组、直接授权、缓存会话、联邦缺口、恢复通道、API 密钥、紧急访问和提供商支持 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-3.14-EXC-08",
          "local_code": "EXC-08",
          "display_code": "X08",
          "safeguard_id": "3.14",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Treat clock skew, actor loss, field truncation, parser drift, dropped or duplicate events, privacy redaction, provider gaps, encrypted paths, quota, and archive failure as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 时钟偏移、行为者丢失、字段截断、解析漂移、事件丢失或重复、隐私脱敏、提供商缺口、加密路径、配额和归档故障 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-3.14-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "3.14",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Perform allowed read/update/delete/export and denied attempts with human and service identities, then trace complete events through collection, parsing, retention and review.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“用人和服务身份执行允许的读改删导出以及拒绝尝试，沿采集、解析、保留、复核全链路核验事件。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-3.14-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "3.14",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-3.14-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "3.14",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 8 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、8 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-3.14-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "3.14",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-3.14-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "3.14",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the data inventory, classification, ownership, and lifecycle authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以数据清单、分类、所有权与生命周期权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-3.14-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "3.14",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Publish known, unknown, classified, ownerless, over-retained, prematurely deleted, unapproved copy, blocked flow, held, and disposal-verified data sets with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已知、未知、已分类、无责任人、超期保留、过早删除、未批准副本、被阻断流、保全及销毁已验证数据集，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-3.14-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "3.14",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Publish requested, approved, effective, excessive, orphaned, stale, emergency, revoked-but-active, and independently reviewed rights with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 申请、批准、实际、过度、孤儿、陈旧、紧急、已撤销仍活跃及独立复核权限，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-3.14-EVD-08",
          "local_code": "EVD-08",
          "display_code": "E08",
          "safeguard_id": "3.14",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Publish healthy, silent, partial, late, malformed, duplicate, unowned, unreviewed, alerted, investigated, and archived sources or events with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 健康、静默、部分、迟到、畸形、重复、无责任人、未审阅、已告警、已调查和已归档来源或事件，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-3.14-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "3.14",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-3.14-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "3.14",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-3.14-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "3.14",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-3.14-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "3.14",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-3.14-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "3.14",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the data inventory, classification, ownership, and lifecycle authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护数据清单、分类、所有权与生命周期权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-3.14-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "3.14",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Restrict authority to change created/collected → classified → approved use and flow → retained/held → disposed with verification; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-3.14-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "3.14",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Restrict authority to change requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-3.14-SEC-08",
          "local_code": "SEC-08",
          "display_code": "S08",
          "safeguard_id": "3.14",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Restrict authority to change event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-3.14-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "3.14",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-3.14-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "3.14",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-3.14-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "3.14",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-3.14-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "3.14",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-3.14-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "3.14",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise approved and unapproved copies, allowed and denied readers, retention boundaries, deletion verification, key loss, and cross-boundary transfers through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 获批与未批准副本、允许与拒绝读取、保留边界、删除验证、密钥丢失和跨边界传输，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-3.14-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "3.14",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Run the positive control an approved data set following its declared use, access, transfer, retention, and disposal path; exercise negative, stale, duplicate, bypass, and outage controls including an unknown or misclassified copy, forbidden reader or flow, early deletion, expired retention, failed disposal, and provider residue.",
          "zh": "运行正向控制“按声明用途、访问、传输、保留和销毁路径流转的获批数据集”，并执行包含“未知或误分类副本、禁止读取者或流向、过早删除、保留过期、销毁失败和提供商残留”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-3.14-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "3.14",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Run the positive control an authorized identity using the required assurance and least privilege; exercise negative, stale, duplicate, bypass, and outage controls including an unauthorized identity, missing factor, stale session, direct grant, inherited excess, revoked token, and recovery bypass.",
          "zh": "运行正向控制“使用所需保证级别和最小权限的授权身份”，并执行包含“未授权身份、缺失认证因子、陈旧会话、直接授权、继承过权、已撤销令牌和恢复绕过”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-3.14-TST-08",
          "local_code": "TST-08",
          "display_code": "V08",
          "safeguard_id": "3.14",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Run the positive control an allowed and denied canary event traced from source through review; exercise negative, stale, duplicate, bypass, and outage controls including source loss, parser/schema change, time skew, queue overflow, duplicate delivery, provider export outage, missed alert, and unreadable archive.",
          "zh": "运行正向控制“一项允许与拒绝金丝雀事件从来源贯穿到审阅”，并执行包含“来源丢失、解析器/模式变化、时钟偏移、队列溢出、重复投递、提供商导出中断、漏报和归档不可读”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-3.14-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "3.14",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-3.14-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "3.14",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-3.14-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "3.14",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-3.14-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "3.14",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-3.14-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "3.14",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever data catalogs, schemas, DLP discovery, cloud/SaaS APIs, owner attestations, flow records, backup catalogs, and legal/privacy schedules change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 数据目录、模式、DLP 发现、云/SaaS API、责任人确认、流向记录、备份目录及法律与隐私期限 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-3.14-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "3.14",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Use known, unknown, classified, ownerless, over-retained, prematurely deleted, unapproved copy, blocked flow, held, and disposal-verified data sets to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已知、未知、已分类、无责任人、超期保留、过早删除、未批准副本、被阻断流、保全及销毁已验证数据集 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-3.14-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "3.14",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Use requested, approved, effective, excessive, orphaned, stale, emergency, revoked-but-active, and independently reviewed rights to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 申请、批准、实际、过度、孤儿、陈旧、紧急、已撤销仍活跃及独立复核权限 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-3.14-OPS-08",
          "local_code": "OPS-08",
          "display_code": "R08",
          "safeguard_id": "3.14",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Use healthy, silent, partial, late, malformed, duplicate, unowned, unreviewed, alerted, investigated, and archived sources or events to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 健康、静默、部分、迟到、畸形、重复、无责任人、未审阅、已告警、已调查和已归档来源或事件 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "4.1",
      "control": 4,
      "title_en": "Establish and Maintain a Secure Configuration Process",
      "title_zh": "资产与软件安全配置流程",
      "first_ig": 1,
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Documentation",
      "security_function": "Govern",
      "patterns": [
        "enforcement",
        "governance"
      ],
      "expanded_complexity": true,
      "cas_context": {
        "dependencies": [
          "2.1"
        ],
        "variables": [
          "GV1",
          "GV3",
          "GV5",
          "M1",
          "M2",
          "M3",
          "M4",
          "M5",
          "M6"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [
        "annually"
      ],
      "implementation_contract": {
        "en": {
          "scope": "The process covers each supported asset and software family, version, role and environment, including endpoints, servers, mobile, IoT, operating systems, applications, databases, containers, cloud resources and provider-managed tenant settings.",
          "build": "Create risk-based, version-controlled baselines from authoritative hardening guidance; document values, rationale, allowed deviations, deployment method, validation and rollback.",
          "proof": "Build a clean instance from the baseline and test required business paths, then introduce a prohibited setting and verify drift detection and repair.",
          "boundary": "A secure setting can break safety, availability or vendor support, so deviations are exact, owned, compensated, expiring and retested."
        },
        "zh": {
          "scope": "覆盖每一种受支持的资产/软件族、版本、角色和环境：终端、服务器、移动、IoT、OS、应用、数据库、容器、云资源以及服务商管理但租户可配的设置。",
          "build": "从权威加固指南生成风险化、版本化基线，写明取值、理由、允许偏差、部署、验证与回滚。",
          "proof": "用基线构建干净实例并跑通业务，再引入一个禁止设置，验证漂移发现与修复。",
          "boundary": "安全设置可能影响安全性、可用性或厂商支持，偏差因此必须精确、具名、有补偿、会到期并复测。"
        }
      },
      "category_counts": {
        "outcome": 8,
        "scope": 8,
        "ownership": 8,
        "data": 8,
        "integration": 8,
        "control": 8,
        "timing": 8,
        "exception": 8,
        "evidence": 8,
        "security": 8,
        "testing": 8,
        "operations": 8
      },
      "requirement_count": 96,
      "requirements": [
        {
          "code": "CIS-4.1-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "4.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Establish and Maintain a Secure Configuration Process; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“资产与软件安全配置流程”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-4.1-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "4.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 4.1, official Asset Class Documentation, Security Function Govern, and IG1 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 4.1、官方资产类别“文档与治理”、安全功能“治理”和首次出现的 IG1，并保存来源抓取日期。"
        },
        {
          "code": "CIS-4.1-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "4.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “The process covers each supported asset and software family, version, role and environment, including endpoints, servers, mobile, IoT, operating systems, applications, databases, containers, cloud resources and provider-managed tenant settings.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“覆盖每一种受支持的资产/软件族、版本、角色和环境：终端、服务器、移动、IoT、OS、应用、数据库、容器、云资源以及服务商管理但租户可配的设置。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-4.1-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "4.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-4.1-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "4.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Establish and Maintain a Secure Configuration Process to its operating object—role-specific secure baselines and effective configurations for endpoints, servers, mobile, cloud, network, software, and administrative paths—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“资产与软件安全配置流程”连接到其运营对象——终端、服务器、移动、云、网络、软件和管理路径的角色化安全基线与实际配置——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-4.1-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "4.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "For Establish and Maintain a Secure Configuration Process, express success as an observable decision over an enforceable allow, deny, contain, quarantine, require, remove, or transform decision at the closest reliable control point; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“资产与软件安全配置流程”，以 在最近可靠控制点执行允许、拒绝、遏制、隔离、强制、移除或转换决策 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-4.1-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "4.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "For Establish and Maintain a Secure Configuration Process, express success as an observable decision over a documented decision system with policy, process, procedure, accountable owner, approval, and review; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“资产与软件安全配置流程”，以 包含策略、流程、程序、责任人、审批和复核的文档化决策系统 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-4.1-OUT-08",
          "local_code": "OUT-08",
          "display_code": "O08",
          "safeguard_id": "4.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "For the expanded Establish and Maintain a Secure Configuration Process scope, resolve conflicts among security, safety, privacy, legal, availability, customer, and operational objectives through an explicit risk decision.",
          "zh": "对“资产与软件安全配置流程”的扩展范围，通过显式风险决策解决安全、安全生产、隐私、法律、可用性、客户和运营目标冲突。"
        },
        {
          "code": "CIS-4.1-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "4.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-4.1-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "4.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-4.1-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "4.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-4.1-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "4.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-4.1-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "4.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across unsupported settings, local overrides, inherited cloud policy, vendor defaults, emergency access, safety constraints, drift, and rollback; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 不支持的设置、本地覆盖、继承云策略、厂商默认值、紧急访问、安全约束、漂移和回滚 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-4.1-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "4.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Include audit-only mode, unsupported platforms, local overrides, race conditions, cached state, alternate paths, fail-open behavior, and emergency bypass in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 仅审计模式、不支持平台、本地覆盖、竞态、缓存状态、替代路径、故障开放和紧急绕过 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-4.1-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "4.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Include missing policy clauses, conflicting authorities, local deviations, obsolete documentation, and decisions made outside the governed workflow in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 策略条款缺失、权限冲突、本地偏离、文档过期及绕过治理流程的决策 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-4.1-SCP-08",
          "local_code": "SCP-08",
          "display_code": "P08",
          "safeguard_id": "4.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Define nested scope at enterprise, business service, tenant, environment, platform, object, identity, data set, and transaction levels; prohibit a parent result from hiding a failing child.",
          "zh": "按企业、业务服务、租户、环境、平台、对象、身份、数据集和交易定义嵌套范围，禁止父级结果遮蔽失败子级。"
        },
        {
          "code": "CIS-4.1-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "4.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-4.1-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "4.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-4.1-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "4.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-4.1-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "4.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-4.1-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "4.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind platform and application owners, network engineering, security architecture, change management, and service owners to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 平台与应用责任人、网络工程、安全架构、变更管理和服务责任人 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-4.1-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "4.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Name who may transition observe → evaluate → decide → enforce → verify outcome → rollback/close, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-4.1-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "4.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Name who may transition draft → reviewed → approved → effective → exception/withdrawn → superseded, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-4.1-OWN-08",
          "local_code": "OWN-08",
          "display_code": "W08",
          "safeguard_id": "4.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Model delegated authority, quorum or dual approval where warranted, escalation deadlines, provider handoffs, conflict resolution, and executive risk acceptance.",
          "zh": "建模委派权限、必要时的双人或法定人数审批、升级期限、提供商交接、冲突解决和管理层风险接受。"
        },
        {
          "code": "CIS-4.1-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "4.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-4.1-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "4.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-4.1-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "4.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV1, GV3, GV5, M1, M2, M3, M4, M5, M6) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV1, GV3, GV5, M1, M2, M3, M4, M5, M6）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-4.1-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "4.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-4.1-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "4.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the versioned secure-configuration authority and exception register as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把版本化安全配置权威库与例外台账作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-4.1-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "4.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle observe → evaluate → decide → enforce → verify outcome → rollback/close.",
          "zh": "对生命周期“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-4.1-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "4.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle draft → reviewed → approved → effective → exception/withdrawn → superseded.",
          "zh": "对生命周期“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-4.1-DAT-08",
          "local_code": "DAT-08",
          "display_code": "D08",
          "safeguard_id": "4.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Version schemas and state transitions with migration, backfill, deduplication, lineage, historical denominator, deletion, and rollback semantics.",
          "zh": "对模式和状态转换做版本管理，定义迁移、回填、去重、血缘、历史分母、删除和回滚语义。"
        },
        {
          "code": "CIS-4.1-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "4.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 2.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 2.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-4.1-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "4.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-4.1-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "4.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-4.1-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "4.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-4.1-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "4.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile benchmarks, golden images, configuration management, IaC, MDM, cloud policy, network controllers, drift scans, and change records and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 基准、黄金镜像、配置管理、IaC、MDM、云策略、网络控制器、漂移扫描和变更记录，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-4.1-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "4.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Require every connector carrying an enforceable allow, deny, contain, quarantine, require, remove, or transform decision at the closest reliable control point to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 在最近可靠控制点执行允许、拒绝、遏制、隔离、强制、移除或转换决策 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-4.1-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "4.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Require every connector carrying a documented decision system with policy, process, procedure, accountable owner, approval, and review to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 包含策略、流程、程序、责任人、审批和复核的文档化决策系统 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-4.1-INT-08",
          "local_code": "INT-08",
          "display_code": "I08",
          "safeguard_id": "4.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Define consistency rules across disagreeing sources, source precedence, confidence, reconciliation queues, dead-letter handling, reprocessing, and end-to-end trace identity.",
          "zh": "定义冲突来源的一致性、优先级、置信度、对账队列、死信、重处理和端到端追踪身份。"
        },
        {
          "code": "CIS-4.1-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "4.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Create risk-based, version-controlled baselines from authoritative hardening guidance; document values, rationale, allowed deviations, deployment method, validation and rollback.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“从权威加固指南生成风险化、版本化基线，写明取值、理由、允许偏差、部署、验证与回滚。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-4.1-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "4.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-4.1-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "4.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-4.1-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "4.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-4.1-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "4.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the versioned secure-configuration authority and exception register and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在版本化安全配置权威库与例外台账中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-4.1-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "4.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Implement the explicit state machine observe → evaluate → decide → enforce → verify outcome → rollback/close; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-4.1-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "4.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Implement the explicit state machine draft → reviewed → approved → effective → exception/withdrawn → superseded; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-4.1-CTL-08",
          "local_code": "CTL-08",
          "display_code": "C08",
          "safeguard_id": "4.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Specify concurrent decisions, partial success, compensating transactions, repeated requests, stale policy, dependency outage, and recovery from an interrupted state transition.",
          "zh": "定义并发决策、部分成功、补偿事务、重复请求、陈旧策略、依赖中断和中途状态转换恢复。"
        },
        {
          "code": "CIS-4.1-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "4.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (annually); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（annually）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-4.1-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "4.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-4.1-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "4.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-4.1-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "4.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-4.1-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "4.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in role-specific secure baselines and effective configurations for endpoints, servers, mobile, cloud, network, software, and administrative paths; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 终端、服务器、移动、云、网络、软件和管理路径的角色化安全基线与实际配置 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-4.1-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "4.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for observe → evaluate → decide → enforce → verify outcome → rollback/close; alert before each deadline becomes overdue.",
          "zh": "为“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-4.1-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "4.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for draft → reviewed → approved → effective → exception/withdrawn → superseded; alert before each deadline becomes overdue.",
          "zh": "为“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-4.1-TIM-08",
          "local_code": "TIM-08",
          "display_code": "T08",
          "safeguard_id": "4.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Allocate an end-to-end SLO budget across discovery, collection, processing, approval, enforcement, verification, and closure; prioritize overdue work by consequence and exposure.",
          "zh": "把端到端 SLO 预算分配到发现、采集、处理、审批、执行、验证和关闭，并按后果与暴露排列逾期工作。"
        },
        {
          "code": "CIS-4.1-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "4.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “A secure setting can break safety, availability or vendor support, so deviations are exact, owned, compensated, expiring and retested.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“安全设置可能影响安全性、可用性或厂商支持，偏差因此必须精确、具名、有补偿、会到期并复测。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-4.1-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "4.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-4.1-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "4.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-4.1-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "4.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-4.1-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "4.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat unsupported settings, local overrides, inherited cloud policy, vendor defaults, emergency access, safety constraints, drift, and rollback as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 不支持的设置、本地覆盖、继承云策略、厂商默认值、紧急访问、安全约束、漂移和回滚 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-4.1-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "4.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Treat audit-only mode, unsupported platforms, local overrides, race conditions, cached state, alternate paths, fail-open behavior, and emergency bypass as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 仅审计模式、不支持平台、本地覆盖、竞态、缓存状态、替代路径、故障开放和紧急绕过 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-4.1-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "4.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Treat missing policy clauses, conflicting authorities, local deviations, obsolete documentation, and decisions made outside the governed workflow as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 策略条款缺失、权限冲突、本地偏离、文档过期及绕过治理流程的决策 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-4.1-EXC-08",
          "local_code": "EXC-08",
          "display_code": "X08",
          "safeguard_id": "4.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Exercise compound failures where an exception, stale source, provider outage, unavailable owner, and degraded control overlap; define one safe command and one accountable decision.",
          "zh": "演练例外、陈旧来源、提供商中断、责任人不可用和控制降级同时出现的复合故障，明确一条安全指令和一个责任决策。"
        },
        {
          "code": "CIS-4.1-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "4.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Build a clean instance from the baseline and test required business paths, then introduce a prohibited setting and verify drift detection and repair.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“用基线构建干净实例并跑通业务，再引入一个禁止设置，验证漂移发现与修复。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-4.1-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "4.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-4.1-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "4.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 9 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、9 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-4.1-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "4.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-4.1-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "4.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the versioned secure-configuration authority and exception register plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以版本化安全配置权威库与例外台账和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-4.1-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "4.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Publish eligible, enforcing, audit-only, failed, bypassed, excepted, rolled-back, and outcome-verified populations with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 适用、已执行、仅审计、失败、被绕过、例外、已回滚和结果已验证总体，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-4.1-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "4.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Publish clause coverage, owner and reviewer completeness, approval age, triggered reviews, deviations, overdue actions, and superseded versions still in use with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 条款覆盖、责任人与复核人完整性、批准年龄、触发式复核、偏离、逾期行动及仍在使用的旧版本，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-4.1-EVD-08",
          "local_code": "EVD-08",
          "display_code": "E08",
          "safeguard_id": "4.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Require an independent party to reconstruct the decision from source receipts and reproduce the population, state transition, calculation, test result, exception, and final closure.",
          "zh": "要求独立人员使用来源回执重建决策，并复现总体、状态转换、计算、测试结果、例外和最终关闭。"
        },
        {
          "code": "CIS-4.1-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "4.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-4.1-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "4.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-4.1-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "4.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-4.1-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "4.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-4.1-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "4.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the versioned secure-configuration authority and exception register; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护版本化安全配置权威库与例外台账的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-4.1-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "4.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Restrict authority to change observe → evaluate → decide → enforce → verify outcome → rollback/close; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-4.1-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "4.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Restrict authority to change draft → reviewed → approved → effective → exception/withdrawn → superseded; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-4.1-SEC-08",
          "local_code": "SEC-08",
          "display_code": "S08",
          "safeguard_id": "4.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Threat-model the implementation system itself: forged evidence, poisoned inventory, privilege abuse, cross-tenant confusion, policy rollback, audit deletion, denial of service, and recovery compromise.",
          "zh": "威胁建模实施系统自身：伪造证据、污染清单、权限滥用、跨租户混淆、策略回滚、审计删除、拒绝服务和恢复失陷。"
        },
        {
          "code": "CIS-4.1-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "4.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-4.1-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "4.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-4.1-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "4.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-4.1-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "4.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-4.1-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "4.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise approved business behavior, a prohibited setting or service, policy tampering, failed rollout, drift recurrence, and tested rollback through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 获批业务行为、禁止设置或服务、策略篡改、发布失败、漂移复发和已测试回滚，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-4.1-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "4.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Run the positive control an approved business action that completes through the enforced path; exercise negative, stale, duplicate, bypass, and outage controls including a prohibited action, alternate path, local override, stale policy, control outage, emergency bypass, and rollback failure.",
          "zh": "运行正向控制“通过受控路径完成的一项获批业务动作”，并执行包含“禁止动作、替代路径、本地覆盖、陈旧策略、控制中断、紧急绕过和回滚失败”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-4.1-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "4.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Run the positive control an approved current process used for a representative decision; exercise negative, stale, duplicate, bypass, and outage controls including an obsolete version, missing approver, undocumented deviation, overdue review, and bypassed workflow.",
          "zh": "运行正向控制“使用当前获批流程完成一项代表性决策”，并执行包含“旧版本、审批人缺失、未记录偏离、逾期复核和绕过流程”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-4.1-TST-08",
          "local_code": "TST-08",
          "display_code": "V08",
          "safeguard_id": "4.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Build a pairwise platform-and-failure matrix, then add high-consequence multi-factor cases, historical regression, source substitution, red-team challenge, and assessor replay.",
          "zh": "建立平台—故障两两组合矩阵，再加入高后果多因素案例、历史回归、来源替换、红队挑战和评估方重放。"
        },
        {
          "code": "CIS-4.1-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "4.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-4.1-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "4.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-4.1-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "4.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-4.1-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "4.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-4.1-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "4.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever benchmarks, golden images, configuration management, IaC, MDM, cloud policy, network controllers, drift scans, and change records change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 基准、黄金镜像、配置管理、IaC、MDM、云策略、网络控制器、漂移扫描和变更记录 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-4.1-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "4.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Use eligible, enforcing, audit-only, failed, bypassed, excepted, rolled-back, and outcome-verified populations to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 适用、已执行、仅审计、失败、被绕过、例外、已回滚和结果已验证总体 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-4.1-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "4.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Use clause coverage, owner and reviewer completeness, approval age, triggered reviews, deviations, overdue actions, and superseded versions still in use to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 条款覆盖、责任人与复核人完整性、批准年龄、触发式复核、偏离、逾期行动及仍在使用的旧版本 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-4.1-OPS-08",
          "local_code": "OPS-08",
          "display_code": "R08",
          "safeguard_id": "4.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Use canary deployment, kill criteria, rollback, backlog burn-down, exception reduction, source-quality targets, quarterly design review, and a measurable retirement plan.",
          "zh": "采用金丝雀、停止标准、回滚、积压燃尽、例外缩减、来源质量目标、季度设计复核和可量化退役计划。"
        }
      ]
    },
    {
      "id": "4.2",
      "control": 4,
      "title_en": "Establish and Maintain a Secure Configuration Process for Network Infrastructure",
      "title_zh": "网络基础设施安全配置流程",
      "first_ig": 1,
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Documentation",
      "security_function": "Govern",
      "patterns": [
        "enforcement",
        "network",
        "governance"
      ],
      "expanded_complexity": true,
      "cas_context": {
        "dependencies": [
          "2.1"
        ],
        "variables": [
          "GV1",
          "GV3",
          "GV5",
          "M1",
          "M2",
          "M3",
          "M4",
          "M5",
          "M6"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [
        "annually"
      ],
      "implementation_contract": {
        "en": {
          "scope": "Include routers, switches, firewalls, wireless, load balancers, DNS/DHCP, VPN, SD-WAN, cloud networks, service meshes and management controllers across physical and virtual infrastructure.",
          "build": "Maintain versioned baselines by device role and trust zone covering management plane, authentication, protocols, routing, logging, time, services, backups and control-plane protection.",
          "proof": "Compare running and intended configuration after normalization, sample devices from every role, and inject a harmless drift in a test segment.",
          "boundary": "High availability pairs, controller-generated state and emergency routing can make text diffs misleading."
        },
        "zh": {
          "scope": "包括路由器、交换机、防火墙、无线、负载均衡、DNS/DHCP、VPN、SD-WAN、云网络、服务网格和管理控制器。",
          "build": "按设备角色和信任区维护版本化基线，覆盖管理面、认证、协议、路由、日志、时间、服务、备份和控制面保护。",
          "proof": "归一化后比较运行与意图配置，从每种角色抽样，并在测试区注入无害漂移，验证批准、部署、发现、回滚和日志。",
          "boundary": "HA 对、控制器生成状态与应急路由会让纯文本 Diff 误导。"
        }
      },
      "category_counts": {
        "outcome": 9,
        "scope": 9,
        "ownership": 9,
        "data": 9,
        "integration": 9,
        "control": 9,
        "timing": 9,
        "exception": 9,
        "evidence": 9,
        "security": 9,
        "testing": 9,
        "operations": 9
      },
      "requirement_count": 108,
      "requirements": [
        {
          "code": "CIS-4.2-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "4.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Establish and Maintain a Secure Configuration Process for Network Infrastructure; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“网络基础设施安全配置流程”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-4.2-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "4.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 4.2, official Asset Class Documentation, Security Function Govern, and IG1 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 4.2、官方资产类别“文档与治理”、安全功能“治理”和首次出现的 IG1，并保存来源抓取日期。"
        },
        {
          "code": "CIS-4.2-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "4.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Include routers, switches, firewalls, wireless, load balancers, DNS/DHCP, VPN, SD-WAN, cloud networks, service meshes and management controllers across physical and virtual infrastructure.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“包括路由器、交换机、防火墙、无线、负载均衡、DNS/DHCP、VPN、SD-WAN、云网络、服务网格和管理控制器。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-4.2-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "4.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-4.2-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "4.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Establish and Maintain a Secure Configuration Process for Network Infrastructure to its operating object—role-specific secure baselines and effective configurations for endpoints, servers, mobile, cloud, network, software, and administrative paths—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“网络基础设施安全配置流程”连接到其运营对象——终端、服务器、移动、云、网络、软件和管理路径的角色化安全基线与实际配置——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-4.2-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "4.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "For Establish and Maintain a Secure Configuration Process for Network Infrastructure, express success as an observable decision over an enforceable allow, deny, contain, quarantine, require, remove, or transform decision at the closest reliable control point; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“网络基础设施安全配置流程”，以 在最近可靠控制点执行允许、拒绝、遏制、隔离、强制、移除或转换决策 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-4.2-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "4.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "For Establish and Maintain a Secure Configuration Process for Network Infrastructure, express success as an observable decision over intended connectivity, trust zone, route, protocol, identity, management path, traffic decision, and observed outcome; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“网络基础设施安全配置流程”，以 预期连接、信任区、路由、协议、身份、管理路径、流量决策和观察结果 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-4.2-OUT-08",
          "local_code": "OUT-08",
          "display_code": "O08",
          "safeguard_id": "4.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "For Establish and Maintain a Secure Configuration Process for Network Infrastructure, express success as an observable decision over a documented decision system with policy, process, procedure, accountable owner, approval, and review; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“网络基础设施安全配置流程”，以 包含策略、流程、程序、责任人、审批和复核的文档化决策系统 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-4.2-OUT-09",
          "local_code": "OUT-09",
          "display_code": "O09",
          "safeguard_id": "4.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "For the expanded Establish and Maintain a Secure Configuration Process for Network Infrastructure scope, resolve conflicts among security, safety, privacy, legal, availability, customer, and operational objectives through an explicit risk decision.",
          "zh": "对“网络基础设施安全配置流程”的扩展范围，通过显式风险决策解决安全、安全生产、隐私、法律、可用性、客户和运营目标冲突。"
        },
        {
          "code": "CIS-4.2-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "4.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-4.2-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "4.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-4.2-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "4.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-4.2-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "4.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-4.2-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "4.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across unsupported settings, local overrides, inherited cloud policy, vendor defaults, emergency access, safety constraints, drift, and rollback; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 不支持的设置、本地覆盖、继承云策略、厂商默认值、紧急访问、安全约束、漂移和回滚 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-4.2-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "4.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Include audit-only mode, unsupported platforms, local overrides, race conditions, cached state, alternate paths, fail-open behavior, and emergency bypass in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 仅审计模式、不支持平台、本地覆盖、竞态、缓存状态、替代路径、故障开放和紧急绕过 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-4.2-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "4.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Include IPv6, overlays, east-west paths, remote and roaming devices, direct egress, alternate resolvers, QUIC, asymmetric routes, provider abstraction, and emergency consoles in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 IPv6、覆盖网络、东西向路径、远程与漫游设备、直接出口、替代解析器、QUIC、非对称路由、提供商抽象和紧急控制台 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-4.2-SCP-08",
          "local_code": "SCP-08",
          "display_code": "P08",
          "safeguard_id": "4.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Include missing policy clauses, conflicting authorities, local deviations, obsolete documentation, and decisions made outside the governed workflow in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 策略条款缺失、权限冲突、本地偏离、文档过期及绕过治理流程的决策 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-4.2-SCP-09",
          "local_code": "SCP-09",
          "display_code": "P09",
          "safeguard_id": "4.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Define nested scope at enterprise, business service, tenant, environment, platform, object, identity, data set, and transaction levels; prohibit a parent result from hiding a failing child.",
          "zh": "按企业、业务服务、租户、环境、平台、对象、身份、数据集和交易定义嵌套范围，禁止父级结果遮蔽失败子级。"
        },
        {
          "code": "CIS-4.2-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "4.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-4.2-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "4.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-4.2-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "4.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-4.2-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "4.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-4.2-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "4.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind platform and application owners, network engineering, security architecture, change management, and service owners to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 平台与应用责任人、网络工程、安全架构、变更管理和服务责任人 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-4.2-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "4.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Name who may transition observe → evaluate → decide → enforce → verify outcome → rollback/close, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-4.2-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "4.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Name who may transition requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-4.2-OWN-08",
          "local_code": "OWN-08",
          "display_code": "W08",
          "safeguard_id": "4.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Name who may transition draft → reviewed → approved → effective → exception/withdrawn → superseded, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-4.2-OWN-09",
          "local_code": "OWN-09",
          "display_code": "W09",
          "safeguard_id": "4.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Model delegated authority, quorum or dual approval where warranted, escalation deadlines, provider handoffs, conflict resolution, and executive risk acceptance.",
          "zh": "建模委派权限、必要时的双人或法定人数审批、升级期限、提供商交接、冲突解决和管理层风险接受。"
        },
        {
          "code": "CIS-4.2-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "4.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-4.2-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "4.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-4.2-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "4.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV1, GV3, GV5, M1, M2, M3, M4, M5, M6) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV1, GV3, GV5, M1, M2, M3, M4, M5, M6）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-4.2-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "4.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-4.2-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "4.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the versioned secure-configuration authority and exception register as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把版本化安全配置权威库与例外台账作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-4.2-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "4.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle observe → evaluate → decide → enforce → verify outcome → rollback/close.",
          "zh": "对生命周期“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-4.2-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "4.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired.",
          "zh": "对生命周期“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-4.2-DAT-08",
          "local_code": "DAT-08",
          "display_code": "D08",
          "safeguard_id": "4.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle draft → reviewed → approved → effective → exception/withdrawn → superseded.",
          "zh": "对生命周期“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-4.2-DAT-09",
          "local_code": "DAT-09",
          "display_code": "D09",
          "safeguard_id": "4.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Version schemas and state transitions with migration, backfill, deduplication, lineage, historical denominator, deletion, and rollback semantics.",
          "zh": "对模式和状态转换做版本管理，定义迁移、回填、去重、血缘、历史分母、删除和回滚语义。"
        },
        {
          "code": "CIS-4.2-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "4.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 2.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 2.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-4.2-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "4.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-4.2-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "4.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-4.2-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "4.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-4.2-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "4.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile benchmarks, golden images, configuration management, IaC, MDM, cloud policy, network controllers, drift scans, and change records and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 基准、黄金镜像、配置管理、IaC、MDM、云策略、网络控制器、漂移扫描和变更记录，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-4.2-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "4.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Require every connector carrying an enforceable allow, deny, contain, quarantine, require, remove, or transform decision at the closest reliable control point to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 在最近可靠控制点执行允许、拒绝、遏制、隔离、强制、移除或转换决策 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-4.2-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "4.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Require every connector carrying intended connectivity, trust zone, route, protocol, identity, management path, traffic decision, and observed outcome to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 预期连接、信任区、路由、协议、身份、管理路径、流量决策和观察结果 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-4.2-INT-08",
          "local_code": "INT-08",
          "display_code": "I08",
          "safeguard_id": "4.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Require every connector carrying a documented decision system with policy, process, procedure, accountable owner, approval, and review to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 包含策略、流程、程序、责任人、审批和复核的文档化决策系统 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-4.2-INT-09",
          "local_code": "INT-09",
          "display_code": "I09",
          "safeguard_id": "4.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Define consistency rules across disagreeing sources, source precedence, confidence, reconciliation queues, dead-letter handling, reprocessing, and end-to-end trace identity.",
          "zh": "定义冲突来源的一致性、优先级、置信度、对账队列、死信、重处理和端到端追踪身份。"
        },
        {
          "code": "CIS-4.2-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "4.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Maintain versioned baselines by device role and trust zone covering management plane, authentication, protocols, routing, logging, time, services, backups and control-plane protection.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“按设备角色和信任区维护版本化基线，覆盖管理面、认证、协议、路由、日志、时间、服务、备份和控制面保护。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-4.2-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "4.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-4.2-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "4.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-4.2-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "4.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-4.2-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "4.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the versioned secure-configuration authority and exception register and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在版本化安全配置权威库与例外台账中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-4.2-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "4.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Implement the explicit state machine observe → evaluate → decide → enforce → verify outcome → rollback/close; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-4.2-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "4.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Implement the explicit state machine requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-4.2-CTL-08",
          "local_code": "CTL-08",
          "display_code": "C08",
          "safeguard_id": "4.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Implement the explicit state machine draft → reviewed → approved → effective → exception/withdrawn → superseded; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-4.2-CTL-09",
          "local_code": "CTL-09",
          "display_code": "C09",
          "safeguard_id": "4.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Specify concurrent decisions, partial success, compensating transactions, repeated requests, stale policy, dependency outage, and recovery from an interrupted state transition.",
          "zh": "定义并发决策、部分成功、补偿事务、重复请求、陈旧策略、依赖中断和中途状态转换恢复。"
        },
        {
          "code": "CIS-4.2-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "4.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (annually); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（annually）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-4.2-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "4.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-4.2-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "4.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-4.2-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "4.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-4.2-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "4.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in role-specific secure baselines and effective configurations for endpoints, servers, mobile, cloud, network, software, and administrative paths; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 终端、服务器、移动、云、网络、软件和管理路径的角色化安全基线与实际配置 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-4.2-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "4.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for observe → evaluate → decide → enforce → verify outcome → rollback/close; alert before each deadline becomes overdue.",
          "zh": "为“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-4.2-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "4.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; alert before each deadline becomes overdue.",
          "zh": "为“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-4.2-TIM-08",
          "local_code": "TIM-08",
          "display_code": "T08",
          "safeguard_id": "4.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for draft → reviewed → approved → effective → exception/withdrawn → superseded; alert before each deadline becomes overdue.",
          "zh": "为“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-4.2-TIM-09",
          "local_code": "TIM-09",
          "display_code": "T09",
          "safeguard_id": "4.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Allocate an end-to-end SLO budget across discovery, collection, processing, approval, enforcement, verification, and closure; prioritize overdue work by consequence and exposure.",
          "zh": "把端到端 SLO 预算分配到发现、采集、处理、审批、执行、验证和关闭，并按后果与暴露排列逾期工作。"
        },
        {
          "code": "CIS-4.2-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "4.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “High availability pairs, controller-generated state and emergency routing can make text diffs misleading.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“HA 对、控制器生成状态与应急路由会让纯文本 Diff 误导。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-4.2-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "4.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-4.2-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "4.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-4.2-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "4.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-4.2-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "4.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat unsupported settings, local overrides, inherited cloud policy, vendor defaults, emergency access, safety constraints, drift, and rollback as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 不支持的设置、本地覆盖、继承云策略、厂商默认值、紧急访问、安全约束、漂移和回滚 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-4.2-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "4.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Treat audit-only mode, unsupported platforms, local overrides, race conditions, cached state, alternate paths, fail-open behavior, and emergency bypass as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 仅审计模式、不支持平台、本地覆盖、竞态、缓存状态、替代路径、故障开放和紧急绕过 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-4.2-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "4.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Treat IPv6, overlays, east-west paths, remote and roaming devices, direct egress, alternate resolvers, QUIC, asymmetric routes, provider abstraction, and emergency consoles as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 IPv6、覆盖网络、东西向路径、远程与漫游设备、直接出口、替代解析器、QUIC、非对称路由、提供商抽象和紧急控制台 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-4.2-EXC-08",
          "local_code": "EXC-08",
          "display_code": "X08",
          "safeguard_id": "4.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Treat missing policy clauses, conflicting authorities, local deviations, obsolete documentation, and decisions made outside the governed workflow as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 策略条款缺失、权限冲突、本地偏离、文档过期及绕过治理流程的决策 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-4.2-EXC-09",
          "local_code": "EXC-09",
          "display_code": "X09",
          "safeguard_id": "4.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Exercise compound failures where an exception, stale source, provider outage, unavailable owner, and degraded control overlap; define one safe command and one accountable decision.",
          "zh": "演练例外、陈旧来源、提供商中断、责任人不可用和控制降级同时出现的复合故障，明确一条安全指令和一个责任决策。"
        },
        {
          "code": "CIS-4.2-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "4.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Compare running and intended configuration after normalization, sample devices from every role, and inject a harmless drift in a test segment.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“归一化后比较运行与意图配置，从每种角色抽样，并在测试区注入无害漂移，验证批准、部署、发现、回滚和日志。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-4.2-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "4.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-4.2-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "4.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 9 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、9 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-4.2-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "4.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-4.2-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "4.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the versioned secure-configuration authority and exception register plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以版本化安全配置权威库与例外台账和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-4.2-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "4.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Publish eligible, enforcing, audit-only, failed, bypassed, excepted, rolled-back, and outcome-verified populations with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 适用、已执行、仅审计、失败、被绕过、例外、已回滚和结果已验证总体，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-4.2-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "4.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Publish known, unknown, allowed, denied, shadow, bypassed, asymmetric, stale-rule, exception, and unobserved paths with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已知、未知、允许、拒绝、影子、绕过、非对称、陈旧规则、例外和未观测路径，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-4.2-EVD-08",
          "local_code": "EVD-08",
          "display_code": "E08",
          "safeguard_id": "4.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Publish clause coverage, owner and reviewer completeness, approval age, triggered reviews, deviations, overdue actions, and superseded versions still in use with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 条款覆盖、责任人与复核人完整性、批准年龄、触发式复核、偏离、逾期行动及仍在使用的旧版本，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-4.2-EVD-09",
          "local_code": "EVD-09",
          "display_code": "E09",
          "safeguard_id": "4.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Require an independent party to reconstruct the decision from source receipts and reproduce the population, state transition, calculation, test result, exception, and final closure.",
          "zh": "要求独立人员使用来源回执重建决策，并复现总体、状态转换、计算、测试结果、例外和最终关闭。"
        },
        {
          "code": "CIS-4.2-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "4.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-4.2-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "4.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-4.2-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "4.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-4.2-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "4.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-4.2-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "4.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the versioned secure-configuration authority and exception register; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护版本化安全配置权威库与例外台账的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-4.2-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "4.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Restrict authority to change observe → evaluate → decide → enforce → verify outcome → rollback/close; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-4.2-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "4.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Restrict authority to change requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-4.2-SEC-08",
          "local_code": "SEC-08",
          "display_code": "S08",
          "safeguard_id": "4.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Restrict authority to change draft → reviewed → approved → effective → exception/withdrawn → superseded; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-4.2-SEC-09",
          "local_code": "SEC-09",
          "display_code": "S09",
          "safeguard_id": "4.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Threat-model the implementation system itself: forged evidence, poisoned inventory, privilege abuse, cross-tenant confusion, policy rollback, audit deletion, denial of service, and recovery compromise.",
          "zh": "威胁建模实施系统自身：伪造证据、污染清单、权限滥用、跨租户混淆、策略回滚、审计删除、拒绝服务和恢复失陷。"
        },
        {
          "code": "CIS-4.2-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "4.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-4.2-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "4.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-4.2-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "4.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-4.2-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "4.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-4.2-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "4.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise approved business behavior, a prohibited setting or service, policy tampering, failed rollout, drift recurrence, and tested rollback through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 获批业务行为、禁止设置或服务、策略篡改、发布失败、漂移复发和已测试回滚，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-4.2-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "4.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Run the positive control an approved business action that completes through the enforced path; exercise negative, stale, duplicate, bypass, and outage controls including a prohibited action, alternate path, local override, stale policy, control outage, emergency bypass, and rollback failure.",
          "zh": "运行正向控制“通过受控路径完成的一项获批业务动作”，并执行包含“禁止动作、替代路径、本地覆盖、陈旧策略、控制中断、紧急绕过和回滚失败”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-4.2-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "4.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Run the positive control an approved flow over the required secure management or business path; exercise negative, stale, duplicate, bypass, and outage controls including an unapproved route, protocol downgrade, direct egress, alternate DNS/QUIC path, segmentation bypass, AAA loss, stale rule, and rollback failure.",
          "zh": "运行正向控制“通过规定安全管理或业务路径的一项获批流量”，并执行包含“未批准路由、协议降级、直接出口、替代 DNS/QUIC 路径、分段绕过、AAA 丢失、陈旧规则和回滚失败”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-4.2-TST-08",
          "local_code": "TST-08",
          "display_code": "V08",
          "safeguard_id": "4.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Run the positive control an approved current process used for a representative decision; exercise negative, stale, duplicate, bypass, and outage controls including an obsolete version, missing approver, undocumented deviation, overdue review, and bypassed workflow.",
          "zh": "运行正向控制“使用当前获批流程完成一项代表性决策”，并执行包含“旧版本、审批人缺失、未记录偏离、逾期复核和绕过流程”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-4.2-TST-09",
          "local_code": "TST-09",
          "display_code": "V09",
          "safeguard_id": "4.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Build a pairwise platform-and-failure matrix, then add high-consequence multi-factor cases, historical regression, source substitution, red-team challenge, and assessor replay.",
          "zh": "建立平台—故障两两组合矩阵，再加入高后果多因素案例、历史回归、来源替换、红队挑战和评估方重放。"
        },
        {
          "code": "CIS-4.2-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "4.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-4.2-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "4.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-4.2-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "4.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-4.2-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "4.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-4.2-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "4.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever benchmarks, golden images, configuration management, IaC, MDM, cloud policy, network controllers, drift scans, and change records change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 基准、黄金镜像、配置管理、IaC、MDM、云策略、网络控制器、漂移扫描和变更记录 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-4.2-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "4.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Use eligible, enforcing, audit-only, failed, bypassed, excepted, rolled-back, and outcome-verified populations to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 适用、已执行、仅审计、失败、被绕过、例外、已回滚和结果已验证总体 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-4.2-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "4.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Use known, unknown, allowed, denied, shadow, bypassed, asymmetric, stale-rule, exception, and unobserved paths to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已知、未知、允许、拒绝、影子、绕过、非对称、陈旧规则、例外和未观测路径 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-4.2-OPS-08",
          "local_code": "OPS-08",
          "display_code": "R08",
          "safeguard_id": "4.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Use clause coverage, owner and reviewer completeness, approval age, triggered reviews, deviations, overdue actions, and superseded versions still in use to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 条款覆盖、责任人与复核人完整性、批准年龄、触发式复核、偏离、逾期行动及仍在使用的旧版本 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-4.2-OPS-09",
          "local_code": "OPS-09",
          "display_code": "R09",
          "safeguard_id": "4.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Use canary deployment, kill criteria, rollback, backlog burn-down, exception reduction, source-quality targets, quarterly design review, and a measurable retirement plan.",
          "zh": "采用金丝雀、停止标准、回滚、积压燃尽、例外缩减、来源质量目标、季度设计复核和可量化退役计划。"
        }
      ]
    },
    {
      "id": "4.3",
      "control": 4,
      "title_en": "Configure Automatic Session Locking on Enterprise Assets",
      "title_zh": "自动会话锁定",
      "first_ig": 1,
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Devices",
      "security_function": "Protect",
      "patterns": [
        "enforcement"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "1.1",
          "2.1",
          "4.1"
        ],
        "variables": [
          "GV1",
          "GV3",
          "GV5",
          "M1",
          "M2",
          "M3",
          "M4",
          "M5",
          "M6"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [
        "15 minutes",
        "2 minutes"
      ],
      "implementation_contract": {
        "en": {
          "scope": "Eligible interactive sessions include desktop, laptop, mobile, virtual desktop, jump host and administrative consoles that can expose enterprise data or authority after inactivity.",
          "build": "Enforce no more than 15 minutes on general-purpose systems and two minutes on mobile through central configuration, with reauthentication on unlock.",
          "proof": "Measure effective live policy and last check for all eligible devices, then leave a session idle beyond the threshold and verify screen lock, protected data, remote/virtual behavior and reauthentication.",
          "boundary": "A screen saver without authentication fails."
        },
        "zh": {
          "scope": "适用会话包括台式机、笔记本、移动设备、VDI、跳板机和可暴露企业数据/权限的管理控制台。",
          "build": "通用系统空闲锁定不超过 15 分钟，移动端不超过 2 分钟，解锁须重新认证；高权限或暴露场景可更短，普通用户不能放宽。",
          "proof": "读取全部合格设备的实时有效策略和最后检查时间，等待超过阈值，验证屏幕、数据、远程/虚拟会话与重新认证；再测试篡改策略和睡眠恢复。",
          "boundary": "只有屏保而无认证即失败。"
        }
      },
      "category_counts": {
        "outcome": 6,
        "scope": 6,
        "ownership": 6,
        "data": 6,
        "integration": 6,
        "control": 6,
        "timing": 6,
        "exception": 6,
        "evidence": 6,
        "security": 6,
        "testing": 6,
        "operations": 6
      },
      "requirement_count": 72,
      "requirements": [
        {
          "code": "CIS-4.3-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "4.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Configure Automatic Session Locking on Enterprise Assets; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“自动会话锁定”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-4.3-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "4.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 4.3, official Asset Class Devices, Security Function Protect, and IG1 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 4.3、官方资产类别“设备”、安全功能“保护”和首次出现的 IG1，并保存来源抓取日期。"
        },
        {
          "code": "CIS-4.3-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "4.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Eligible interactive sessions include desktop, laptop, mobile, virtual desktop, jump host and administrative consoles that can expose enterprise data or authority after inactivity.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“适用会话包括台式机、笔记本、移动设备、VDI、跳板机和可暴露企业数据/权限的管理控制台。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-4.3-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "4.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-4.3-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "4.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Configure Automatic Session Locking on Enterprise Assets to its operating object—role-specific secure baselines and effective configurations for endpoints, servers, mobile, cloud, network, software, and administrative paths—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“自动会话锁定”连接到其运营对象——终端、服务器、移动、云、网络、软件和管理路径的角色化安全基线与实际配置——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-4.3-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "4.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "For Configure Automatic Session Locking on Enterprise Assets, express success as an observable decision over an enforceable allow, deny, contain, quarantine, require, remove, or transform decision at the closest reliable control point; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“自动会话锁定”，以 在最近可靠控制点执行允许、拒绝、遏制、隔离、强制、移除或转换决策 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-4.3-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "4.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-4.3-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "4.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-4.3-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "4.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-4.3-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "4.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-4.3-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "4.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across unsupported settings, local overrides, inherited cloud policy, vendor defaults, emergency access, safety constraints, drift, and rollback; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 不支持的设置、本地覆盖、继承云策略、厂商默认值、紧急访问、安全约束、漂移和回滚 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-4.3-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "4.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Include audit-only mode, unsupported platforms, local overrides, race conditions, cached state, alternate paths, fail-open behavior, and emergency bypass in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 仅审计模式、不支持平台、本地覆盖、竞态、缓存状态、替代路径、故障开放和紧急绕过 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-4.3-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "4.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-4.3-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "4.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-4.3-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "4.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-4.3-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "4.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-4.3-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "4.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind platform and application owners, network engineering, security architecture, change management, and service owners to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 平台与应用责任人、网络工程、安全架构、变更管理和服务责任人 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-4.3-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "4.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Name who may transition observe → evaluate → decide → enforce → verify outcome → rollback/close, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-4.3-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "4.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-4.3-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "4.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-4.3-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "4.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV1, GV3, GV5, M1, M2, M3, M4, M5, M6) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV1, GV3, GV5, M1, M2, M3, M4, M5, M6）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-4.3-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "4.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-4.3-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "4.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the versioned secure-configuration authority and exception register as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把版本化安全配置权威库与例外台账作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-4.3-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "4.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle observe → evaluate → decide → enforce → verify outcome → rollback/close.",
          "zh": "对生命周期“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-4.3-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "4.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 1.1, Safeguard 2.1, Safeguard 4.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 1.1、Safeguard 2.1、Safeguard 4.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-4.3-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "4.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-4.3-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "4.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-4.3-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "4.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-4.3-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "4.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile benchmarks, golden images, configuration management, IaC, MDM, cloud policy, network controllers, drift scans, and change records and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 基准、黄金镜像、配置管理、IaC、MDM、云策略、网络控制器、漂移扫描和变更记录，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-4.3-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "4.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Require every connector carrying an enforceable allow, deny, contain, quarantine, require, remove, or transform decision at the closest reliable control point to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 在最近可靠控制点执行允许、拒绝、遏制、隔离、强制、移除或转换决策 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-4.3-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "4.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Enforce no more than 15 minutes on general-purpose systems and two minutes on mobile through central configuration, with reauthentication on unlock.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“通用系统空闲锁定不超过 15 分钟，移动端不超过 2 分钟，解锁须重新认证；高权限或暴露场景可更短，普通用户不能放宽。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-4.3-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "4.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-4.3-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "4.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-4.3-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "4.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-4.3-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "4.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the versioned secure-configuration authority and exception register and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在版本化安全配置权威库与例外台账中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-4.3-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "4.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Implement the explicit state machine observe → evaluate → decide → enforce → verify outcome → rollback/close; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-4.3-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "4.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (15 minutes, 2 minutes); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（15 minutes, 2 minutes）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-4.3-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "4.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-4.3-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "4.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-4.3-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "4.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-4.3-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "4.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in role-specific secure baselines and effective configurations for endpoints, servers, mobile, cloud, network, software, and administrative paths; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 终端、服务器、移动、云、网络、软件和管理路径的角色化安全基线与实际配置 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-4.3-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "4.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for observe → evaluate → decide → enforce → verify outcome → rollback/close; alert before each deadline becomes overdue.",
          "zh": "为“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-4.3-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "4.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “A screen saver without authentication fails.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“只有屏保而无认证即失败。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-4.3-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "4.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-4.3-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "4.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-4.3-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "4.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-4.3-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "4.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat unsupported settings, local overrides, inherited cloud policy, vendor defaults, emergency access, safety constraints, drift, and rollback as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 不支持的设置、本地覆盖、继承云策略、厂商默认值、紧急访问、安全约束、漂移和回滚 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-4.3-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "4.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Treat audit-only mode, unsupported platforms, local overrides, race conditions, cached state, alternate paths, fail-open behavior, and emergency bypass as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 仅审计模式、不支持平台、本地覆盖、竞态、缓存状态、替代路径、故障开放和紧急绕过 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-4.3-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "4.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Measure effective live policy and last check for all eligible devices, then leave a session idle beyond the threshold and verify screen lock, protected data, remote/virtual behavior and reauthentication.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“读取全部合格设备的实时有效策略和最后检查时间，等待超过阈值，验证屏幕、数据、远程/虚拟会话与重新认证；再测试篡改策略和睡眠恢复。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-4.3-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "4.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-4.3-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "4.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 9 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、9 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-4.3-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "4.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-4.3-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "4.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the versioned secure-configuration authority and exception register plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以版本化安全配置权威库与例外台账和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-4.3-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "4.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Publish eligible, enforcing, audit-only, failed, bypassed, excepted, rolled-back, and outcome-verified populations with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 适用、已执行、仅审计、失败、被绕过、例外、已回滚和结果已验证总体，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-4.3-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "4.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-4.3-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "4.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-4.3-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "4.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-4.3-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "4.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-4.3-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "4.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the versioned secure-configuration authority and exception register; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护版本化安全配置权威库与例外台账的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-4.3-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "4.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Restrict authority to change observe → evaluate → decide → enforce → verify outcome → rollback/close; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-4.3-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "4.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-4.3-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "4.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-4.3-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "4.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-4.3-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "4.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-4.3-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "4.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise approved business behavior, a prohibited setting or service, policy tampering, failed rollout, drift recurrence, and tested rollback through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 获批业务行为、禁止设置或服务、策略篡改、发布失败、漂移复发和已测试回滚，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-4.3-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "4.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Run the positive control an approved business action that completes through the enforced path; exercise negative, stale, duplicate, bypass, and outage controls including a prohibited action, alternate path, local override, stale policy, control outage, emergency bypass, and rollback failure.",
          "zh": "运行正向控制“通过受控路径完成的一项获批业务动作”，并执行包含“禁止动作、替代路径、本地覆盖、陈旧策略、控制中断、紧急绕过和回滚失败”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-4.3-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "4.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-4.3-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "4.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-4.3-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "4.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-4.3-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "4.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-4.3-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "4.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever benchmarks, golden images, configuration management, IaC, MDM, cloud policy, network controllers, drift scans, and change records change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 基准、黄金镜像、配置管理、IaC、MDM、云策略、网络控制器、漂移扫描和变更记录 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-4.3-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "4.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Use eligible, enforcing, audit-only, failed, bypassed, excepted, rolled-back, and outcome-verified populations to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 适用、已执行、仅审计、失败、被绕过、例外、已回滚和结果已验证总体 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "4.4",
      "control": 4,
      "title_en": "Implement and Manage a Firewall on Servers",
      "title_zh": "服务器主机防火墙",
      "first_ig": 1,
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Devices",
      "security_function": "Protect",
      "patterns": [
        "enforcement",
        "network"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "1.1",
          "2.1",
          "4.1"
        ],
        "variables": [
          "GV1",
          "GV3",
          "GV5",
          "M1",
          "M2",
          "M3",
          "M4",
          "M5",
          "M6"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "The server population includes physical, virtual, cloud and container hosts plus serverless or platform equivalents where a local or workload policy is available.",
          "build": "Apply default-deny or least-exposure ingress and, where risk supports it, egress rules at host, workload, security-group or virtual-firewall layers.",
          "proof": "From allowed and disallowed source zones, test required ports, unexpected listeners, IPv4/IPv6, overlay and management paths.",
          "boundary": "Platform services and clustered control traffic need documented rules, not blanket any-to-any."
        },
        "zh": {
          "scope": "包括物理、虚拟、云和容器宿主服务器，以及有本地/工作负载策略能力的 Serverless 或平台等效物。",
          "build": "在主机、工作负载、安全组或虚拟防火墙层做默认拒绝或最小暴露，按风险控制出站；策略从服务责任和流向生成，集中变更，保留破窗，并把监听服务与允许源/端口对账。",
          "proof": "从允许与不允许源区测试必需端口、意外监听、IPv4/IPv6、Overlay 和管理路径；检查所有合格服务器的有效规则和强制状态，验证停 Agent 或本地加规则能告警并修复，且不会锁死恢复。",
          "boundary": "平台服务和集群控制流需明确规则，不能一条全放。"
        }
      },
      "category_counts": {
        "outcome": 7,
        "scope": 7,
        "ownership": 7,
        "data": 7,
        "integration": 7,
        "control": 7,
        "timing": 7,
        "exception": 7,
        "evidence": 7,
        "security": 7,
        "testing": 7,
        "operations": 7
      },
      "requirement_count": 84,
      "requirements": [
        {
          "code": "CIS-4.4-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "4.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Implement and Manage a Firewall on Servers; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“服务器主机防火墙”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-4.4-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "4.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 4.4, official Asset Class Devices, Security Function Protect, and IG1 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 4.4、官方资产类别“设备”、安全功能“保护”和首次出现的 IG1，并保存来源抓取日期。"
        },
        {
          "code": "CIS-4.4-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "4.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “The server population includes physical, virtual, cloud and container hosts plus serverless or platform equivalents where a local or workload policy is available.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“包括物理、虚拟、云和容器宿主服务器，以及有本地/工作负载策略能力的 Serverless 或平台等效物。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-4.4-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "4.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-4.4-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "4.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Implement and Manage a Firewall on Servers to its operating object—role-specific secure baselines and effective configurations for endpoints, servers, mobile, cloud, network, software, and administrative paths—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“服务器主机防火墙”连接到其运营对象——终端、服务器、移动、云、网络、软件和管理路径的角色化安全基线与实际配置——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-4.4-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "4.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "For Implement and Manage a Firewall on Servers, express success as an observable decision over an enforceable allow, deny, contain, quarantine, require, remove, or transform decision at the closest reliable control point; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“服务器主机防火墙”，以 在最近可靠控制点执行允许、拒绝、遏制、隔离、强制、移除或转换决策 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-4.4-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "4.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "For Implement and Manage a Firewall on Servers, express success as an observable decision over intended connectivity, trust zone, route, protocol, identity, management path, traffic decision, and observed outcome; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“服务器主机防火墙”，以 预期连接、信任区、路由、协议、身份、管理路径、流量决策和观察结果 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-4.4-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "4.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-4.4-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "4.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-4.4-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "4.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-4.4-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "4.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-4.4-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "4.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across unsupported settings, local overrides, inherited cloud policy, vendor defaults, emergency access, safety constraints, drift, and rollback; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 不支持的设置、本地覆盖、继承云策略、厂商默认值、紧急访问、安全约束、漂移和回滚 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-4.4-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "4.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Include audit-only mode, unsupported platforms, local overrides, race conditions, cached state, alternate paths, fail-open behavior, and emergency bypass in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 仅审计模式、不支持平台、本地覆盖、竞态、缓存状态、替代路径、故障开放和紧急绕过 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-4.4-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "4.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Include IPv6, overlays, east-west paths, remote and roaming devices, direct egress, alternate resolvers, QUIC, asymmetric routes, provider abstraction, and emergency consoles in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 IPv6、覆盖网络、东西向路径、远程与漫游设备、直接出口、替代解析器、QUIC、非对称路由、提供商抽象和紧急控制台 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-4.4-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "4.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-4.4-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "4.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-4.4-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "4.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-4.4-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "4.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-4.4-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "4.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind platform and application owners, network engineering, security architecture, change management, and service owners to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 平台与应用责任人、网络工程、安全架构、变更管理和服务责任人 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-4.4-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "4.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Name who may transition observe → evaluate → decide → enforce → verify outcome → rollback/close, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-4.4-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "4.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Name who may transition requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-4.4-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "4.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-4.4-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "4.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-4.4-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "4.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV1, GV3, GV5, M1, M2, M3, M4, M5, M6) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV1, GV3, GV5, M1, M2, M3, M4, M5, M6）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-4.4-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "4.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-4.4-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "4.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the versioned secure-configuration authority and exception register as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把版本化安全配置权威库与例外台账作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-4.4-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "4.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle observe → evaluate → decide → enforce → verify outcome → rollback/close.",
          "zh": "对生命周期“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-4.4-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "4.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired.",
          "zh": "对生命周期“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-4.4-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "4.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 1.1, Safeguard 2.1, Safeguard 4.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 1.1、Safeguard 2.1、Safeguard 4.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-4.4-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "4.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-4.4-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "4.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-4.4-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "4.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-4.4-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "4.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile benchmarks, golden images, configuration management, IaC, MDM, cloud policy, network controllers, drift scans, and change records and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 基准、黄金镜像、配置管理、IaC、MDM、云策略、网络控制器、漂移扫描和变更记录，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-4.4-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "4.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Require every connector carrying an enforceable allow, deny, contain, quarantine, require, remove, or transform decision at the closest reliable control point to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 在最近可靠控制点执行允许、拒绝、遏制、隔离、强制、移除或转换决策 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-4.4-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "4.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Require every connector carrying intended connectivity, trust zone, route, protocol, identity, management path, traffic decision, and observed outcome to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 预期连接、信任区、路由、协议、身份、管理路径、流量决策和观察结果 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-4.4-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "4.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Apply default-deny or least-exposure ingress and, where risk supports it, egress rules at host, workload, security-group or virtual-firewall layers.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“在主机、工作负载、安全组或虚拟防火墙层做默认拒绝或最小暴露，按风险控制出站；策略从服务责任和流向生成，集中变更，保留破窗，并把监听服务与允许源/端口对账。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-4.4-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "4.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-4.4-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "4.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-4.4-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "4.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-4.4-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "4.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the versioned secure-configuration authority and exception register and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在版本化安全配置权威库与例外台账中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-4.4-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "4.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Implement the explicit state machine observe → evaluate → decide → enforce → verify outcome → rollback/close; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-4.4-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "4.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Implement the explicit state machine requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-4.4-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "4.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-4.4-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "4.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-4.4-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "4.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-4.4-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "4.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-4.4-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "4.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in role-specific secure baselines and effective configurations for endpoints, servers, mobile, cloud, network, software, and administrative paths; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 终端、服务器、移动、云、网络、软件和管理路径的角色化安全基线与实际配置 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-4.4-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "4.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for observe → evaluate → decide → enforce → verify outcome → rollback/close; alert before each deadline becomes overdue.",
          "zh": "为“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-4.4-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "4.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; alert before each deadline becomes overdue.",
          "zh": "为“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-4.4-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "4.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “Platform services and clustered control traffic need documented rules, not blanket any-to-any.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“平台服务和集群控制流需明确规则，不能一条全放。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-4.4-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "4.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-4.4-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "4.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-4.4-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "4.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-4.4-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "4.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat unsupported settings, local overrides, inherited cloud policy, vendor defaults, emergency access, safety constraints, drift, and rollback as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 不支持的设置、本地覆盖、继承云策略、厂商默认值、紧急访问、安全约束、漂移和回滚 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-4.4-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "4.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Treat audit-only mode, unsupported platforms, local overrides, race conditions, cached state, alternate paths, fail-open behavior, and emergency bypass as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 仅审计模式、不支持平台、本地覆盖、竞态、缓存状态、替代路径、故障开放和紧急绕过 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-4.4-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "4.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Treat IPv6, overlays, east-west paths, remote and roaming devices, direct egress, alternate resolvers, QUIC, asymmetric routes, provider abstraction, and emergency consoles as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 IPv6、覆盖网络、东西向路径、远程与漫游设备、直接出口、替代解析器、QUIC、非对称路由、提供商抽象和紧急控制台 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-4.4-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "4.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “From allowed and disallowed source zones, test required ports, unexpected listeners, IPv4/IPv6, overlay and management paths.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“从允许与不允许源区测试必需端口、意外监听、IPv4/IPv6、Overlay 和管理路径；检查所有合格服务器的有效规则和强制状态，验证停 Agent 或本地加规则能告警并修复，且不会锁死恢复。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-4.4-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "4.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-4.4-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "4.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 9 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、9 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-4.4-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "4.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-4.4-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "4.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the versioned secure-configuration authority and exception register plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以版本化安全配置权威库与例外台账和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-4.4-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "4.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Publish eligible, enforcing, audit-only, failed, bypassed, excepted, rolled-back, and outcome-verified populations with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 适用、已执行、仅审计、失败、被绕过、例外、已回滚和结果已验证总体，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-4.4-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "4.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Publish known, unknown, allowed, denied, shadow, bypassed, asymmetric, stale-rule, exception, and unobserved paths with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已知、未知、允许、拒绝、影子、绕过、非对称、陈旧规则、例外和未观测路径，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-4.4-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "4.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-4.4-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "4.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-4.4-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "4.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-4.4-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "4.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-4.4-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "4.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the versioned secure-configuration authority and exception register; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护版本化安全配置权威库与例外台账的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-4.4-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "4.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Restrict authority to change observe → evaluate → decide → enforce → verify outcome → rollback/close; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-4.4-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "4.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Restrict authority to change requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-4.4-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "4.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-4.4-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "4.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-4.4-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "4.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-4.4-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "4.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-4.4-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "4.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise approved business behavior, a prohibited setting or service, policy tampering, failed rollout, drift recurrence, and tested rollback through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 获批业务行为、禁止设置或服务、策略篡改、发布失败、漂移复发和已测试回滚，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-4.4-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "4.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Run the positive control an approved business action that completes through the enforced path; exercise negative, stale, duplicate, bypass, and outage controls including a prohibited action, alternate path, local override, stale policy, control outage, emergency bypass, and rollback failure.",
          "zh": "运行正向控制“通过受控路径完成的一项获批业务动作”，并执行包含“禁止动作、替代路径、本地覆盖、陈旧策略、控制中断、紧急绕过和回滚失败”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-4.4-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "4.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Run the positive control an approved flow over the required secure management or business path; exercise negative, stale, duplicate, bypass, and outage controls including an unapproved route, protocol downgrade, direct egress, alternate DNS/QUIC path, segmentation bypass, AAA loss, stale rule, and rollback failure.",
          "zh": "运行正向控制“通过规定安全管理或业务路径的一项获批流量”，并执行包含“未批准路由、协议降级、直接出口、替代 DNS/QUIC 路径、分段绕过、AAA 丢失、陈旧规则和回滚失败”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-4.4-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "4.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-4.4-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "4.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-4.4-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "4.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-4.4-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "4.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-4.4-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "4.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever benchmarks, golden images, configuration management, IaC, MDM, cloud policy, network controllers, drift scans, and change records change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 基准、黄金镜像、配置管理、IaC、MDM、云策略、网络控制器、漂移扫描和变更记录 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-4.4-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "4.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Use eligible, enforcing, audit-only, failed, bypassed, excepted, rolled-back, and outcome-verified populations to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 适用、已执行、仅审计、失败、被绕过、例外、已回滚和结果已验证总体 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-4.4-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "4.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Use known, unknown, allowed, denied, shadow, bypassed, asymmetric, stale-rule, exception, and unobserved paths to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已知、未知、允许、拒绝、影子、绕过、非对称、陈旧规则、例外和未观测路径 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "4.5",
      "control": 4,
      "title_en": "Implement and Manage a Firewall on End-User Devices",
      "title_zh": "终端主机防火墙",
      "first_ig": 1,
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Devices",
      "security_function": "Protect",
      "patterns": [
        "enforcement",
        "network"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "1.1",
          "2.1",
          "4.1"
        ],
        "variables": [
          "GV1",
          "GV3",
          "GV5",
          "M1",
          "M2",
          "M3",
          "M4"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "Cover managed desktops, laptops and other end-user devices on corporate, home, public, VPN and disconnected networks, for both IP families and every network profile.",
          "build": "Centrally enforce host firewall profiles, block local user override, minimize inbound exceptions by application, source and profile, and keep outbound controls proportional to the threat model.",
          "proof": "Probe a representative device from trusted, guest and remote networks over IPv4/IPv6, verify allowed business functions and denied unexpected ports, then disable the firewall or change profile to test detection.",
          "boundary": "Developer servers, peer collaboration, assistive technology and support tools need narrow time-bound rules."
        },
        "zh": {
          "scope": "覆盖受管台式机、笔记本和其他终端在办公、家庭、公共、VPN 与离线网络上的 IPv4/IPv6 和全部网络 Profile。",
          "build": "集中强制各 Profile 的主机防火墙，阻止本地用户改写，按应用、来源与 Profile 收窄入站例外；出站控制按威胁模型决定。",
          "proof": "从可信、访客和远程网络经 IPv4/IPv6 探测代表设备，验证业务通、意外端口拒绝；再停防火墙或切 Profile，检查发现。",
          "boundary": "开发服务、协作、辅助技术和支持工具要有窄且限时规则。"
        }
      },
      "category_counts": {
        "outcome": 7,
        "scope": 7,
        "ownership": 7,
        "data": 7,
        "integration": 7,
        "control": 7,
        "timing": 7,
        "exception": 7,
        "evidence": 7,
        "security": 7,
        "testing": 7,
        "operations": 7
      },
      "requirement_count": 84,
      "requirements": [
        {
          "code": "CIS-4.5-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "4.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Implement and Manage a Firewall on End-User Devices; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“终端主机防火墙”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-4.5-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "4.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 4.5, official Asset Class Devices, Security Function Protect, and IG1 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 4.5、官方资产类别“设备”、安全功能“保护”和首次出现的 IG1，并保存来源抓取日期。"
        },
        {
          "code": "CIS-4.5-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "4.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Cover managed desktops, laptops and other end-user devices on corporate, home, public, VPN and disconnected networks, for both IP families and every network profile.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“覆盖受管台式机、笔记本和其他终端在办公、家庭、公共、VPN 与离线网络上的 IPv4/IPv6 和全部网络 Profile。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-4.5-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "4.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-4.5-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "4.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Implement and Manage a Firewall on End-User Devices to its operating object—role-specific secure baselines and effective configurations for endpoints, servers, mobile, cloud, network, software, and administrative paths—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“终端主机防火墙”连接到其运营对象——终端、服务器、移动、云、网络、软件和管理路径的角色化安全基线与实际配置——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-4.5-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "4.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "For Implement and Manage a Firewall on End-User Devices, express success as an observable decision over an enforceable allow, deny, contain, quarantine, require, remove, or transform decision at the closest reliable control point; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“终端主机防火墙”，以 在最近可靠控制点执行允许、拒绝、遏制、隔离、强制、移除或转换决策 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-4.5-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "4.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "For Implement and Manage a Firewall on End-User Devices, express success as an observable decision over intended connectivity, trust zone, route, protocol, identity, management path, traffic decision, and observed outcome; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“终端主机防火墙”，以 预期连接、信任区、路由、协议、身份、管理路径、流量决策和观察结果 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-4.5-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "4.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-4.5-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "4.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-4.5-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "4.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-4.5-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "4.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-4.5-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "4.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across unsupported settings, local overrides, inherited cloud policy, vendor defaults, emergency access, safety constraints, drift, and rollback; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 不支持的设置、本地覆盖、继承云策略、厂商默认值、紧急访问、安全约束、漂移和回滚 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-4.5-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "4.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Include audit-only mode, unsupported platforms, local overrides, race conditions, cached state, alternate paths, fail-open behavior, and emergency bypass in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 仅审计模式、不支持平台、本地覆盖、竞态、缓存状态、替代路径、故障开放和紧急绕过 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-4.5-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "4.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Include IPv6, overlays, east-west paths, remote and roaming devices, direct egress, alternate resolvers, QUIC, asymmetric routes, provider abstraction, and emergency consoles in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 IPv6、覆盖网络、东西向路径、远程与漫游设备、直接出口、替代解析器、QUIC、非对称路由、提供商抽象和紧急控制台 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-4.5-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "4.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-4.5-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "4.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-4.5-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "4.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-4.5-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "4.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-4.5-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "4.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind platform and application owners, network engineering, security architecture, change management, and service owners to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 平台与应用责任人、网络工程、安全架构、变更管理和服务责任人 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-4.5-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "4.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Name who may transition observe → evaluate → decide → enforce → verify outcome → rollback/close, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-4.5-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "4.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Name who may transition requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-4.5-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "4.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-4.5-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "4.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-4.5-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "4.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV1, GV3, GV5, M1, M2, M3, M4) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV1, GV3, GV5, M1, M2, M3, M4）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-4.5-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "4.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-4.5-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "4.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the versioned secure-configuration authority and exception register as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把版本化安全配置权威库与例外台账作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-4.5-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "4.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle observe → evaluate → decide → enforce → verify outcome → rollback/close.",
          "zh": "对生命周期“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-4.5-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "4.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired.",
          "zh": "对生命周期“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-4.5-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "4.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 1.1, Safeguard 2.1, Safeguard 4.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 1.1、Safeguard 2.1、Safeguard 4.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-4.5-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "4.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-4.5-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "4.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-4.5-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "4.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-4.5-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "4.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile benchmarks, golden images, configuration management, IaC, MDM, cloud policy, network controllers, drift scans, and change records and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 基准、黄金镜像、配置管理、IaC、MDM、云策略、网络控制器、漂移扫描和变更记录，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-4.5-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "4.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Require every connector carrying an enforceable allow, deny, contain, quarantine, require, remove, or transform decision at the closest reliable control point to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 在最近可靠控制点执行允许、拒绝、遏制、隔离、强制、移除或转换决策 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-4.5-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "4.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Require every connector carrying intended connectivity, trust zone, route, protocol, identity, management path, traffic decision, and observed outcome to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 预期连接、信任区、路由、协议、身份、管理路径、流量决策和观察结果 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-4.5-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "4.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Centrally enforce host firewall profiles, block local user override, minimize inbound exceptions by application, source and profile, and keep outbound controls proportional to the threat model.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“集中强制各 Profile 的主机防火墙，阻止本地用户改写，按应用、来源与 Profile 收窄入站例外；出站控制按威胁模型决定。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-4.5-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "4.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-4.5-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "4.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-4.5-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "4.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-4.5-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "4.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the versioned secure-configuration authority and exception register and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在版本化安全配置权威库与例外台账中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-4.5-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "4.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Implement the explicit state machine observe → evaluate → decide → enforce → verify outcome → rollback/close; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-4.5-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "4.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Implement the explicit state machine requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-4.5-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "4.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-4.5-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "4.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-4.5-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "4.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-4.5-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "4.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-4.5-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "4.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in role-specific secure baselines and effective configurations for endpoints, servers, mobile, cloud, network, software, and administrative paths; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 终端、服务器、移动、云、网络、软件和管理路径的角色化安全基线与实际配置 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-4.5-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "4.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for observe → evaluate → decide → enforce → verify outcome → rollback/close; alert before each deadline becomes overdue.",
          "zh": "为“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-4.5-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "4.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; alert before each deadline becomes overdue.",
          "zh": "为“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-4.5-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "4.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “Developer servers, peer collaboration, assistive technology and support tools need narrow time-bound rules.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“开发服务、协作、辅助技术和支持工具要有窄且限时规则。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-4.5-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "4.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-4.5-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "4.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-4.5-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "4.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-4.5-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "4.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat unsupported settings, local overrides, inherited cloud policy, vendor defaults, emergency access, safety constraints, drift, and rollback as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 不支持的设置、本地覆盖、继承云策略、厂商默认值、紧急访问、安全约束、漂移和回滚 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-4.5-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "4.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Treat audit-only mode, unsupported platforms, local overrides, race conditions, cached state, alternate paths, fail-open behavior, and emergency bypass as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 仅审计模式、不支持平台、本地覆盖、竞态、缓存状态、替代路径、故障开放和紧急绕过 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-4.5-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "4.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Treat IPv6, overlays, east-west paths, remote and roaming devices, direct egress, alternate resolvers, QUIC, asymmetric routes, provider abstraction, and emergency consoles as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 IPv6、覆盖网络、东西向路径、远程与漫游设备、直接出口、替代解析器、QUIC、非对称路由、提供商抽象和紧急控制台 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-4.5-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "4.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Probe a representative device from trusted, guest and remote networks over IPv4/IPv6, verify allowed business functions and denied unexpected ports, then disable the firewall or change profile to test detection.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“从可信、访客和远程网络经 IPv4/IPv6 探测代表设备，验证业务通、意外端口拒绝；再停防火墙或切 Profile，检查发现。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-4.5-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "4.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-4.5-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "4.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 7 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、7 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-4.5-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "4.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-4.5-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "4.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the versioned secure-configuration authority and exception register plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以版本化安全配置权威库与例外台账和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-4.5-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "4.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Publish eligible, enforcing, audit-only, failed, bypassed, excepted, rolled-back, and outcome-verified populations with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 适用、已执行、仅审计、失败、被绕过、例外、已回滚和结果已验证总体，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-4.5-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "4.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Publish known, unknown, allowed, denied, shadow, bypassed, asymmetric, stale-rule, exception, and unobserved paths with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已知、未知、允许、拒绝、影子、绕过、非对称、陈旧规则、例外和未观测路径，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-4.5-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "4.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-4.5-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "4.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-4.5-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "4.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-4.5-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "4.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-4.5-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "4.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the versioned secure-configuration authority and exception register; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护版本化安全配置权威库与例外台账的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-4.5-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "4.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Restrict authority to change observe → evaluate → decide → enforce → verify outcome → rollback/close; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-4.5-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "4.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Restrict authority to change requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-4.5-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "4.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-4.5-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "4.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-4.5-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "4.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-4.5-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "4.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-4.5-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "4.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise approved business behavior, a prohibited setting or service, policy tampering, failed rollout, drift recurrence, and tested rollback through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 获批业务行为、禁止设置或服务、策略篡改、发布失败、漂移复发和已测试回滚，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-4.5-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "4.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Run the positive control an approved business action that completes through the enforced path; exercise negative, stale, duplicate, bypass, and outage controls including a prohibited action, alternate path, local override, stale policy, control outage, emergency bypass, and rollback failure.",
          "zh": "运行正向控制“通过受控路径完成的一项获批业务动作”，并执行包含“禁止动作、替代路径、本地覆盖、陈旧策略、控制中断、紧急绕过和回滚失败”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-4.5-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "4.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Run the positive control an approved flow over the required secure management or business path; exercise negative, stale, duplicate, bypass, and outage controls including an unapproved route, protocol downgrade, direct egress, alternate DNS/QUIC path, segmentation bypass, AAA loss, stale rule, and rollback failure.",
          "zh": "运行正向控制“通过规定安全管理或业务路径的一项获批流量”，并执行包含“未批准路由、协议降级、直接出口、替代 DNS/QUIC 路径、分段绕过、AAA 丢失、陈旧规则和回滚失败”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-4.5-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "4.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-4.5-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "4.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-4.5-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "4.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-4.5-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "4.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-4.5-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "4.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever benchmarks, golden images, configuration management, IaC, MDM, cloud policy, network controllers, drift scans, and change records change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 基准、黄金镜像、配置管理、IaC、MDM、云策略、网络控制器、漂移扫描和变更记录 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-4.5-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "4.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Use eligible, enforcing, audit-only, failed, bypassed, excepted, rolled-back, and outcome-verified populations to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 适用、已执行、仅审计、失败、被绕过、例外、已回滚和结果已验证总体 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-4.5-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "4.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Use known, unknown, allowed, denied, shadow, bypassed, asymmetric, stale-rule, exception, and unobserved paths to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已知、未知、允许、拒绝、影子、绕过、非对称、陈旧规则、例外和未观测路径 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "4.6",
      "control": 4,
      "title_en": "Securely Manage Enterprise Assets and Software",
      "title_zh": "安全管理资产与软件",
      "first_ig": 1,
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Devices",
      "security_function": "Protect",
      "patterns": [
        "enforcement",
        "software_dev"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "1.1",
          "2.1",
          "4.1"
        ],
        "variables": [
          "GV1",
          "GV3",
          "GV5",
          "M1",
          "M2",
          "M3",
          "M4",
          "M5"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "Management scope includes local and remote administration of devices, operating systems, applications, cloud/SaaS, hypervisors, containers and infrastructure-as-code.",
          "build": "Route administration through dedicated trusted paths using SSH, HTTPS or equivalent authenticated encryption, central identity/MFA, least privilege and version-controlled changes.",
          "proof": "Attempt management from an unauthorized network and identity, try insecure protocol and expired credential paths, then verify denial and alerting.",
          "boundary": "Encryption alone does not make an exposed management plane safe."
        },
        "zh": {
          "scope": "管理范围是通过本地、远程、API 和 IaC 管理设备、OS、应用、云/SaaS、虚拟化与容器；同时覆盖协议、管理面可达性、管理员身份、变更来源、秘密，以及高后果场景的会话记录。",
          "build": "经专用可信路径使用 SSH、HTTPS 或同等认证加密，接入集中身份/MFA 与最小权限；关闭 Telnet/HTTP 和公网上的直接管理，保护 IaC 状态/密钥，分隔生产管理，并记录 API 与交互行为。",
          "proof": "从未授权网络和身份尝试管理，再测试不安全协议和过期凭据，验证拒绝/告警。",
          "boundary": "加密不能让公开暴露的管理面自动安全。"
        }
      },
      "category_counts": {
        "outcome": 7,
        "scope": 7,
        "ownership": 7,
        "data": 7,
        "integration": 7,
        "control": 7,
        "timing": 7,
        "exception": 7,
        "evidence": 7,
        "security": 7,
        "testing": 7,
        "operations": 7
      },
      "requirement_count": 84,
      "requirements": [
        {
          "code": "CIS-4.6-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "4.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Securely Manage Enterprise Assets and Software; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“安全管理资产与软件”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-4.6-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "4.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 4.6, official Asset Class Devices, Security Function Protect, and IG1 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 4.6、官方资产类别“设备”、安全功能“保护”和首次出现的 IG1，并保存来源抓取日期。"
        },
        {
          "code": "CIS-4.6-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "4.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Management scope includes local and remote administration of devices, operating systems, applications, cloud/SaaS, hypervisors, containers and infrastructure-as-code.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“管理范围是通过本地、远程、API 和 IaC 管理设备、OS、应用、云/SaaS、虚拟化与容器；同时覆盖协议、管理面可达性、管理员身份、变更来源、秘密，以及高后果场景的会话记录。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-4.6-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "4.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-4.6-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "4.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Securely Manage Enterprise Assets and Software to its operating object—role-specific secure baselines and effective configurations for endpoints, servers, mobile, cloud, network, software, and administrative paths—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“安全管理资产与软件”连接到其运营对象——终端、服务器、移动、云、网络、软件和管理路径的角色化安全基线与实际配置——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-4.6-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "4.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "For Securely Manage Enterprise Assets and Software, express success as an observable decision over an enforceable allow, deny, contain, quarantine, require, remove, or transform decision at the closest reliable control point; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“安全管理资产与软件”，以 在最近可靠控制点执行允许、拒绝、遏制、隔离、强制、移除或转换决策 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-4.6-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "4.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "For Securely Manage Enterprise Assets and Software, express success as an observable decision over source-to-production software identity, design invariant, component trust, build provenance, test result, deployment state, runtime outcome, and vulnerability response; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“安全管理资产与软件”，以 从源码到生产的软件身份、设计不变量、组件信任、构建来源、测试结果、部署状态、运行结果和漏洞响应 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-4.6-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "4.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-4.6-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "4.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-4.6-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "4.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-4.6-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "4.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-4.6-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "4.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across unsupported settings, local overrides, inherited cloud policy, vendor defaults, emergency access, safety constraints, drift, and rollback; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 不支持的设置、本地覆盖、继承云策略、厂商默认值、紧急访问、安全约束、漂移和回滚 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-4.6-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "4.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Include audit-only mode, unsupported platforms, local overrides, race conditions, cached state, alternate paths, fail-open behavior, and emergency bypass in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 仅审计模式、不支持平台、本地覆盖、竞态、缓存状态、替代路径、故障开放和紧急绕过 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-4.6-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "4.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Include generated and copied code, forks, vendoring, transitive dependencies, mutable tags, build plugins, feature flags, tenant logic, secrets, emergency release, and provider components in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 生成与复制代码、分叉、vendoring、传递依赖、可变标签、构建插件、功能开关、租户逻辑、秘密、紧急发布和提供商组件 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-4.6-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "4.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-4.6-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "4.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-4.6-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "4.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-4.6-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "4.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-4.6-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "4.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind platform and application owners, network engineering, security architecture, change management, and service owners to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 平台与应用责任人、网络工程、安全架构、变更管理和服务责任人 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-4.6-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "4.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Name who may transition observe → evaluate → decide → enforce → verify outcome → rollback/close, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-4.6-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "4.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Name who may transition designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-4.6-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "4.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-4.6-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "4.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-4.6-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "4.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV1, GV3, GV5, M1, M2, M3, M4, M5) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV1, GV3, GV5, M1, M2, M3, M4, M5）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-4.6-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "4.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-4.6-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "4.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the versioned secure-configuration authority and exception register as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把版本化安全配置权威库与例外台账作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-4.6-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "4.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle observe → evaluate → decide → enforce → verify outcome → rollback/close.",
          "zh": "对生命周期“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-4.6-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "4.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired.",
          "zh": "对生命周期“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-4.6-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "4.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 1.1, Safeguard 2.1, Safeguard 4.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 1.1、Safeguard 2.1、Safeguard 4.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-4.6-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "4.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-4.6-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "4.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-4.6-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "4.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-4.6-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "4.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile benchmarks, golden images, configuration management, IaC, MDM, cloud policy, network controllers, drift scans, and change records and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 基准、黄金镜像、配置管理、IaC、MDM、云策略、网络控制器、漂移扫描和变更记录，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-4.6-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "4.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Require every connector carrying an enforceable allow, deny, contain, quarantine, require, remove, or transform decision at the closest reliable control point to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 在最近可靠控制点执行允许、拒绝、遏制、隔离、强制、移除或转换决策 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-4.6-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "4.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Require every connector carrying source-to-production software identity, design invariant, component trust, build provenance, test result, deployment state, runtime outcome, and vulnerability response to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 从源码到生产的软件身份、设计不变量、组件信任、构建来源、测试结果、部署状态、运行结果和漏洞响应 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-4.6-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "4.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Route administration through dedicated trusted paths using SSH, HTTPS or equivalent authenticated encryption, central identity/MFA, least privilege and version-controlled changes.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“经专用可信路径使用 SSH、HTTPS 或同等认证加密，接入集中身份/MFA 与最小权限；关闭 Telnet/HTTP 和公网上的直接管理，保护 IaC 状态/密钥，分隔生产管理，并记录 API 与交互行为。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-4.6-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "4.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-4.6-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "4.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-4.6-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "4.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-4.6-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "4.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the versioned secure-configuration authority and exception register and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在版本化安全配置权威库与例外台账中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-4.6-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "4.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Implement the explicit state machine observe → evaluate → decide → enforce → verify outcome → rollback/close; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-4.6-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "4.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Implement the explicit state machine designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-4.6-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "4.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-4.6-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "4.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-4.6-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "4.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-4.6-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "4.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-4.6-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "4.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in role-specific secure baselines and effective configurations for endpoints, servers, mobile, cloud, network, software, and administrative paths; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 终端、服务器、移动、云、网络、软件和管理路径的角色化安全基线与实际配置 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-4.6-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "4.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for observe → evaluate → decide → enforce → verify outcome → rollback/close; alert before each deadline becomes overdue.",
          "zh": "为“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-4.6-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "4.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; alert before each deadline becomes overdue.",
          "zh": "为“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-4.6-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "4.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “Encryption alone does not make an exposed management plane safe.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“加密不能让公开暴露的管理面自动安全。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-4.6-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "4.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-4.6-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "4.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-4.6-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "4.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-4.6-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "4.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat unsupported settings, local overrides, inherited cloud policy, vendor defaults, emergency access, safety constraints, drift, and rollback as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 不支持的设置、本地覆盖、继承云策略、厂商默认值、紧急访问、安全约束、漂移和回滚 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-4.6-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "4.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Treat audit-only mode, unsupported platforms, local overrides, race conditions, cached state, alternate paths, fail-open behavior, and emergency bypass as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 仅审计模式、不支持平台、本地覆盖、竞态、缓存状态、替代路径、故障开放和紧急绕过 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-4.6-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "4.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Treat generated and copied code, forks, vendoring, transitive dependencies, mutable tags, build plugins, feature flags, tenant logic, secrets, emergency release, and provider components as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 生成与复制代码、分叉、vendoring、传递依赖、可变标签、构建插件、功能开关、租户逻辑、秘密、紧急发布和提供商组件 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-4.6-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "4.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Attempt management from an unauthorized network and identity, try insecure protocol and expired credential paths, then verify denial and alerting.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“从未授权网络和身份尝试管理，再测试不安全协议和过期凭据，验证拒绝/告警。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-4.6-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "4.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-4.6-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "4.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 8 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、8 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-4.6-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "4.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-4.6-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "4.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the versioned secure-configuration authority and exception register plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以版本化安全配置权威库与例外台账和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-4.6-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "4.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Publish eligible, enforcing, audit-only, failed, bypassed, excepted, rolled-back, and outcome-verified populations with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 适用、已执行、仅审计、失败、被绕过、例外、已回滚和结果已验证总体，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-4.6-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "4.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Publish reviewed, unreviewed, reproducible, provenance-bound, vulnerable, test-failed, exception, deployed-unverified, drifted, rolled-back, and regression-protected releases with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已评审、未评审、可复现、来源绑定、存在漏洞、测试失败、例外、已部署未验证、漂移、已回滚和受回归保护发布物，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-4.6-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "4.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-4.6-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "4.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-4.6-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "4.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-4.6-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "4.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-4.6-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "4.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the versioned secure-configuration authority and exception register; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护版本化安全配置权威库与例外台账的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-4.6-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "4.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Restrict authority to change observe → evaluate → decide → enforce → verify outcome → rollback/close; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-4.6-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "4.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Restrict authority to change designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-4.6-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "4.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-4.6-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "4.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-4.6-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "4.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-4.6-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "4.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-4.6-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "4.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise approved business behavior, a prohibited setting or service, policy tampering, failed rollout, drift recurrence, and tested rollback through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 获批业务行为、禁止设置或服务、策略篡改、发布失败、漂移复发和已测试回滚，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-4.6-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "4.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Run the positive control an approved business action that completes through the enforced path; exercise negative, stale, duplicate, bypass, and outage controls including a prohibited action, alternate path, local override, stale policy, control outage, emergency bypass, and rollback failure.",
          "zh": "运行正向控制“通过受控路径完成的一项获批业务动作”，并执行包含“禁止动作、替代路径、本地覆盖、陈旧策略、控制中断、紧急绕过和回滚失败”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-4.6-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "4.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Run the positive control a trusted build that preserves the security invariant through deployment and runtime; exercise negative, stale, duplicate, bypass, and outage controls including a substituted dependency, unreviewed change, poisoned build input, failed security test, bypass path, vulnerable release, rollback, and regression.",
          "zh": "运行正向控制“一个把安全不变量贯穿部署与运行的可信构建”，并执行包含“依赖替换、未评审变更、构建输入污染、安全测试失败、绕过路径、漏洞发布、回滚和回归”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-4.6-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "4.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-4.6-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "4.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-4.6-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "4.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-4.6-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "4.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-4.6-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "4.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever benchmarks, golden images, configuration management, IaC, MDM, cloud policy, network controllers, drift scans, and change records change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 基准、黄金镜像、配置管理、IaC、MDM、云策略、网络控制器、漂移扫描和变更记录 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-4.6-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "4.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Use eligible, enforcing, audit-only, failed, bypassed, excepted, rolled-back, and outcome-verified populations to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 适用、已执行、仅审计、失败、被绕过、例外、已回滚和结果已验证总体 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-4.6-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "4.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Use reviewed, unreviewed, reproducible, provenance-bound, vulnerable, test-failed, exception, deployed-unverified, drifted, rolled-back, and regression-protected releases to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已评审、未评审、可复现、来源绑定、存在漏洞、测试失败、例外、已部署未验证、漂移、已回滚和受回归保护发布物 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "4.7",
      "control": 4,
      "title_en": "Manage Default Accounts on Enterprise Assets and Software",
      "title_zh": "默认账户",
      "first_ig": 1,
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Users",
      "security_function": "Protect",
      "patterns": [
        "enforcement",
        "identity",
        "software_dev"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "1.1",
          "2.1",
          "5.2"
        ],
        "variables": [
          "GV1",
          "GV5",
          "GV20",
          "M1",
          "M2",
          "M3",
          "M4",
          "M5",
          "M6"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "Include factory, built-in, sample, guest, root, administrator, maintenance, cloud break-glass and vendor-support accounts across assets and software.",
          "build": "Disable or render default accounts unusable; where impossible, rotate to unique managed secrets, restrict sources and roles, monitor use and assign an accountable custodian.",
          "proof": "Attempt authentication with published defaults and enumerate enabled built-in identities on representative systems.",
          "boundary": "The CAS formula lacks parentheses and can overstate the result."
        },
        "zh": {
          "scope": "覆盖设备与软件里的出厂、内置、示例、Guest、Root、Administrator、维护、云破窗和厂商支持账户。",
          "build": "能禁则禁或使其不可用；不能禁则换为唯一受管秘密，限制来源/角色，监测使用并指定保管人。",
          "proof": "在代表系统用公开默认凭据尝试登录并枚举已启用内置身份，测试安装、升级和重置；每个无法禁用的账户都要对到唯一秘密、限制和责任人。",
          "boundary": "CAS 公式缺括号，会高估结果。"
        }
      },
      "category_counts": {
        "outcome": 8,
        "scope": 8,
        "ownership": 8,
        "data": 8,
        "integration": 8,
        "control": 8,
        "timing": 8,
        "exception": 8,
        "evidence": 8,
        "security": 8,
        "testing": 8,
        "operations": 8
      },
      "requirement_count": 96,
      "requirements": [
        {
          "code": "CIS-4.7-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "4.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Manage Default Accounts on Enterprise Assets and Software; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“默认账户”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-4.7-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "4.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 4.7, official Asset Class Users, Security Function Protect, and IG1 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 4.7、官方资产类别“用户与身份”、安全功能“保护”和首次出现的 IG1，并保存来源抓取日期。"
        },
        {
          "code": "CIS-4.7-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "4.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Include factory, built-in, sample, guest, root, administrator, maintenance, cloud break-glass and vendor-support accounts across assets and software.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“覆盖设备与软件里的出厂、内置、示例、Guest、Root、Administrator、维护、云破窗和厂商支持账户。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-4.7-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "4.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-4.7-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "4.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Manage Default Accounts on Enterprise Assets and Software to its operating object—role-specific secure baselines and effective configurations for endpoints, servers, mobile, cloud, network, software, and administrative paths—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“默认账户”连接到其运营对象——终端、服务器、移动、云、网络、软件和管理路径的角色化安全基线与实际配置——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-4.7-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "4.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "For Manage Default Accounts on Enterprise Assets and Software, express success as an observable decision over an enforceable allow, deny, contain, quarantine, require, remove, or transform decision at the closest reliable control point; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“默认账户”，以 在最近可靠控制点执行允许、拒绝、遏制、隔离、强制、移除或转换决策 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-4.7-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "4.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "For Manage Default Accounts on Enterprise Assets and Software, express success as an observable decision over effective identity, authentication, authorization, privilege, session, and revocation state across every access path; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“默认账户”，以 所有访问路径上的实际身份、认证、授权、权限、会话和撤销状态 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-4.7-OUT-08",
          "local_code": "OUT-08",
          "display_code": "O08",
          "safeguard_id": "4.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "For Manage Default Accounts on Enterprise Assets and Software, express success as an observable decision over source-to-production software identity, design invariant, component trust, build provenance, test result, deployment state, runtime outcome, and vulnerability response; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“默认账户”，以 从源码到生产的软件身份、设计不变量、组件信任、构建来源、测试结果、部署状态、运行结果和漏洞响应 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-4.7-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "4.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-4.7-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "4.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-4.7-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "4.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-4.7-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "4.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-4.7-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "4.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across unsupported settings, local overrides, inherited cloud policy, vendor defaults, emergency access, safety constraints, drift, and rollback; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 不支持的设置、本地覆盖、继承云策略、厂商默认值、紧急访问、安全约束、漂移和回滚 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-4.7-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "4.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Include audit-only mode, unsupported platforms, local overrides, race conditions, cached state, alternate paths, fail-open behavior, and emergency bypass in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 仅审计模式、不支持平台、本地覆盖、竞态、缓存状态、替代路径、故障开放和紧急绕过 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-4.7-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "4.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Include shared and service identities, nested groups, direct grants, cached sessions, federation gaps, recovery channels, API keys, emergency access, and provider support in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 共享与服务身份、嵌套组、直接授权、缓存会话、联邦缺口、恢复通道、API 密钥、紧急访问和提供商支持 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-4.7-SCP-08",
          "local_code": "SCP-08",
          "display_code": "P08",
          "safeguard_id": "4.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Include generated and copied code, forks, vendoring, transitive dependencies, mutable tags, build plugins, feature flags, tenant logic, secrets, emergency release, and provider components in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 生成与复制代码、分叉、vendoring、传递依赖、可变标签、构建插件、功能开关、租户逻辑、秘密、紧急发布和提供商组件 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-4.7-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "4.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-4.7-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "4.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-4.7-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "4.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-4.7-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "4.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-4.7-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "4.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind platform and application owners, network engineering, security architecture, change management, and service owners to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 平台与应用责任人、网络工程、安全架构、变更管理和服务责任人 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-4.7-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "4.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Name who may transition observe → evaluate → decide → enforce → verify outcome → rollback/close, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-4.7-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "4.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Name who may transition requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-4.7-OWN-08",
          "local_code": "OWN-08",
          "display_code": "W08",
          "safeguard_id": "4.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Name who may transition designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-4.7-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "4.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-4.7-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "4.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-4.7-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "4.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV1, GV5, GV20, M1, M2, M3, M4, M5, M6) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV1, GV5, GV20, M1, M2, M3, M4, M5, M6）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-4.7-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "4.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-4.7-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "4.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the versioned secure-configuration authority and exception register as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把版本化安全配置权威库与例外台账作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-4.7-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "4.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle observe → evaluate → decide → enforce → verify outcome → rollback/close.",
          "zh": "对生命周期“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-4.7-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "4.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated.",
          "zh": "对生命周期“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-4.7-DAT-08",
          "local_code": "DAT-08",
          "display_code": "D08",
          "safeguard_id": "4.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired.",
          "zh": "对生命周期“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-4.7-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "4.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 1.1, Safeguard 2.1, Safeguard 5.2; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 1.1、Safeguard 2.1、Safeguard 5.2 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-4.7-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "4.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-4.7-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "4.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-4.7-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "4.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-4.7-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "4.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile benchmarks, golden images, configuration management, IaC, MDM, cloud policy, network controllers, drift scans, and change records and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 基准、黄金镜像、配置管理、IaC、MDM、云策略、网络控制器、漂移扫描和变更记录，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-4.7-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "4.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Require every connector carrying an enforceable allow, deny, contain, quarantine, require, remove, or transform decision at the closest reliable control point to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 在最近可靠控制点执行允许、拒绝、遏制、隔离、强制、移除或转换决策 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-4.7-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "4.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Require every connector carrying effective identity, authentication, authorization, privilege, session, and revocation state across every access path to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 所有访问路径上的实际身份、认证、授权、权限、会话和撤销状态 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-4.7-INT-08",
          "local_code": "INT-08",
          "display_code": "I08",
          "safeguard_id": "4.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Require every connector carrying source-to-production software identity, design invariant, component trust, build provenance, test result, deployment state, runtime outcome, and vulnerability response to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 从源码到生产的软件身份、设计不变量、组件信任、构建来源、测试结果、部署状态、运行结果和漏洞响应 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-4.7-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "4.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Disable or render default accounts unusable; where impossible, rotate to unique managed secrets, restrict sources and roles, monitor use and assign an accountable custodian.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“能禁则禁或使其不可用；不能禁则换为唯一受管秘密，限制来源/角色，监测使用并指定保管人。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-4.7-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "4.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-4.7-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "4.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-4.7-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "4.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-4.7-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "4.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the versioned secure-configuration authority and exception register and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在版本化安全配置权威库与例外台账中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-4.7-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "4.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Implement the explicit state machine observe → evaluate → decide → enforce → verify outcome → rollback/close; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-4.7-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "4.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Implement the explicit state machine requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-4.7-CTL-08",
          "local_code": "CTL-08",
          "display_code": "C08",
          "safeguard_id": "4.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Implement the explicit state machine designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-4.7-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "4.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-4.7-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "4.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-4.7-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "4.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-4.7-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "4.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-4.7-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "4.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in role-specific secure baselines and effective configurations for endpoints, servers, mobile, cloud, network, software, and administrative paths; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 终端、服务器、移动、云、网络、软件和管理路径的角色化安全基线与实际配置 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-4.7-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "4.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for observe → evaluate → decide → enforce → verify outcome → rollback/close; alert before each deadline becomes overdue.",
          "zh": "为“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-4.7-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "4.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated; alert before each deadline becomes overdue.",
          "zh": "为“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-4.7-TIM-08",
          "local_code": "TIM-08",
          "display_code": "T08",
          "safeguard_id": "4.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; alert before each deadline becomes overdue.",
          "zh": "为“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-4.7-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "4.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “The CAS formula lacks parentheses and can overstate the result.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“CAS 公式缺括号，会高估结果。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-4.7-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "4.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-4.7-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "4.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-4.7-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "4.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-4.7-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "4.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat unsupported settings, local overrides, inherited cloud policy, vendor defaults, emergency access, safety constraints, drift, and rollback as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 不支持的设置、本地覆盖、继承云策略、厂商默认值、紧急访问、安全约束、漂移和回滚 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-4.7-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "4.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Treat audit-only mode, unsupported platforms, local overrides, race conditions, cached state, alternate paths, fail-open behavior, and emergency bypass as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 仅审计模式、不支持平台、本地覆盖、竞态、缓存状态、替代路径、故障开放和紧急绕过 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-4.7-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "4.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Treat shared and service identities, nested groups, direct grants, cached sessions, federation gaps, recovery channels, API keys, emergency access, and provider support as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 共享与服务身份、嵌套组、直接授权、缓存会话、联邦缺口、恢复通道、API 密钥、紧急访问和提供商支持 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-4.7-EXC-08",
          "local_code": "EXC-08",
          "display_code": "X08",
          "safeguard_id": "4.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Treat generated and copied code, forks, vendoring, transitive dependencies, mutable tags, build plugins, feature flags, tenant logic, secrets, emergency release, and provider components as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 生成与复制代码、分叉、vendoring、传递依赖、可变标签、构建插件、功能开关、租户逻辑、秘密、紧急发布和提供商组件 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-4.7-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "4.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Attempt authentication with published defaults and enumerate enabled built-in identities on representative systems.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“在代表系统用公开默认凭据尝试登录并枚举已启用内置身份，测试安装、升级和重置；每个无法禁用的账户都要对到唯一秘密、限制和责任人。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-4.7-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "4.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-4.7-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "4.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 9 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、9 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-4.7-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "4.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-4.7-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "4.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the versioned secure-configuration authority and exception register plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以版本化安全配置权威库与例外台账和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-4.7-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "4.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Publish eligible, enforcing, audit-only, failed, bypassed, excepted, rolled-back, and outcome-verified populations with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 适用、已执行、仅审计、失败、被绕过、例外、已回滚和结果已验证总体，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-4.7-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "4.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Publish requested, approved, effective, excessive, orphaned, stale, emergency, revoked-but-active, and independently reviewed rights with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 申请、批准、实际、过度、孤儿、陈旧、紧急、已撤销仍活跃及独立复核权限，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-4.7-EVD-08",
          "local_code": "EVD-08",
          "display_code": "E08",
          "safeguard_id": "4.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Publish reviewed, unreviewed, reproducible, provenance-bound, vulnerable, test-failed, exception, deployed-unverified, drifted, rolled-back, and regression-protected releases with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已评审、未评审、可复现、来源绑定、存在漏洞、测试失败、例外、已部署未验证、漂移、已回滚和受回归保护发布物，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-4.7-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "4.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-4.7-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "4.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-4.7-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "4.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-4.7-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "4.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-4.7-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "4.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the versioned secure-configuration authority and exception register; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护版本化安全配置权威库与例外台账的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-4.7-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "4.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Restrict authority to change observe → evaluate → decide → enforce → verify outcome → rollback/close; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-4.7-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "4.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Restrict authority to change requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-4.7-SEC-08",
          "local_code": "SEC-08",
          "display_code": "S08",
          "safeguard_id": "4.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Restrict authority to change designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-4.7-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "4.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-4.7-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "4.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-4.7-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "4.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-4.7-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "4.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-4.7-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "4.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise approved business behavior, a prohibited setting or service, policy tampering, failed rollout, drift recurrence, and tested rollback through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 获批业务行为、禁止设置或服务、策略篡改、发布失败、漂移复发和已测试回滚，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-4.7-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "4.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Run the positive control an approved business action that completes through the enforced path; exercise negative, stale, duplicate, bypass, and outage controls including a prohibited action, alternate path, local override, stale policy, control outage, emergency bypass, and rollback failure.",
          "zh": "运行正向控制“通过受控路径完成的一项获批业务动作”，并执行包含“禁止动作、替代路径、本地覆盖、陈旧策略、控制中断、紧急绕过和回滚失败”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-4.7-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "4.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Run the positive control an authorized identity using the required assurance and least privilege; exercise negative, stale, duplicate, bypass, and outage controls including an unauthorized identity, missing factor, stale session, direct grant, inherited excess, revoked token, and recovery bypass.",
          "zh": "运行正向控制“使用所需保证级别和最小权限的授权身份”，并执行包含“未授权身份、缺失认证因子、陈旧会话、直接授权、继承过权、已撤销令牌和恢复绕过”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-4.7-TST-08",
          "local_code": "TST-08",
          "display_code": "V08",
          "safeguard_id": "4.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Run the positive control a trusted build that preserves the security invariant through deployment and runtime; exercise negative, stale, duplicate, bypass, and outage controls including a substituted dependency, unreviewed change, poisoned build input, failed security test, bypass path, vulnerable release, rollback, and regression.",
          "zh": "运行正向控制“一个把安全不变量贯穿部署与运行的可信构建”，并执行包含“依赖替换、未评审变更、构建输入污染、安全测试失败、绕过路径、漏洞发布、回滚和回归”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-4.7-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "4.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-4.7-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "4.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-4.7-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "4.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-4.7-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "4.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-4.7-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "4.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever benchmarks, golden images, configuration management, IaC, MDM, cloud policy, network controllers, drift scans, and change records change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 基准、黄金镜像、配置管理、IaC、MDM、云策略、网络控制器、漂移扫描和变更记录 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-4.7-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "4.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Use eligible, enforcing, audit-only, failed, bypassed, excepted, rolled-back, and outcome-verified populations to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 适用、已执行、仅审计、失败、被绕过、例外、已回滚和结果已验证总体 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-4.7-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "4.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Use requested, approved, effective, excessive, orphaned, stale, emergency, revoked-but-active, and independently reviewed rights to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 申请、批准、实际、过度、孤儿、陈旧、紧急、已撤销仍活跃及独立复核权限 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-4.7-OPS-08",
          "local_code": "OPS-08",
          "display_code": "R08",
          "safeguard_id": "4.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Use reviewed, unreviewed, reproducible, provenance-bound, vulnerable, test-failed, exception, deployed-unverified, drifted, rolled-back, and regression-protected releases to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已评审、未评审、可复现、来源绑定、存在漏洞、测试失败、例外、已部署未验证、漂移、已回滚和受回归保护发布物 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "4.8",
      "control": 4,
      "title_en": "Uninstall or Disable Unnecessary Services on Enterprise Assets and Software",
      "title_zh": "不必要服务与功能",
      "first_ig": 2,
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Devices",
      "security_function": "Protect",
      "patterns": [
        "enforcement",
        "software_dev"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "1.1",
          "2.1"
        ],
        "variables": [
          "GV1",
          "GV3",
          "GV5",
          "M1",
          "M2",
          "M3",
          "M4",
          "M5",
          "M6"
        ],
        "metric_branches": 2,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "The population includes OS daemons, listeners, application modules, cloud features, management APIs, packages, browser services and container sidecars that are installed or enabled.",
          "build": "Define required services per asset role in the secure baseline, remove packages when practical, otherwise disable and block them, and prevent automatic re-enablement.",
          "proof": "Compare live services and ports to the role baseline, disable a benign test service and verify persistence after restart/update, then start an unapproved listener to test detection and remediation.",
          "boundary": "Socket activation, scheduled tasks, containers and on-demand cloud features may be dormant during a snapshot."
        },
        "zh": {
          "scope": "范围包括 OS Daemon、监听器、应用模块、云功能、管理 API、包、浏览器服务和容器 Sidecar 中已安装或启用的功能。",
          "build": "按资产角色在安全基线中列必需服务，能卸载就移除，否则禁用并阻断，防止自动重启；例外绑定业务依赖，并观察真实监听端口、进程和云/API 配置。",
          "proof": "把实时服务与角色基线对比，禁用无害测试服务并验证重启/更新后仍禁用；再启动未批准监听测试发现和修复。",
          "boundary": "Socket 激活、计划任务、容器与按需云功能在快照时可能休眠。"
        }
      },
      "category_counts": {
        "outcome": 7,
        "scope": 7,
        "ownership": 7,
        "data": 7,
        "integration": 7,
        "control": 7,
        "timing": 7,
        "exception": 7,
        "evidence": 7,
        "security": 7,
        "testing": 7,
        "operations": 7
      },
      "requirement_count": 84,
      "requirements": [
        {
          "code": "CIS-4.8-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "4.8",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Uninstall or Disable Unnecessary Services on Enterprise Assets and Software; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“不必要服务与功能”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-4.8-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "4.8",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 4.8, official Asset Class Devices, Security Function Protect, and IG2 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 4.8、官方资产类别“设备”、安全功能“保护”和首次出现的 IG2，并保存来源抓取日期。"
        },
        {
          "code": "CIS-4.8-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "4.8",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “The population includes OS daemons, listeners, application modules, cloud features, management APIs, packages, browser services and container sidecars that are installed or enabled.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“范围包括 OS Daemon、监听器、应用模块、云功能、管理 API、包、浏览器服务和容器 Sidecar 中已安装或启用的功能。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-4.8-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "4.8",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-4.8-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "4.8",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Uninstall or Disable Unnecessary Services on Enterprise Assets and Software to its operating object—role-specific secure baselines and effective configurations for endpoints, servers, mobile, cloud, network, software, and administrative paths—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“不必要服务与功能”连接到其运营对象——终端、服务器、移动、云、网络、软件和管理路径的角色化安全基线与实际配置——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-4.8-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "4.8",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "For Uninstall or Disable Unnecessary Services on Enterprise Assets and Software, express success as an observable decision over an enforceable allow, deny, contain, quarantine, require, remove, or transform decision at the closest reliable control point; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“不必要服务与功能”，以 在最近可靠控制点执行允许、拒绝、遏制、隔离、强制、移除或转换决策 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-4.8-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "4.8",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "For Uninstall or Disable Unnecessary Services on Enterprise Assets and Software, express success as an observable decision over source-to-production software identity, design invariant, component trust, build provenance, test result, deployment state, runtime outcome, and vulnerability response; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“不必要服务与功能”，以 从源码到生产的软件身份、设计不变量、组件信任、构建来源、测试结果、部署状态、运行结果和漏洞响应 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-4.8-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "4.8",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-4.8-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "4.8",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-4.8-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "4.8",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-4.8-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "4.8",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-4.8-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "4.8",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across unsupported settings, local overrides, inherited cloud policy, vendor defaults, emergency access, safety constraints, drift, and rollback; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 不支持的设置、本地覆盖、继承云策略、厂商默认值、紧急访问、安全约束、漂移和回滚 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-4.8-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "4.8",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Include audit-only mode, unsupported platforms, local overrides, race conditions, cached state, alternate paths, fail-open behavior, and emergency bypass in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 仅审计模式、不支持平台、本地覆盖、竞态、缓存状态、替代路径、故障开放和紧急绕过 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-4.8-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "4.8",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Include generated and copied code, forks, vendoring, transitive dependencies, mutable tags, build plugins, feature flags, tenant logic, secrets, emergency release, and provider components in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 生成与复制代码、分叉、vendoring、传递依赖、可变标签、构建插件、功能开关、租户逻辑、秘密、紧急发布和提供商组件 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-4.8-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "4.8",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-4.8-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "4.8",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-4.8-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "4.8",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-4.8-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "4.8",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-4.8-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "4.8",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind platform and application owners, network engineering, security architecture, change management, and service owners to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 平台与应用责任人、网络工程、安全架构、变更管理和服务责任人 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-4.8-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "4.8",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Name who may transition observe → evaluate → decide → enforce → verify outcome → rollback/close, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-4.8-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "4.8",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Name who may transition designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-4.8-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "4.8",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-4.8-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "4.8",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-4.8-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "4.8",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV1, GV3, GV5, M1, M2, M3, M4, M5, M6) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV1, GV3, GV5, M1, M2, M3, M4, M5, M6）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-4.8-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "4.8",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-4.8-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "4.8",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the versioned secure-configuration authority and exception register as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把版本化安全配置权威库与例外台账作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-4.8-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "4.8",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle observe → evaluate → decide → enforce → verify outcome → rollback/close.",
          "zh": "对生命周期“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-4.8-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "4.8",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired.",
          "zh": "对生命周期“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-4.8-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "4.8",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 1.1, Safeguard 2.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 1.1、Safeguard 2.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-4.8-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "4.8",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-4.8-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "4.8",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-4.8-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "4.8",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-4.8-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "4.8",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile benchmarks, golden images, configuration management, IaC, MDM, cloud policy, network controllers, drift scans, and change records and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 基准、黄金镜像、配置管理、IaC、MDM、云策略、网络控制器、漂移扫描和变更记录，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-4.8-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "4.8",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Require every connector carrying an enforceable allow, deny, contain, quarantine, require, remove, or transform decision at the closest reliable control point to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 在最近可靠控制点执行允许、拒绝、遏制、隔离、强制、移除或转换决策 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-4.8-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "4.8",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Require every connector carrying source-to-production software identity, design invariant, component trust, build provenance, test result, deployment state, runtime outcome, and vulnerability response to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 从源码到生产的软件身份、设计不变量、组件信任、构建来源、测试结果、部署状态、运行结果和漏洞响应 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-4.8-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "4.8",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Define required services per asset role in the secure baseline, remove packages when practical, otherwise disable and block them, and prevent automatic re-enablement.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“按资产角色在安全基线中列必需服务，能卸载就移除，否则禁用并阻断，防止自动重启；例外绑定业务依赖，并观察真实监听端口、进程和云/API 配置。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-4.8-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "4.8",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-4.8-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "4.8",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-4.8-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "4.8",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-4.8-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "4.8",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the versioned secure-configuration authority and exception register and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在版本化安全配置权威库与例外台账中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-4.8-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "4.8",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Implement the explicit state machine observe → evaluate → decide → enforce → verify outcome → rollback/close; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-4.8-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "4.8",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Implement the explicit state machine designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-4.8-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "4.8",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-4.8-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "4.8",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-4.8-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "4.8",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-4.8-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "4.8",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-4.8-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "4.8",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in role-specific secure baselines and effective configurations for endpoints, servers, mobile, cloud, network, software, and administrative paths; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 终端、服务器、移动、云、网络、软件和管理路径的角色化安全基线与实际配置 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-4.8-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "4.8",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for observe → evaluate → decide → enforce → verify outcome → rollback/close; alert before each deadline becomes overdue.",
          "zh": "为“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-4.8-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "4.8",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; alert before each deadline becomes overdue.",
          "zh": "为“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-4.8-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "4.8",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “Socket activation, scheduled tasks, containers and on-demand cloud features may be dormant during a snapshot.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“Socket 激活、计划任务、容器与按需云功能在快照时可能休眠。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-4.8-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "4.8",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-4.8-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "4.8",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-4.8-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "4.8",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-4.8-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "4.8",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat unsupported settings, local overrides, inherited cloud policy, vendor defaults, emergency access, safety constraints, drift, and rollback as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 不支持的设置、本地覆盖、继承云策略、厂商默认值、紧急访问、安全约束、漂移和回滚 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-4.8-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "4.8",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Treat audit-only mode, unsupported platforms, local overrides, race conditions, cached state, alternate paths, fail-open behavior, and emergency bypass as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 仅审计模式、不支持平台、本地覆盖、竞态、缓存状态、替代路径、故障开放和紧急绕过 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-4.8-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "4.8",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Treat generated and copied code, forks, vendoring, transitive dependencies, mutable tags, build plugins, feature flags, tenant logic, secrets, emergency release, and provider components as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 生成与复制代码、分叉、vendoring、传递依赖、可变标签、构建插件、功能开关、租户逻辑、秘密、紧急发布和提供商组件 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-4.8-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "4.8",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Compare live services and ports to the role baseline, disable a benign test service and verify persistence after restart/update, then start an unapproved listener to test detection and remediation.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“把实时服务与角色基线对比，禁用无害测试服务并验证重启/更新后仍禁用；再启动未批准监听测试发现和修复。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-4.8-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "4.8",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-4.8-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "4.8",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 2 pinned CAS metric branch(es), 9 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 2 个指标分支、9 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-4.8-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "4.8",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-4.8-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "4.8",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the versioned secure-configuration authority and exception register plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以版本化安全配置权威库与例外台账和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-4.8-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "4.8",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Publish eligible, enforcing, audit-only, failed, bypassed, excepted, rolled-back, and outcome-verified populations with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 适用、已执行、仅审计、失败、被绕过、例外、已回滚和结果已验证总体，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-4.8-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "4.8",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Publish reviewed, unreviewed, reproducible, provenance-bound, vulnerable, test-failed, exception, deployed-unverified, drifted, rolled-back, and regression-protected releases with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已评审、未评审、可复现、来源绑定、存在漏洞、测试失败、例外、已部署未验证、漂移、已回滚和受回归保护发布物，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-4.8-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "4.8",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-4.8-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "4.8",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-4.8-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "4.8",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-4.8-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "4.8",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-4.8-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "4.8",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the versioned secure-configuration authority and exception register; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护版本化安全配置权威库与例外台账的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-4.8-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "4.8",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Restrict authority to change observe → evaluate → decide → enforce → verify outcome → rollback/close; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-4.8-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "4.8",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Restrict authority to change designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-4.8-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "4.8",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-4.8-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "4.8",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-4.8-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "4.8",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-4.8-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "4.8",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-4.8-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "4.8",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise approved business behavior, a prohibited setting or service, policy tampering, failed rollout, drift recurrence, and tested rollback through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 获批业务行为、禁止设置或服务、策略篡改、发布失败、漂移复发和已测试回滚，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-4.8-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "4.8",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Run the positive control an approved business action that completes through the enforced path; exercise negative, stale, duplicate, bypass, and outage controls including a prohibited action, alternate path, local override, stale policy, control outage, emergency bypass, and rollback failure.",
          "zh": "运行正向控制“通过受控路径完成的一项获批业务动作”，并执行包含“禁止动作、替代路径、本地覆盖、陈旧策略、控制中断、紧急绕过和回滚失败”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-4.8-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "4.8",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Run the positive control a trusted build that preserves the security invariant through deployment and runtime; exercise negative, stale, duplicate, bypass, and outage controls including a substituted dependency, unreviewed change, poisoned build input, failed security test, bypass path, vulnerable release, rollback, and regression.",
          "zh": "运行正向控制“一个把安全不变量贯穿部署与运行的可信构建”，并执行包含“依赖替换、未评审变更、构建输入污染、安全测试失败、绕过路径、漏洞发布、回滚和回归”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-4.8-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "4.8",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-4.8-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "4.8",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-4.8-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "4.8",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-4.8-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "4.8",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-4.8-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "4.8",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever benchmarks, golden images, configuration management, IaC, MDM, cloud policy, network controllers, drift scans, and change records change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 基准、黄金镜像、配置管理、IaC、MDM、云策略、网络控制器、漂移扫描和变更记录 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-4.8-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "4.8",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Use eligible, enforcing, audit-only, failed, bypassed, excepted, rolled-back, and outcome-verified populations to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 适用、已执行、仅审计、失败、被绕过、例外、已回滚和结果已验证总体 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-4.8-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "4.8",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Use reviewed, unreviewed, reproducible, provenance-bound, vulnerable, test-failed, exception, deployed-unverified, drifted, rolled-back, and regression-protected releases to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已评审、未评审、可复现、来源绑定、存在漏洞、测试失败、例外、已部署未验证、漂移、已回滚和受回归保护发布物 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "4.9",
      "control": 4,
      "title_en": "Configure Trusted DNS Servers on Enterprise Assets",
      "title_zh": "可信 DNS 解析器",
      "first_ig": 2,
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Devices",
      "security_function": "Protect",
      "patterns": [
        "enforcement",
        "network"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "1.1",
          "4.1"
        ],
        "variables": [
          "GV1",
          "GV3",
          "M1",
          "M2",
          "M3",
          "M4"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "Cover DNS settings and effective resolution paths on endpoints, servers, network devices, VPNs, mobile, cloud networks, containers and applications using embedded or encrypted DNS.",
          "build": "Enforce enterprise or explicitly approved resolvers through DHCP/RA, device policy, VPN, cloud and application configuration; authenticate encrypted DNS where used, control bypass, protect resolver administration and monitor fallback.",
          "proof": "Resolve test names through normal and failure paths and confirm the actual resolver, policy response, logging and DNSSEC behavior where required.",
          "boundary": "Captive portals, roaming clients, split DNS, IPv6 RDNSS and application-level DoH can bypass endpoint settings."
        },
        "zh": {
          "scope": "覆盖终端、服务器、网络设备、VPN、移动、云网络、容器以及自带/加密 DNS 的应用之真实解析路径。",
          "build": "通过 DHCP/RA、设备策略、VPN、云与应用配置强制企业或明确批准的解析器；使用加密 DNS 时认证对端，控制绕过，保护解析器管理并监控回退。",
          "proof": "在正常与故障路径解析测试域名，确认实际解析器、策略结果、日志以及需要时 DNSSEC；再尝试 Rogue 解析器、硬编码公共 DNS 和浏览器 DoH。",
          "boundary": "Captive Portal、漫游、分区 DNS、IPv6 RDNSS 和应用 DoH 会绕开终端设置。"
        }
      },
      "category_counts": {
        "outcome": 7,
        "scope": 7,
        "ownership": 7,
        "data": 7,
        "integration": 7,
        "control": 7,
        "timing": 7,
        "exception": 7,
        "evidence": 7,
        "security": 7,
        "testing": 7,
        "operations": 7
      },
      "requirement_count": 84,
      "requirements": [
        {
          "code": "CIS-4.9-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "4.9",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Configure Trusted DNS Servers on Enterprise Assets; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“可信 DNS 解析器”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-4.9-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "4.9",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 4.9, official Asset Class Devices, Security Function Protect, and IG2 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 4.9、官方资产类别“设备”、安全功能“保护”和首次出现的 IG2，并保存来源抓取日期。"
        },
        {
          "code": "CIS-4.9-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "4.9",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Cover DNS settings and effective resolution paths on endpoints, servers, network devices, VPNs, mobile, cloud networks, containers and applications using embedded or encrypted DNS.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“覆盖终端、服务器、网络设备、VPN、移动、云网络、容器以及自带/加密 DNS 的应用之真实解析路径。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-4.9-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "4.9",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-4.9-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "4.9",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Configure Trusted DNS Servers on Enterprise Assets to its operating object—role-specific secure baselines and effective configurations for endpoints, servers, mobile, cloud, network, software, and administrative paths—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“可信 DNS 解析器”连接到其运营对象——终端、服务器、移动、云、网络、软件和管理路径的角色化安全基线与实际配置——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-4.9-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "4.9",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "For Configure Trusted DNS Servers on Enterprise Assets, express success as an observable decision over an enforceable allow, deny, contain, quarantine, require, remove, or transform decision at the closest reliable control point; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“可信 DNS 解析器”，以 在最近可靠控制点执行允许、拒绝、遏制、隔离、强制、移除或转换决策 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-4.9-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "4.9",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "For Configure Trusted DNS Servers on Enterprise Assets, express success as an observable decision over intended connectivity, trust zone, route, protocol, identity, management path, traffic decision, and observed outcome; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“可信 DNS 解析器”，以 预期连接、信任区、路由、协议、身份、管理路径、流量决策和观察结果 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-4.9-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "4.9",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-4.9-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "4.9",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-4.9-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "4.9",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-4.9-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "4.9",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-4.9-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "4.9",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across unsupported settings, local overrides, inherited cloud policy, vendor defaults, emergency access, safety constraints, drift, and rollback; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 不支持的设置、本地覆盖、继承云策略、厂商默认值、紧急访问、安全约束、漂移和回滚 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-4.9-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "4.9",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Include audit-only mode, unsupported platforms, local overrides, race conditions, cached state, alternate paths, fail-open behavior, and emergency bypass in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 仅审计模式、不支持平台、本地覆盖、竞态、缓存状态、替代路径、故障开放和紧急绕过 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-4.9-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "4.9",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Include IPv6, overlays, east-west paths, remote and roaming devices, direct egress, alternate resolvers, QUIC, asymmetric routes, provider abstraction, and emergency consoles in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 IPv6、覆盖网络、东西向路径、远程与漫游设备、直接出口、替代解析器、QUIC、非对称路由、提供商抽象和紧急控制台 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-4.9-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "4.9",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-4.9-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "4.9",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-4.9-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "4.9",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-4.9-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "4.9",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-4.9-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "4.9",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind platform and application owners, network engineering, security architecture, change management, and service owners to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 平台与应用责任人、网络工程、安全架构、变更管理和服务责任人 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-4.9-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "4.9",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Name who may transition observe → evaluate → decide → enforce → verify outcome → rollback/close, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-4.9-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "4.9",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Name who may transition requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-4.9-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "4.9",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-4.9-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "4.9",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-4.9-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "4.9",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV1, GV3, M1, M2, M3, M4) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV1, GV3, M1, M2, M3, M4）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-4.9-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "4.9",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-4.9-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "4.9",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the versioned secure-configuration authority and exception register as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把版本化安全配置权威库与例外台账作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-4.9-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "4.9",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle observe → evaluate → decide → enforce → verify outcome → rollback/close.",
          "zh": "对生命周期“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-4.9-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "4.9",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired.",
          "zh": "对生命周期“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-4.9-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "4.9",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 1.1, Safeguard 4.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 1.1、Safeguard 4.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-4.9-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "4.9",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-4.9-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "4.9",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-4.9-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "4.9",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-4.9-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "4.9",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile benchmarks, golden images, configuration management, IaC, MDM, cloud policy, network controllers, drift scans, and change records and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 基准、黄金镜像、配置管理、IaC、MDM、云策略、网络控制器、漂移扫描和变更记录，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-4.9-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "4.9",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Require every connector carrying an enforceable allow, deny, contain, quarantine, require, remove, or transform decision at the closest reliable control point to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 在最近可靠控制点执行允许、拒绝、遏制、隔离、强制、移除或转换决策 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-4.9-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "4.9",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Require every connector carrying intended connectivity, trust zone, route, protocol, identity, management path, traffic decision, and observed outcome to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 预期连接、信任区、路由、协议、身份、管理路径、流量决策和观察结果 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-4.9-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "4.9",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Enforce enterprise or explicitly approved resolvers through DHCP/RA, device policy, VPN, cloud and application configuration; authenticate encrypted DNS where used, control bypass, protect resolver administration and monitor fallback.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“通过 DHCP/RA、设备策略、VPN、云与应用配置强制企业或明确批准的解析器；使用加密 DNS 时认证对端，控制绕过，保护解析器管理并监控回退。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-4.9-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "4.9",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-4.9-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "4.9",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-4.9-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "4.9",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-4.9-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "4.9",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the versioned secure-configuration authority and exception register and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在版本化安全配置权威库与例外台账中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-4.9-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "4.9",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Implement the explicit state machine observe → evaluate → decide → enforce → verify outcome → rollback/close; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-4.9-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "4.9",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Implement the explicit state machine requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-4.9-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "4.9",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-4.9-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "4.9",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-4.9-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "4.9",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-4.9-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "4.9",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-4.9-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "4.9",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in role-specific secure baselines and effective configurations for endpoints, servers, mobile, cloud, network, software, and administrative paths; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 终端、服务器、移动、云、网络、软件和管理路径的角色化安全基线与实际配置 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-4.9-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "4.9",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for observe → evaluate → decide → enforce → verify outcome → rollback/close; alert before each deadline becomes overdue.",
          "zh": "为“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-4.9-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "4.9",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; alert before each deadline becomes overdue.",
          "zh": "为“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-4.9-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "4.9",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “Captive portals, roaming clients, split DNS, IPv6 RDNSS and application-level DoH can bypass endpoint settings.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“Captive Portal、漫游、分区 DNS、IPv6 RDNSS 和应用 DoH 会绕开终端设置。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-4.9-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "4.9",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-4.9-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "4.9",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-4.9-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "4.9",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-4.9-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "4.9",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat unsupported settings, local overrides, inherited cloud policy, vendor defaults, emergency access, safety constraints, drift, and rollback as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 不支持的设置、本地覆盖、继承云策略、厂商默认值、紧急访问、安全约束、漂移和回滚 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-4.9-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "4.9",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Treat audit-only mode, unsupported platforms, local overrides, race conditions, cached state, alternate paths, fail-open behavior, and emergency bypass as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 仅审计模式、不支持平台、本地覆盖、竞态、缓存状态、替代路径、故障开放和紧急绕过 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-4.9-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "4.9",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Treat IPv6, overlays, east-west paths, remote and roaming devices, direct egress, alternate resolvers, QUIC, asymmetric routes, provider abstraction, and emergency consoles as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 IPv6、覆盖网络、东西向路径、远程与漫游设备、直接出口、替代解析器、QUIC、非对称路由、提供商抽象和紧急控制台 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-4.9-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "4.9",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Resolve test names through normal and failure paths and confirm the actual resolver, policy response, logging and DNSSEC behavior where required.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“在正常与故障路径解析测试域名，确认实际解析器、策略结果、日志以及需要时 DNSSEC；再尝试 Rogue 解析器、硬编码公共 DNS 和浏览器 DoH。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-4.9-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "4.9",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-4.9-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "4.9",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 6 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、6 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-4.9-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "4.9",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-4.9-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "4.9",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the versioned secure-configuration authority and exception register plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以版本化安全配置权威库与例外台账和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-4.9-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "4.9",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Publish eligible, enforcing, audit-only, failed, bypassed, excepted, rolled-back, and outcome-verified populations with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 适用、已执行、仅审计、失败、被绕过、例外、已回滚和结果已验证总体，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-4.9-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "4.9",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Publish known, unknown, allowed, denied, shadow, bypassed, asymmetric, stale-rule, exception, and unobserved paths with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已知、未知、允许、拒绝、影子、绕过、非对称、陈旧规则、例外和未观测路径，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-4.9-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "4.9",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-4.9-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "4.9",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-4.9-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "4.9",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-4.9-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "4.9",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-4.9-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "4.9",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the versioned secure-configuration authority and exception register; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护版本化安全配置权威库与例外台账的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-4.9-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "4.9",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Restrict authority to change observe → evaluate → decide → enforce → verify outcome → rollback/close; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-4.9-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "4.9",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Restrict authority to change requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-4.9-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "4.9",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-4.9-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "4.9",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-4.9-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "4.9",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-4.9-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "4.9",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-4.9-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "4.9",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise approved business behavior, a prohibited setting or service, policy tampering, failed rollout, drift recurrence, and tested rollback through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 获批业务行为、禁止设置或服务、策略篡改、发布失败、漂移复发和已测试回滚，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-4.9-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "4.9",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Run the positive control an approved business action that completes through the enforced path; exercise negative, stale, duplicate, bypass, and outage controls including a prohibited action, alternate path, local override, stale policy, control outage, emergency bypass, and rollback failure.",
          "zh": "运行正向控制“通过受控路径完成的一项获批业务动作”，并执行包含“禁止动作、替代路径、本地覆盖、陈旧策略、控制中断、紧急绕过和回滚失败”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-4.9-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "4.9",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Run the positive control an approved flow over the required secure management or business path; exercise negative, stale, duplicate, bypass, and outage controls including an unapproved route, protocol downgrade, direct egress, alternate DNS/QUIC path, segmentation bypass, AAA loss, stale rule, and rollback failure.",
          "zh": "运行正向控制“通过规定安全管理或业务路径的一项获批流量”，并执行包含“未批准路由、协议降级、直接出口、替代 DNS/QUIC 路径、分段绕过、AAA 丢失、陈旧规则和回滚失败”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-4.9-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "4.9",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-4.9-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "4.9",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-4.9-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "4.9",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-4.9-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "4.9",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-4.9-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "4.9",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever benchmarks, golden images, configuration management, IaC, MDM, cloud policy, network controllers, drift scans, and change records change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 基准、黄金镜像、配置管理、IaC、MDM、云策略、网络控制器、漂移扫描和变更记录 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-4.9-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "4.9",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Use eligible, enforcing, audit-only, failed, bypassed, excepted, rolled-back, and outcome-verified populations to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 适用、已执行、仅审计、失败、被绕过、例外、已回滚和结果已验证总体 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-4.9-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "4.9",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Use known, unknown, allowed, denied, shadow, bypassed, asymmetric, stale-rule, exception, and unobserved paths to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已知、未知、允许、拒绝、影子、绕过、非对称、陈旧规则、例外和未观测路径 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "4.10",
      "control": 4,
      "title_en": "Enforce Automatic Device Lockout on Portable End-User Devices",
      "title_zh": "便携设备失败认证锁定",
      "first_ig": 2,
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Devices",
      "security_function": "Protect",
      "patterns": [
        "enforcement"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "1.1",
          "4.1"
        ],
        "variables": [
          "GV1",
          "GV3",
          "M1",
          "M2",
          "M3",
          "M4",
          "M5"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "Eligible devices are laptops, tablets and smartphones with local authentication and enterprise data or authority.",
          "build": "Enforce thresholds through MDM/endpoint policy with escalating delay, lock or secure wipe appropriate to data and recovery risk.",
          "proof": "On test devices, exceed the threshold using local, biometric-fallback and offline paths, verify lock state, data preservation or wipe, alerting and approved recovery.",
          "boundary": "Aggressive wipe can cause denial of service or destroy unsynchronized evidence; choose lock versus wipe deliberately."
        },
        "zh": {
          "scope": "适用设备是带本地认证且承载企业数据/权限的笔记本、平板和手机。",
          "build": "通过 MDM/终端策略设置逐步延迟、锁定或按数据/恢复风险决定的安全擦除；保护恢复凭据，阻止用户放宽，并让生物/PIN 回退、离线尝试和硬件限制与政策一致。",
          "proof": "在测试设备经本地、生物回退和离线路径超过阈值，验证锁定、保留/擦除数据、告警和获批恢复；读取真实生效策略与最近证明，不看 Profile 是否“已分配”。",
          "boundary": "过激擦除可造成拒绝服务或毁掉未同步证据，应明确选择锁还是擦。"
        }
      },
      "category_counts": {
        "outcome": 6,
        "scope": 6,
        "ownership": 6,
        "data": 6,
        "integration": 6,
        "control": 6,
        "timing": 6,
        "exception": 6,
        "evidence": 6,
        "security": 6,
        "testing": 6,
        "operations": 6
      },
      "requirement_count": 72,
      "requirements": [
        {
          "code": "CIS-4.10-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "4.10",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Enforce Automatic Device Lockout on Portable End-User Devices; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“便携设备失败认证锁定”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-4.10-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "4.10",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 4.10, official Asset Class Devices, Security Function Protect, and IG2 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 4.10、官方资产类别“设备”、安全功能“保护”和首次出现的 IG2，并保存来源抓取日期。"
        },
        {
          "code": "CIS-4.10-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "4.10",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Eligible devices are laptops, tablets and smartphones with local authentication and enterprise data or authority.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“适用设备是带本地认证且承载企业数据/权限的笔记本、平板和手机。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-4.10-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "4.10",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-4.10-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "4.10",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Enforce Automatic Device Lockout on Portable End-User Devices to its operating object—role-specific secure baselines and effective configurations for endpoints, servers, mobile, cloud, network, software, and administrative paths—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“便携设备失败认证锁定”连接到其运营对象——终端、服务器、移动、云、网络、软件和管理路径的角色化安全基线与实际配置——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-4.10-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "4.10",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "For Enforce Automatic Device Lockout on Portable End-User Devices, express success as an observable decision over an enforceable allow, deny, contain, quarantine, require, remove, or transform decision at the closest reliable control point; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“便携设备失败认证锁定”，以 在最近可靠控制点执行允许、拒绝、遏制、隔离、强制、移除或转换决策 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-4.10-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "4.10",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-4.10-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "4.10",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-4.10-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "4.10",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-4.10-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "4.10",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-4.10-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "4.10",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across unsupported settings, local overrides, inherited cloud policy, vendor defaults, emergency access, safety constraints, drift, and rollback; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 不支持的设置、本地覆盖、继承云策略、厂商默认值、紧急访问、安全约束、漂移和回滚 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-4.10-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "4.10",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Include audit-only mode, unsupported platforms, local overrides, race conditions, cached state, alternate paths, fail-open behavior, and emergency bypass in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 仅审计模式、不支持平台、本地覆盖、竞态、缓存状态、替代路径、故障开放和紧急绕过 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-4.10-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "4.10",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-4.10-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "4.10",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-4.10-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "4.10",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-4.10-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "4.10",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-4.10-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "4.10",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind platform and application owners, network engineering, security architecture, change management, and service owners to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 平台与应用责任人、网络工程、安全架构、变更管理和服务责任人 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-4.10-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "4.10",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Name who may transition observe → evaluate → decide → enforce → verify outcome → rollback/close, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-4.10-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "4.10",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-4.10-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "4.10",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-4.10-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "4.10",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV1, GV3, M1, M2, M3, M4, M5) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV1, GV3, M1, M2, M3, M4, M5）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-4.10-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "4.10",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-4.10-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "4.10",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the versioned secure-configuration authority and exception register as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把版本化安全配置权威库与例外台账作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-4.10-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "4.10",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle observe → evaluate → decide → enforce → verify outcome → rollback/close.",
          "zh": "对生命周期“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-4.10-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "4.10",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 1.1, Safeguard 4.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 1.1、Safeguard 4.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-4.10-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "4.10",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-4.10-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "4.10",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-4.10-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "4.10",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-4.10-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "4.10",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile benchmarks, golden images, configuration management, IaC, MDM, cloud policy, network controllers, drift scans, and change records and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 基准、黄金镜像、配置管理、IaC、MDM、云策略、网络控制器、漂移扫描和变更记录，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-4.10-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "4.10",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Require every connector carrying an enforceable allow, deny, contain, quarantine, require, remove, or transform decision at the closest reliable control point to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 在最近可靠控制点执行允许、拒绝、遏制、隔离、强制、移除或转换决策 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-4.10-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "4.10",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Enforce thresholds through MDM/endpoint policy with escalating delay, lock or secure wipe appropriate to data and recovery risk.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“通过 MDM/终端策略设置逐步延迟、锁定或按数据/恢复风险决定的安全擦除；保护恢复凭据，阻止用户放宽，并让生物/PIN 回退、离线尝试和硬件限制与政策一致。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-4.10-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "4.10",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-4.10-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "4.10",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-4.10-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "4.10",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-4.10-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "4.10",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the versioned secure-configuration authority and exception register and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在版本化安全配置权威库与例外台账中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-4.10-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "4.10",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Implement the explicit state machine observe → evaluate → decide → enforce → verify outcome → rollback/close; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-4.10-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "4.10",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-4.10-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "4.10",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-4.10-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "4.10",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-4.10-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "4.10",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-4.10-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "4.10",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in role-specific secure baselines and effective configurations for endpoints, servers, mobile, cloud, network, software, and administrative paths; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 终端、服务器、移动、云、网络、软件和管理路径的角色化安全基线与实际配置 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-4.10-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "4.10",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for observe → evaluate → decide → enforce → verify outcome → rollback/close; alert before each deadline becomes overdue.",
          "zh": "为“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-4.10-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "4.10",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “Aggressive wipe can cause denial of service or destroy unsynchronized evidence; choose lock versus wipe deliberately.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“过激擦除可造成拒绝服务或毁掉未同步证据，应明确选择锁还是擦。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-4.10-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "4.10",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-4.10-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "4.10",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-4.10-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "4.10",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-4.10-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "4.10",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat unsupported settings, local overrides, inherited cloud policy, vendor defaults, emergency access, safety constraints, drift, and rollback as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 不支持的设置、本地覆盖、继承云策略、厂商默认值、紧急访问、安全约束、漂移和回滚 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-4.10-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "4.10",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Treat audit-only mode, unsupported platforms, local overrides, race conditions, cached state, alternate paths, fail-open behavior, and emergency bypass as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 仅审计模式、不支持平台、本地覆盖、竞态、缓存状态、替代路径、故障开放和紧急绕过 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-4.10-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "4.10",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “On test devices, exceed the threshold using local, biometric-fallback and offline paths, verify lock state, data preservation or wipe, alerting and approved recovery.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“在测试设备经本地、生物回退和离线路径超过阈值，验证锁定、保留/擦除数据、告警和获批恢复；读取真实生效策略与最近证明，不看 Profile 是否“已分配”。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-4.10-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "4.10",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-4.10-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "4.10",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 7 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、7 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-4.10-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "4.10",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-4.10-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "4.10",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the versioned secure-configuration authority and exception register plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以版本化安全配置权威库与例外台账和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-4.10-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "4.10",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Publish eligible, enforcing, audit-only, failed, bypassed, excepted, rolled-back, and outcome-verified populations with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 适用、已执行、仅审计、失败、被绕过、例外、已回滚和结果已验证总体，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-4.10-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "4.10",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-4.10-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "4.10",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-4.10-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "4.10",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-4.10-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "4.10",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-4.10-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "4.10",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the versioned secure-configuration authority and exception register; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护版本化安全配置权威库与例外台账的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-4.10-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "4.10",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Restrict authority to change observe → evaluate → decide → enforce → verify outcome → rollback/close; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-4.10-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "4.10",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-4.10-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "4.10",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-4.10-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "4.10",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-4.10-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "4.10",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-4.10-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "4.10",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise approved business behavior, a prohibited setting or service, policy tampering, failed rollout, drift recurrence, and tested rollback through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 获批业务行为、禁止设置或服务、策略篡改、发布失败、漂移复发和已测试回滚，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-4.10-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "4.10",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Run the positive control an approved business action that completes through the enforced path; exercise negative, stale, duplicate, bypass, and outage controls including a prohibited action, alternate path, local override, stale policy, control outage, emergency bypass, and rollback failure.",
          "zh": "运行正向控制“通过受控路径完成的一项获批业务动作”，并执行包含“禁止动作、替代路径、本地覆盖、陈旧策略、控制中断、紧急绕过和回滚失败”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-4.10-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "4.10",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-4.10-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "4.10",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-4.10-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "4.10",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-4.10-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "4.10",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-4.10-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "4.10",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever benchmarks, golden images, configuration management, IaC, MDM, cloud policy, network controllers, drift scans, and change records change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 基准、黄金镜像、配置管理、IaC、MDM、云策略、网络控制器、漂移扫描和变更记录 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-4.10-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "4.10",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Use eligible, enforcing, audit-only, failed, bypassed, excepted, rolled-back, and outcome-verified populations to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 适用、已执行、仅审计、失败、被绕过、例外、已回滚和结果已验证总体 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "4.11",
      "control": 4,
      "title_en": "Enforce Remote Wipe Capability on Portable End-User Devices",
      "title_zh": "远程擦除",
      "first_ig": 2,
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Data",
      "security_function": "Protect",
      "patterns": [
        "enforcement",
        "recovery",
        "network"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "1.1",
          "4.1"
        ],
        "variables": [
          "GV1",
          "GV3",
          "M1",
          "M2",
          "M3"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "Scope enterprise-owned portable devices and the enterprise workspace/data on supported personally owned devices.",
          "build": "Enroll devices before access, maintain MDM authority and last contact, separate full-device from selective wipe, require incident authorization and preserve a chain of actions.",
          "proof": "Use a sacrificial enrolled device to test command authorization, delivery, offline queueing, workspace/full wipe result, token revocation and audit receipt.",
          "boundary": "Powered-off, reset, jailbroken, unenrolled and permanently offline devices may never receive the command."
        },
        "zh": {
          "scope": "范围是企业所有便携设备，以及受支持个人设备里的企业工作区/数据。",
          "build": "在授予访问前完成 MDM 注册，维护管理权和最后在线时间，区分全机与选择性擦除，要求事件授权并保留操作链；同时撤销 Token/密钥，配合加密、本地锁和取证/法务决定。",
          "proof": "用可牺牲受管设备测试命令授权、投递、离线排队、工作区/全机结果、Token 撤销和回执。",
          "boundary": "关机、重置、越狱、未注册或永久离线设备可能永收不到命令。"
        }
      },
      "category_counts": {
        "outcome": 8,
        "scope": 8,
        "ownership": 8,
        "data": 8,
        "integration": 8,
        "control": 8,
        "timing": 8,
        "exception": 8,
        "evidence": 8,
        "security": 8,
        "testing": 8,
        "operations": 8
      },
      "requirement_count": 96,
      "requirements": [
        {
          "code": "CIS-4.11-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "4.11",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Enforce Remote Wipe Capability on Portable End-User Devices; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“远程擦除”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-4.11-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "4.11",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 4.11, official Asset Class Data, Security Function Protect, and IG2 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 4.11、官方资产类别“数据”、安全功能“保护”和首次出现的 IG2，并保存来源抓取日期。"
        },
        {
          "code": "CIS-4.11-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "4.11",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Scope enterprise-owned portable devices and the enterprise workspace/data on supported personally owned devices.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“范围是企业所有便携设备，以及受支持个人设备里的企业工作区/数据。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-4.11-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "4.11",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-4.11-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "4.11",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Enforce Remote Wipe Capability on Portable End-User Devices to its operating object—role-specific secure baselines and effective configurations for endpoints, servers, mobile, cloud, network, software, and administrative paths—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“远程擦除”连接到其运营对象——终端、服务器、移动、云、网络、软件和管理路径的角色化安全基线与实际配置——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-4.11-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "4.11",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "For Enforce Remote Wipe Capability on Portable End-User Devices, express success as an observable decision over an enforceable allow, deny, contain, quarantine, require, remove, or transform decision at the closest reliable control point; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“远程擦除”，以 在最近可靠控制点执行允许、拒绝、遏制、隔离、强制、移除或转换决策 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-4.11-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "4.11",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original recovery pattern analysis",
          "basis_zh": "SOSEC 原创 recovery 模式分析",
          "en": "For Enforce Remote Wipe Capability on Portable End-User Devices, express success as an observable decision over recoverable business service, protected recovery point, trustworthy copy, dependency, recovery objective, and verified restored outcome; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“远程擦除”，以 可恢复业务服务、受保护恢复点、可信副本、依赖、恢复目标和经验证的恢复结果 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-4.11-OUT-08",
          "local_code": "OUT-08",
          "display_code": "O08",
          "safeguard_id": "4.11",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "For Enforce Remote Wipe Capability on Portable End-User Devices, express success as an observable decision over intended connectivity, trust zone, route, protocol, identity, management path, traffic decision, and observed outcome; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“远程擦除”，以 预期连接、信任区、路由、协议、身份、管理路径、流量决策和观察结果 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-4.11-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "4.11",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-4.11-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "4.11",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-4.11-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "4.11",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-4.11-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "4.11",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-4.11-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "4.11",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across unsupported settings, local overrides, inherited cloud policy, vendor defaults, emergency access, safety constraints, drift, and rollback; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 不支持的设置、本地覆盖、继承云策略、厂商默认值、紧急访问、安全约束、漂移和回滚 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-4.11-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "4.11",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Include audit-only mode, unsupported platforms, local overrides, race conditions, cached state, alternate paths, fail-open behavior, and emergency bypass in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 仅审计模式、不支持平台、本地覆盖、竞态、缓存状态、替代路径、故障开放和紧急绕过 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-4.11-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "4.11",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original recovery pattern analysis",
          "basis_zh": "SOSEC 原创 recovery 模式分析",
          "en": "Include silent job failure, corrupt source, ransomware reachability, missing key, provider or region loss, quota, partial restore, stale runbook, and clean-room unavailability in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 作业静默失败、源损坏、勒索软件可达、密钥缺失、提供商或地域丢失、配额、部分恢复、手册陈旧和洁净室不可用 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-4.11-SCP-08",
          "local_code": "SCP-08",
          "display_code": "P08",
          "safeguard_id": "4.11",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Include IPv6, overlays, east-west paths, remote and roaming devices, direct egress, alternate resolvers, QUIC, asymmetric routes, provider abstraction, and emergency consoles in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 IPv6、覆盖网络、东西向路径、远程与漫游设备、直接出口、替代解析器、QUIC、非对称路由、提供商抽象和紧急控制台 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-4.11-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "4.11",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-4.11-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "4.11",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-4.11-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "4.11",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-4.11-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "4.11",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-4.11-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "4.11",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind platform and application owners, network engineering, security architecture, change management, and service owners to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 平台与应用责任人、网络工程、安全架构、变更管理和服务责任人 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-4.11-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "4.11",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Name who may transition observe → evaluate → decide → enforce → verify outcome → rollback/close, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-4.11-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "4.11",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original recovery pattern analysis",
          "basis_zh": "SOSEC 原创 recovery 模式分析",
          "en": "Name who may transition protected object identified → copy created → isolated/verified → retained → selected → restored → business-validated → expired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 识别受保护对象 → 创建副本 → 隔离/验证 → 保留 → 选择 → 恢复 → 业务验证 → 到期，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-4.11-OWN-08",
          "local_code": "OWN-08",
          "display_code": "W08",
          "safeguard_id": "4.11",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Name who may transition requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-4.11-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "4.11",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-4.11-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "4.11",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-4.11-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "4.11",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV1, GV3, M1, M2, M3) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV1, GV3, M1, M2, M3）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-4.11-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "4.11",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-4.11-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "4.11",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the versioned secure-configuration authority and exception register as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把版本化安全配置权威库与例外台账作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-4.11-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "4.11",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle observe → evaluate → decide → enforce → verify outcome → rollback/close.",
          "zh": "对生命周期“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-4.11-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "4.11",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original recovery pattern analysis",
          "basis_zh": "SOSEC 原创 recovery 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle protected object identified → copy created → isolated/verified → retained → selected → restored → business-validated → expired.",
          "zh": "对生命周期“识别受保护对象 → 创建副本 → 隔离/验证 → 保留 → 选择 → 恢复 → 业务验证 → 到期”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-4.11-DAT-08",
          "local_code": "DAT-08",
          "display_code": "D08",
          "safeguard_id": "4.11",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired.",
          "zh": "对生命周期“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-4.11-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "4.11",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 1.1, Safeguard 4.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 1.1、Safeguard 4.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-4.11-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "4.11",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-4.11-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "4.11",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-4.11-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "4.11",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-4.11-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "4.11",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile benchmarks, golden images, configuration management, IaC, MDM, cloud policy, network controllers, drift scans, and change records and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 基准、黄金镜像、配置管理、IaC、MDM、云策略、网络控制器、漂移扫描和变更记录，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-4.11-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "4.11",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Require every connector carrying an enforceable allow, deny, contain, quarantine, require, remove, or transform decision at the closest reliable control point to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 在最近可靠控制点执行允许、拒绝、遏制、隔离、强制、移除或转换决策 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-4.11-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "4.11",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original recovery pattern analysis",
          "basis_zh": "SOSEC 原创 recovery 模式分析",
          "en": "Require every connector carrying recoverable business service, protected recovery point, trustworthy copy, dependency, recovery objective, and verified restored outcome to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 可恢复业务服务、受保护恢复点、可信副本、依赖、恢复目标和经验证的恢复结果 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-4.11-INT-08",
          "local_code": "INT-08",
          "display_code": "I08",
          "safeguard_id": "4.11",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Require every connector carrying intended connectivity, trust zone, route, protocol, identity, management path, traffic decision, and observed outcome to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 预期连接、信任区、路由、协议、身份、管理路径、流量决策和观察结果 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-4.11-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "4.11",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Enroll devices before access, maintain MDM authority and last contact, separate full-device from selective wipe, require incident authorization and preserve a chain of actions.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“在授予访问前完成 MDM 注册，维护管理权和最后在线时间，区分全机与选择性擦除，要求事件授权并保留操作链；同时撤销 Token/密钥，配合加密、本地锁和取证/法务决定。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-4.11-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "4.11",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-4.11-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "4.11",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-4.11-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "4.11",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-4.11-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "4.11",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the versioned secure-configuration authority and exception register and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在版本化安全配置权威库与例外台账中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-4.11-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "4.11",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Implement the explicit state machine observe → evaluate → decide → enforce → verify outcome → rollback/close; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-4.11-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "4.11",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original recovery pattern analysis",
          "basis_zh": "SOSEC 原创 recovery 模式分析",
          "en": "Implement the explicit state machine protected object identified → copy created → isolated/verified → retained → selected → restored → business-validated → expired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“识别受保护对象 → 创建副本 → 隔离/验证 → 保留 → 选择 → 恢复 → 业务验证 → 到期”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-4.11-CTL-08",
          "local_code": "CTL-08",
          "display_code": "C08",
          "safeguard_id": "4.11",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Implement the explicit state machine requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-4.11-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "4.11",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-4.11-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "4.11",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-4.11-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "4.11",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-4.11-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "4.11",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-4.11-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "4.11",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in role-specific secure baselines and effective configurations for endpoints, servers, mobile, cloud, network, software, and administrative paths; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 终端、服务器、移动、云、网络、软件和管理路径的角色化安全基线与实际配置 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-4.11-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "4.11",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for observe → evaluate → decide → enforce → verify outcome → rollback/close; alert before each deadline becomes overdue.",
          "zh": "为“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-4.11-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "4.11",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original recovery pattern analysis",
          "basis_zh": "SOSEC 原创 recovery 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for protected object identified → copy created → isolated/verified → retained → selected → restored → business-validated → expired; alert before each deadline becomes overdue.",
          "zh": "为“识别受保护对象 → 创建副本 → 隔离/验证 → 保留 → 选择 → 恢复 → 业务验证 → 到期”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-4.11-TIM-08",
          "local_code": "TIM-08",
          "display_code": "T08",
          "safeguard_id": "4.11",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; alert before each deadline becomes overdue.",
          "zh": "为“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-4.11-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "4.11",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “Powered-off, reset, jailbroken, unenrolled and permanently offline devices may never receive the command.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“关机、重置、越狱、未注册或永久离线设备可能永收不到命令。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-4.11-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "4.11",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-4.11-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "4.11",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-4.11-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "4.11",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-4.11-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "4.11",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat unsupported settings, local overrides, inherited cloud policy, vendor defaults, emergency access, safety constraints, drift, and rollback as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 不支持的设置、本地覆盖、继承云策略、厂商默认值、紧急访问、安全约束、漂移和回滚 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-4.11-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "4.11",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Treat audit-only mode, unsupported platforms, local overrides, race conditions, cached state, alternate paths, fail-open behavior, and emergency bypass as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 仅审计模式、不支持平台、本地覆盖、竞态、缓存状态、替代路径、故障开放和紧急绕过 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-4.11-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "4.11",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original recovery pattern analysis",
          "basis_zh": "SOSEC 原创 recovery 模式分析",
          "en": "Treat silent job failure, corrupt source, ransomware reachability, missing key, provider or region loss, quota, partial restore, stale runbook, and clean-room unavailability as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 作业静默失败、源损坏、勒索软件可达、密钥缺失、提供商或地域丢失、配额、部分恢复、手册陈旧和洁净室不可用 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-4.11-EXC-08",
          "local_code": "EXC-08",
          "display_code": "X08",
          "safeguard_id": "4.11",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Treat IPv6, overlays, east-west paths, remote and roaming devices, direct egress, alternate resolvers, QUIC, asymmetric routes, provider abstraction, and emergency consoles as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 IPv6、覆盖网络、东西向路径、远程与漫游设备、直接出口、替代解析器、QUIC、非对称路由、提供商抽象和紧急控制台 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-4.11-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "4.11",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Use a sacrificial enrolled device to test command authorization, delivery, offline queueing, workspace/full wipe result, token revocation and audit receipt.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“用可牺牲受管设备测试命令授权、投递、离线排队、工作区/全机结果、Token 撤销和回执。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-4.11-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "4.11",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-4.11-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "4.11",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 5 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、5 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-4.11-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "4.11",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-4.11-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "4.11",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the versioned secure-configuration authority and exception register plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以版本化安全配置权威库与例外台账和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-4.11-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "4.11",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Publish eligible, enforcing, audit-only, failed, bypassed, excepted, rolled-back, and outcome-verified populations with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 适用、已执行、仅审计、失败、被绕过、例外、已回滚和结果已验证总体，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-4.11-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "4.11",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original recovery pattern analysis",
          "basis_zh": "SOSEC 原创 recovery 模式分析",
          "en": "Publish protected, missed, failed, stale, corrupt, reachable-by-production, keyless, untested, restore-failed, and business-validated recovery objects with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已保护、漏备、失败、陈旧、损坏、生产可达、无密钥、未测试、恢复失败和业务已验证恢复对象，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-4.11-EVD-08",
          "local_code": "EVD-08",
          "display_code": "E08",
          "safeguard_id": "4.11",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Publish known, unknown, allowed, denied, shadow, bypassed, asymmetric, stale-rule, exception, and unobserved paths with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已知、未知、允许、拒绝、影子、绕过、非对称、陈旧规则、例外和未观测路径，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-4.11-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "4.11",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-4.11-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "4.11",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-4.11-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "4.11",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-4.11-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "4.11",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-4.11-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "4.11",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the versioned secure-configuration authority and exception register; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护版本化安全配置权威库与例外台账的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-4.11-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "4.11",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Restrict authority to change observe → evaluate → decide → enforce → verify outcome → rollback/close; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-4.11-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "4.11",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original recovery pattern analysis",
          "basis_zh": "SOSEC 原创 recovery 模式分析",
          "en": "Restrict authority to change protected object identified → copy created → isolated/verified → retained → selected → restored → business-validated → expired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“识别受保护对象 → 创建副本 → 隔离/验证 → 保留 → 选择 → 恢复 → 业务验证 → 到期”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-4.11-SEC-08",
          "local_code": "SEC-08",
          "display_code": "S08",
          "safeguard_id": "4.11",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Restrict authority to change requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-4.11-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "4.11",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-4.11-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "4.11",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-4.11-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "4.11",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-4.11-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "4.11",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-4.11-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "4.11",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise approved business behavior, a prohibited setting or service, policy tampering, failed rollout, drift recurrence, and tested rollback through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 获批业务行为、禁止设置或服务、策略篡改、发布失败、漂移复发和已测试回滚，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-4.11-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "4.11",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Run the positive control an approved business action that completes through the enforced path; exercise negative, stale, duplicate, bypass, and outage controls including a prohibited action, alternate path, local override, stale policy, control outage, emergency bypass, and rollback failure.",
          "zh": "运行正向控制“通过受控路径完成的一项获批业务动作”，并执行包含“禁止动作、替代路径、本地覆盖、陈旧策略、控制中断、紧急绕过和回滚失败”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-4.11-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "4.11",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original recovery pattern analysis",
          "basis_zh": "SOSEC 原创 recovery 模式分析",
          "en": "Run the positive control a representative point-in-time restoration that passes data and business checks; exercise negative, stale, duplicate, bypass, and outage controls including failed job, corrupt copy, deletion/encryption attempt, lost key, unavailable provider, dependency omission, partial restore, and missed recovery objective.",
          "zh": "运行正向控制“一项通过数据与业务检查的代表性时间点恢复”，并执行包含“作业失败、副本损坏、删除/加密尝试、密钥丢失、提供商不可用、依赖遗漏、部分恢复和未达恢复目标”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-4.11-TST-08",
          "local_code": "TST-08",
          "display_code": "V08",
          "safeguard_id": "4.11",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Run the positive control an approved flow over the required secure management or business path; exercise negative, stale, duplicate, bypass, and outage controls including an unapproved route, protocol downgrade, direct egress, alternate DNS/QUIC path, segmentation bypass, AAA loss, stale rule, and rollback failure.",
          "zh": "运行正向控制“通过规定安全管理或业务路径的一项获批流量”，并执行包含“未批准路由、协议降级、直接出口、替代 DNS/QUIC 路径、分段绕过、AAA 丢失、陈旧规则和回滚失败”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-4.11-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "4.11",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-4.11-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "4.11",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-4.11-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "4.11",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-4.11-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "4.11",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-4.11-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "4.11",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever benchmarks, golden images, configuration management, IaC, MDM, cloud policy, network controllers, drift scans, and change records change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 基准、黄金镜像、配置管理、IaC、MDM、云策略、网络控制器、漂移扫描和变更记录 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-4.11-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "4.11",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Use eligible, enforcing, audit-only, failed, bypassed, excepted, rolled-back, and outcome-verified populations to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 适用、已执行、仅审计、失败、被绕过、例外、已回滚和结果已验证总体 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-4.11-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "4.11",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original recovery pattern analysis",
          "basis_zh": "SOSEC 原创 recovery 模式分析",
          "en": "Use protected, missed, failed, stale, corrupt, reachable-by-production, keyless, untested, restore-failed, and business-validated recovery objects to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已保护、漏备、失败、陈旧、损坏、生产可达、无密钥、未测试、恢复失败和业务已验证恢复对象 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-4.11-OPS-08",
          "local_code": "OPS-08",
          "display_code": "R08",
          "safeguard_id": "4.11",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Use known, unknown, allowed, denied, shadow, bypassed, asymmetric, stale-rule, exception, and unobserved paths to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已知、未知、允许、拒绝、影子、绕过、非对称、陈旧规则、例外和未观测路径 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "4.12",
      "control": 4,
      "title_en": "Separate Enterprise Workspaces on Mobile End-User Devices",
      "title_zh": "移动端企业工作区隔离",
      "first_ig": 3,
      "implementation_groups": [
        3
      ],
      "asset_class": "Data",
      "security_function": "Protect",
      "patterns": [
        "enforcement"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "1.1",
          "2.1",
          "4.1"
        ],
        "variables": [
          "GV1",
          "GV3",
          "GV5",
          "M1",
          "M2",
          "M3",
          "M4",
          "M5",
          "M6"
        ],
        "metric_branches": 0,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "The boundary separates enterprise applications, identities, data, clipboard, storage, backup and network paths from personal apps and accounts on supported mobile devices.",
          "build": "Use managed work profiles or containers, managed app configuration, per-app VPN and data-transfer policies; block unmanaged destinations, personal backups and unauthorized account mixing.",
          "proof": "Move test data through copy/paste, share sheets, open-in, screenshots, notifications, backups, keyboards, accessibility and personal cloud applications; verify intended allow/deny behavior and selective wipe.",
          "boundary": "Platform capabilities differ by OS version and ownership model."
        },
        "zh": {
          "scope": "边界要把移动端企业应用、身份、数据、剪贴板、存储、备份和网络路径与个人应用/账户分开。",
          "build": "用受管工作 Profile/容器、受管应用配置、Per-app VPN 与数据传输策略，禁止去未管理目的、个人备份和账户混用；企业所有、COPE 与 BYOD 分别制定 Profile，访问取决于经证明的工作区状态。",
          "proof": "用测试数据遍历复制粘贴、分享、Open-in、截图、通知、备份、键盘、辅助功能和个人云应用，验证预期准入/拒绝与选择性擦除。",
          "boundary": "各 OS 版本与所有权模式能力不同，有些泄漏路径无法完全阻断，需数据最小化或仅浏览器访问。"
        }
      },
      "category_counts": {
        "outcome": 6,
        "scope": 6,
        "ownership": 6,
        "data": 6,
        "integration": 6,
        "control": 6,
        "timing": 6,
        "exception": 6,
        "evidence": 6,
        "security": 6,
        "testing": 6,
        "operations": 6
      },
      "requirement_count": 72,
      "requirements": [
        {
          "code": "CIS-4.12-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "4.12",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Separate Enterprise Workspaces on Mobile End-User Devices; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“移动端企业工作区隔离”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-4.12-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "4.12",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 4.12, official Asset Class Data, Security Function Protect, and IG3 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 4.12、官方资产类别“数据”、安全功能“保护”和首次出现的 IG3，并保存来源抓取日期。"
        },
        {
          "code": "CIS-4.12-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "4.12",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “The boundary separates enterprise applications, identities, data, clipboard, storage, backup and network paths from personal apps and accounts on supported mobile devices.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“边界要把移动端企业应用、身份、数据、剪贴板、存储、备份和网络路径与个人应用/账户分开。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-4.12-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "4.12",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-4.12-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "4.12",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Separate Enterprise Workspaces on Mobile End-User Devices to its operating object—role-specific secure baselines and effective configurations for endpoints, servers, mobile, cloud, network, software, and administrative paths—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“移动端企业工作区隔离”连接到其运营对象——终端、服务器、移动、云、网络、软件和管理路径的角色化安全基线与实际配置——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-4.12-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "4.12",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "For Separate Enterprise Workspaces on Mobile End-User Devices, express success as an observable decision over an enforceable allow, deny, contain, quarantine, require, remove, or transform decision at the closest reliable control point; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“移动端企业工作区隔离”，以 在最近可靠控制点执行允许、拒绝、遏制、隔离、强制、移除或转换决策 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-4.12-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "4.12",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-4.12-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "4.12",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-4.12-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "4.12",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-4.12-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "4.12",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-4.12-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "4.12",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across unsupported settings, local overrides, inherited cloud policy, vendor defaults, emergency access, safety constraints, drift, and rollback; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 不支持的设置、本地覆盖、继承云策略、厂商默认值、紧急访问、安全约束、漂移和回滚 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-4.12-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "4.12",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Include audit-only mode, unsupported platforms, local overrides, race conditions, cached state, alternate paths, fail-open behavior, and emergency bypass in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 仅审计模式、不支持平台、本地覆盖、竞态、缓存状态、替代路径、故障开放和紧急绕过 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-4.12-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "4.12",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-4.12-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "4.12",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-4.12-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "4.12",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-4.12-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "4.12",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-4.12-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "4.12",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind platform and application owners, network engineering, security architecture, change management, and service owners to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 平台与应用责任人、网络工程、安全架构、变更管理和服务责任人 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-4.12-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "4.12",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Name who may transition observe → evaluate → decide → enforce → verify outcome → rollback/close, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-4.12-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "4.12",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-4.12-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "4.12",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-4.12-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "4.12",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV1, GV3, GV5, M1, M2, M3, M4, M5, M6) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV1, GV3, GV5, M1, M2, M3, M4, M5, M6）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-4.12-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "4.12",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-4.12-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "4.12",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the versioned secure-configuration authority and exception register as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把版本化安全配置权威库与例外台账作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-4.12-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "4.12",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle observe → evaluate → decide → enforce → verify outcome → rollback/close.",
          "zh": "对生命周期“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-4.12-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "4.12",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 1.1, Safeguard 2.1, Safeguard 4.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 1.1、Safeguard 2.1、Safeguard 4.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-4.12-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "4.12",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-4.12-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "4.12",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-4.12-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "4.12",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-4.12-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "4.12",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile benchmarks, golden images, configuration management, IaC, MDM, cloud policy, network controllers, drift scans, and change records and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 基准、黄金镜像、配置管理、IaC、MDM、云策略、网络控制器、漂移扫描和变更记录，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-4.12-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "4.12",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Require every connector carrying an enforceable allow, deny, contain, quarantine, require, remove, or transform decision at the closest reliable control point to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 在最近可靠控制点执行允许、拒绝、遏制、隔离、强制、移除或转换决策 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-4.12-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "4.12",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Use managed work profiles or containers, managed app configuration, per-app VPN and data-transfer policies; block unmanaged destinations, personal backups and unauthorized account mixing.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“用受管工作 Profile/容器、受管应用配置、Per-app VPN 与数据传输策略，禁止去未管理目的、个人备份和账户混用；企业所有、COPE 与 BYOD 分别制定 Profile，访问取决于经证明的工作区状态。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-4.12-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "4.12",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-4.12-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "4.12",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-4.12-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "4.12",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-4.12-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "4.12",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the versioned secure-configuration authority and exception register and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在版本化安全配置权威库与例外台账中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-4.12-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "4.12",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Implement the explicit state machine observe → evaluate → decide → enforce → verify outcome → rollback/close; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-4.12-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "4.12",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-4.12-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "4.12",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-4.12-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "4.12",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-4.12-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "4.12",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-4.12-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "4.12",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in role-specific secure baselines and effective configurations for endpoints, servers, mobile, cloud, network, software, and administrative paths; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 终端、服务器、移动、云、网络、软件和管理路径的角色化安全基线与实际配置 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-4.12-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "4.12",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for observe → evaluate → decide → enforce → verify outcome → rollback/close; alert before each deadline becomes overdue.",
          "zh": "为“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-4.12-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "4.12",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “Platform capabilities differ by OS version and ownership model.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“各 OS 版本与所有权模式能力不同，有些泄漏路径无法完全阻断，需数据最小化或仅浏览器访问。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-4.12-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "4.12",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-4.12-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "4.12",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-4.12-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "4.12",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-4.12-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "4.12",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat unsupported settings, local overrides, inherited cloud policy, vendor defaults, emergency access, safety constraints, drift, and rollback as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 不支持的设置、本地覆盖、继承云策略、厂商默认值、紧急访问、安全约束、漂移和回滚 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-4.12-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "4.12",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Treat audit-only mode, unsupported platforms, local overrides, race conditions, cached state, alternate paths, fail-open behavior, and emergency bypass as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 仅审计模式、不支持平台、本地覆盖、竞态、缓存状态、替代路径、故障开放和紧急绕过 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-4.12-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "4.12",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Move test data through copy/paste, share sheets, open-in, screenshots, notifications, backups, keyboards, accessibility and personal cloud applications; verify intended allow/deny behavior and selective wipe.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“用测试数据遍历复制粘贴、分享、Open-in、截图、通知、备份、键盘、辅助功能和个人云应用，验证预期准入/拒绝与选择性擦除。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-4.12-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "4.12",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-4.12-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "4.12",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 0 pinned CAS metric branch(es), 9 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 0 个指标分支、9 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-4.12-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "4.12",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-4.12-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "4.12",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the versioned secure-configuration authority and exception register plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以版本化安全配置权威库与例外台账和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-4.12-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "4.12",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Publish eligible, enforcing, audit-only, failed, bypassed, excepted, rolled-back, and outcome-verified populations with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 适用、已执行、仅审计、失败、被绕过、例外、已回滚和结果已验证总体，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-4.12-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "4.12",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-4.12-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "4.12",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-4.12-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "4.12",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-4.12-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "4.12",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-4.12-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "4.12",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the versioned secure-configuration authority and exception register; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护版本化安全配置权威库与例外台账的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-4.12-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "4.12",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Restrict authority to change observe → evaluate → decide → enforce → verify outcome → rollback/close; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-4.12-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "4.12",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-4.12-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "4.12",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-4.12-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "4.12",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-4.12-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "4.12",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-4.12-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "4.12",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise approved business behavior, a prohibited setting or service, policy tampering, failed rollout, drift recurrence, and tested rollback through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 获批业务行为、禁止设置或服务、策略篡改、发布失败、漂移复发和已测试回滚，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-4.12-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "4.12",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Run the positive control an approved business action that completes through the enforced path; exercise negative, stale, duplicate, bypass, and outage controls including a prohibited action, alternate path, local override, stale policy, control outage, emergency bypass, and rollback failure.",
          "zh": "运行正向控制“通过受控路径完成的一项获批业务动作”，并执行包含“禁止动作、替代路径、本地覆盖、陈旧策略、控制中断、紧急绕过和回滚失败”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-4.12-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "4.12",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-4.12-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "4.12",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-4.12-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "4.12",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-4.12-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "4.12",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-4.12-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "4.12",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever benchmarks, golden images, configuration management, IaC, MDM, cloud policy, network controllers, drift scans, and change records change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 基准、黄金镜像、配置管理、IaC、MDM、云策略、网络控制器、漂移扫描和变更记录 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-4.12-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "4.12",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Use eligible, enforcing, audit-only, failed, bypassed, excepted, rolled-back, and outcome-verified populations to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 适用、已执行、仅审计、失败、被绕过、例外、已回滚和结果已验证总体 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "5.1",
      "control": 5,
      "title_en": "Establish and Maintain an Inventory of Accounts",
      "title_zh": "账户总账",
      "first_ig": 1,
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Users",
      "security_function": "Identify",
      "patterns": [
        "identity",
        "inventory"
      ],
      "expanded_complexity": true,
      "cas_context": {
        "dependencies": [
          "2.1"
        ],
        "variables": [
          "GV5",
          "GV22",
          "GV23",
          "M1",
          "M2",
          "M3",
          "M4",
          "M5",
          "M6",
          "M7",
          "M8",
          "M9"
        ],
        "metric_branches": 2,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [
        "quarterly"
      ],
      "implementation_contract": {
        "en": {
          "scope": "Include all human, administrator and service accounts in directories, local systems, applications, databases, cloud/SaaS tenants, CI/CD, devices and provider portals, whether interactive, federated, dormant, disabled or emergency.",
          "build": "Reconcile authoritative HR/vendor/workload sources with every authentication system at least quarterly and on lifecycle events.",
          "proof": "Enumerate accounts independently from identity systems and compare both directions to the register.",
          "boundary": "The current CAS formulas divide complete accounts by two and label unauthorized accounts as “accuracy,” producing invalid results."
        },
        "zh": {
          "scope": "包括目录、本地系统、应用、数据库、云/SaaS、CI/CD、设备与服务商门户中的人、管理员和服务账户，无论交互式、联邦、休眠、禁用还是应急。",
          "build": "至少每季度并在生命周期事件上，把 HR/供应商/工作负载权威源与所有认证系统对账。",
          "proof": "独立从身份系统枚举账户，与台账双向比较。",
          "boundary": "CAS 把完整账户数除以 2，并把未授权账户率标成“准确度”，公式无效。"
        }
      },
      "category_counts": {
        "outcome": 8,
        "scope": 8,
        "ownership": 8,
        "data": 8,
        "integration": 8,
        "control": 8,
        "timing": 8,
        "exception": 8,
        "evidence": 8,
        "security": 8,
        "testing": 8,
        "operations": 8
      },
      "requirement_count": 96,
      "requirements": [
        {
          "code": "CIS-5.1-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "5.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Establish and Maintain an Inventory of Accounts; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“账户总账”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-5.1-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "5.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 5.1, official Asset Class Users, Security Function Identify, and IG1 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 5.1、官方资产类别“用户与身份”、安全功能“识别”和首次出现的 IG1，并保存来源抓取日期。"
        },
        {
          "code": "CIS-5.1-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "5.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Include all human, administrator and service accounts in directories, local systems, applications, databases, cloud/SaaS tenants, CI/CD, devices and provider portals, whether interactive, federated, dormant, disabled or emergency.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“包括目录、本地系统、应用、数据库、云/SaaS、CI/CD、设备与服务商门户中的人、管理员和服务账户，无论交互式、联邦、休眠、禁用还是应急。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-5.1-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "5.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-5.1-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "5.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Establish and Maintain an Inventory of Accounts to its operating object—human, administrative, service, workload, device, emergency, provider, and shared or default account identities—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“账户总账”连接到其运营对象——人员、管理员、服务、工作负载、设备、紧急、提供商以及共享或默认账户身份——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-5.1-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "5.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "For Establish and Maintain an Inventory of Accounts, express success as an observable decision over effective identity, authentication, authorization, privilege, session, and revocation state across every access path; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“账户总账”，以 所有访问路径上的实际身份、认证、授权、权限、会话和撤销状态 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-5.1-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "5.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "For Establish and Maintain an Inventory of Accounts, express success as an observable decision over observed, approved, unapproved, ownerless, stale, duplicate, and retired object identity; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“账户总账”，以 已观测、已批准、未批准、无责任人、陈旧、重复和已退役对象身份 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-5.1-OUT-08",
          "local_code": "OUT-08",
          "display_code": "O08",
          "safeguard_id": "5.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "For the expanded Establish and Maintain an Inventory of Accounts scope, resolve conflicts among security, safety, privacy, legal, availability, customer, and operational objectives through an explicit risk decision.",
          "zh": "对“账户总账”的扩展范围，通过显式风险决策解决安全、安全生产、隐私、法律、可用性、客户和运营目标冲突。"
        },
        {
          "code": "CIS-5.1-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "5.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-5.1-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "5.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-5.1-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "5.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-5.1-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "5.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-5.1-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "5.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across dormant, orphaned, shared, default, break-glass, non-interactive, federated, cross-tenant, and ownerless accounts; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 休眠、孤儿、共享、默认、破窗、非交互、联邦、跨租户和无责任人账户 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-5.1-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "5.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Include shared and service identities, nested groups, direct grants, cached sessions, federation gaps, recovery channels, API keys, emergency access, and provider support in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 共享与服务身份、嵌套组、直接授权、缓存会话、联邦缺口、恢复通道、API 密钥、紧急访问和提供商支持 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-5.1-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "5.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Include dormant, ephemeral, disconnected, externally managed, provider-held, aliased, cloned, and cross-tenant objects in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 休眠、短生、离线、外部托管、提供商持有、别名、克隆和跨租户对象 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-5.1-SCP-08",
          "local_code": "SCP-08",
          "display_code": "P08",
          "safeguard_id": "5.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Define nested scope at enterprise, business service, tenant, environment, platform, object, identity, data set, and transaction levels; prohibit a parent result from hiding a failing child.",
          "zh": "按企业、业务服务、租户、环境、平台、对象、身份、数据集和交易定义嵌套范围，禁止父级结果遮蔽失败子级。"
        },
        {
          "code": "CIS-5.1-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "5.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-5.1-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "5.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-5.1-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "5.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-5.1-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "5.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-5.1-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "5.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind identity governance, HR, managers, application and platform owners, PAM operators, service owners, and security to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 身份治理、HR、直属经理、应用与平台责任人、PAM 运营方、服务责任人和安全团队 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-5.1-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "5.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Name who may transition requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-5.1-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "5.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Name who may transition discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-5.1-OWN-08",
          "local_code": "OWN-08",
          "display_code": "W08",
          "safeguard_id": "5.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Model delegated authority, quorum or dual approval where warranted, escalation deadlines, provider handoffs, conflict resolution, and executive risk acceptance.",
          "zh": "建模委派权限、必要时的双人或法定人数审批、升级期限、提供商交接、冲突解决和管理层风险接受。"
        },
        {
          "code": "CIS-5.1-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "5.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-5.1-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "5.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-5.1-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "5.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV5, GV22, GV23, M1, M2, M3, M4, M5, M6, M7, M8, M9) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV5, GV22, GV23, M1, M2, M3, M4, M5, M6, M7, M8, M9）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-5.1-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "5.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-5.1-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "5.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the authoritative account inventory and identity lifecycle as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把权威账户清单与身份生命周期作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-5.1-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "5.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated.",
          "zh": "对生命周期“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-5.1-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "5.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence.",
          "zh": "对生命周期“发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-5.1-DAT-08",
          "local_code": "DAT-08",
          "display_code": "D08",
          "safeguard_id": "5.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Version schemas and state transitions with migration, backfill, deduplication, lineage, historical denominator, deletion, and rollback semantics.",
          "zh": "对模式和状态转换做版本管理，定义迁移、回填、去重、血缘、历史分母、删除和回滚语义。"
        },
        {
          "code": "CIS-5.1-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "5.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 2.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 2.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-5.1-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "5.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-5.1-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "5.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-5.1-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "5.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-5.1-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "5.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile HR/workforce systems, directories, IAM, cloud tenants, PAM, application databases, secrets platforms, provider consoles, and authentication logs and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 HR/人员系统、目录、IAM、云租户、PAM、应用数据库、密钥平台、提供商控制台和认证日志，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-5.1-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "5.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Require every connector carrying effective identity, authentication, authorization, privilege, session, and revocation state across every access path to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 所有访问路径上的实际身份、认证、授权、权限、会话和撤销状态 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-5.1-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "5.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Require every connector carrying observed, approved, unapproved, ownerless, stale, duplicate, and retired object identity to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 已观测、已批准、未批准、无责任人、陈旧、重复和已退役对象身份 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-5.1-INT-08",
          "local_code": "INT-08",
          "display_code": "I08",
          "safeguard_id": "5.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Define consistency rules across disagreeing sources, source precedence, confidence, reconciliation queues, dead-letter handling, reprocessing, and end-to-end trace identity.",
          "zh": "定义冲突来源的一致性、优先级、置信度、对账队列、死信、重处理和端到端追踪身份。"
        },
        {
          "code": "CIS-5.1-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "5.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Reconcile authoritative HR/vendor/workload sources with every authentication system at least quarterly and on lifecycle events.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“至少每季度并在生命周期事件上，把 HR/供应商/工作负载权威源与所有认证系统对账。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-5.1-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "5.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-5.1-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "5.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-5.1-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "5.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-5.1-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "5.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the authoritative account inventory and identity lifecycle and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在权威账户清单与身份生命周期中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-5.1-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "5.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Implement the explicit state machine requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-5.1-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "5.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Implement the explicit state machine discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-5.1-CTL-08",
          "local_code": "CTL-08",
          "display_code": "C08",
          "safeguard_id": "5.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Specify concurrent decisions, partial success, compensating transactions, repeated requests, stale policy, dependency outage, and recovery from an interrupted state transition.",
          "zh": "定义并发决策、部分成功、补偿事务、重复请求、陈旧策略、依赖中断和中途状态转换恢复。"
        },
        {
          "code": "CIS-5.1-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "5.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (quarterly); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（quarterly）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-5.1-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "5.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-5.1-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "5.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-5.1-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "5.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-5.1-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "5.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in human, administrative, service, workload, device, emergency, provider, and shared or default account identities; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 人员、管理员、服务、工作负载、设备、紧急、提供商以及共享或默认账户身份 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-5.1-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "5.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated; alert before each deadline becomes overdue.",
          "zh": "为“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-5.1-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "5.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence; alert before each deadline becomes overdue.",
          "zh": "为“发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-5.1-TIM-08",
          "local_code": "TIM-08",
          "display_code": "T08",
          "safeguard_id": "5.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Allocate an end-to-end SLO budget across discovery, collection, processing, approval, enforcement, verification, and closure; prioritize overdue work by consequence and exposure.",
          "zh": "把端到端 SLO 预算分配到发现、采集、处理、审批、执行、验证和关闭，并按后果与暴露排列逾期工作。"
        },
        {
          "code": "CIS-5.1-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "5.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “The current CAS formulas divide complete accounts by two and label unauthorized accounts as “accuracy,” producing invalid results.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“CAS 把完整账户数除以 2，并把未授权账户率标成“准确度”，公式无效。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-5.1-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "5.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-5.1-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "5.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-5.1-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "5.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-5.1-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "5.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat dormant, orphaned, shared, default, break-glass, non-interactive, federated, cross-tenant, and ownerless accounts as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 休眠、孤儿、共享、默认、破窗、非交互、联邦、跨租户和无责任人账户 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-5.1-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "5.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Treat shared and service identities, nested groups, direct grants, cached sessions, federation gaps, recovery channels, API keys, emergency access, and provider support as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 共享与服务身份、嵌套组、直接授权、缓存会话、联邦缺口、恢复通道、API 密钥、紧急访问和提供商支持 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-5.1-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "5.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Treat dormant, ephemeral, disconnected, externally managed, provider-held, aliased, cloned, and cross-tenant objects as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 休眠、短生、离线、外部托管、提供商持有、别名、克隆和跨租户对象 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-5.1-EXC-08",
          "local_code": "EXC-08",
          "display_code": "X08",
          "safeguard_id": "5.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Exercise compound failures where an exception, stale source, provider outage, unavailable owner, and degraded control overlap; define one safe command and one accountable decision.",
          "zh": "演练例外、陈旧来源、提供商中断、责任人不可用和控制降级同时出现的复合故障，明确一条安全指令和一个责任决策。"
        },
        {
          "code": "CIS-5.1-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "5.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Enumerate accounts independently from identity systems and compare both directions to the register.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“独立从身份系统枚举账户，与台账双向比较。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-5.1-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "5.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-5.1-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "5.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 2 pinned CAS metric branch(es), 12 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 2 个指标分支、12 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-5.1-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "5.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-5.1-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "5.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the authoritative account inventory and identity lifecycle plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以权威账户清单与身份生命周期和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-5.1-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "5.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Publish requested, approved, effective, excessive, orphaned, stale, emergency, revoked-but-active, and independently reviewed rights with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 申请、批准、实际、过度、孤儿、陈旧、紧急、已撤销仍活跃及独立复核权限，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-5.1-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "5.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Publish matched, missing, duplicate, stale, ownerless, unapproved, unevaluable, and retired-without-proof counts with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 匹配、缺失、重复、陈旧、无责任人、未批准、不可评估及无证明退役数量，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-5.1-EVD-08",
          "local_code": "EVD-08",
          "display_code": "E08",
          "safeguard_id": "5.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Require an independent party to reconstruct the decision from source receipts and reproduce the population, state transition, calculation, test result, exception, and final closure.",
          "zh": "要求独立人员使用来源回执重建决策，并复现总体、状态转换、计算、测试结果、例外和最终关闭。"
        },
        {
          "code": "CIS-5.1-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "5.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-5.1-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "5.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-5.1-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "5.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-5.1-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "5.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-5.1-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "5.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the authoritative account inventory and identity lifecycle; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护权威账户清单与身份生命周期的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-5.1-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "5.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Restrict authority to change requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-5.1-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "5.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Restrict authority to change discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-5.1-SEC-08",
          "local_code": "SEC-08",
          "display_code": "S08",
          "safeguard_id": "5.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Threat-model the implementation system itself: forged evidence, poisoned inventory, privilege abuse, cross-tenant confusion, policy rollback, audit deletion, denial of service, and recovery compromise.",
          "zh": "威胁建模实施系统自身：伪造证据、污染清单、权限滥用、跨租户混淆、策略回滚、审计删除、拒绝服务和恢复失陷。"
        },
        {
          "code": "CIS-5.1-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "5.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-5.1-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "5.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-5.1-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "5.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-5.1-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "5.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-5.1-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "5.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise joiner, mover, leaver, dormant and orphan accounts, default credentials, privilege separation, secret rotation, and directory outage through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 入转离、休眠与孤儿账户、默认凭据、权限分离、密钥轮换和目录中断，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-5.1-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "5.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Run the positive control an authorized identity using the required assurance and least privilege; exercise negative, stale, duplicate, bypass, and outage controls including an unauthorized identity, missing factor, stale session, direct grant, inherited excess, revoked token, and recovery bypass.",
          "zh": "运行正向控制“使用所需保证级别和最小权限的授权身份”，并执行包含“未授权身份、缺失认证因子、陈旧会话、直接授权、继承过权、已撤销令牌和恢复绕过”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-5.1-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "5.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Run the positive control a seeded approved object reconciled from two independent sources; exercise negative, stale, duplicate, bypass, and outage controls including an unknown object, duplicate identity, stale record, vanished object, failed source, and cross-tenant collision.",
          "zh": "运行正向控制“从两个独立来源对账的一项植入已批准对象”，并执行包含“未知对象、重复身份、陈旧记录、突然消失对象、失效来源和跨租户碰撞”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-5.1-TST-08",
          "local_code": "TST-08",
          "display_code": "V08",
          "safeguard_id": "5.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Build a pairwise platform-and-failure matrix, then add high-consequence multi-factor cases, historical regression, source substitution, red-team challenge, and assessor replay.",
          "zh": "建立平台—故障两两组合矩阵，再加入高后果多因素案例、历史回归、来源替换、红队挑战和评估方重放。"
        },
        {
          "code": "CIS-5.1-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "5.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-5.1-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "5.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-5.1-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "5.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-5.1-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "5.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-5.1-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "5.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever HR/workforce systems, directories, IAM, cloud tenants, PAM, application databases, secrets platforms, provider consoles, and authentication logs change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 HR/人员系统、目录、IAM、云租户、PAM、应用数据库、密钥平台、提供商控制台和认证日志 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-5.1-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "5.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Use requested, approved, effective, excessive, orphaned, stale, emergency, revoked-but-active, and independently reviewed rights to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 申请、批准、实际、过度、孤儿、陈旧、紧急、已撤销仍活跃及独立复核权限 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-5.1-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "5.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Use matched, missing, duplicate, stale, ownerless, unapproved, unevaluable, and retired-without-proof counts to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 匹配、缺失、重复、陈旧、无责任人、未批准、不可评估及无证明退役数量 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-5.1-OPS-08",
          "local_code": "OPS-08",
          "display_code": "R08",
          "safeguard_id": "5.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Use canary deployment, kill criteria, rollback, backlog burn-down, exception reduction, source-quality targets, quarterly design review, and a measurable retirement plan.",
          "zh": "采用金丝雀、停止标准、回滚、积压燃尽、例外缩减、来源质量目标、季度设计复核和可量化退役计划。"
        }
      ]
    },
    {
      "id": "5.2",
      "control": 5,
      "title_en": "Use Unique Passwords",
      "title_zh": "唯一口令",
      "first_ig": 1,
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Users",
      "security_function": "Protect",
      "patterns": [
        "identity"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [],
        "variables": [
          "GV20",
          "M1",
          "M2",
          "M3",
          "M4",
          "M5"
        ],
        "metric_branches": 2,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "Every password-bearing account must use a secret not reused by another enterprise or personal account; cover users, local admins, devices, applications and break-glass identities.",
          "build": "Use an identity platform/password manager to generate and store unique secrets, block known-compromised and default passwords, rate-limit guessing, and migrate service accounts to managed keys or workload identity.",
          "proof": "Test policy at creation, change, reset and imported-account paths with short, known-breached and reused canary passwords where safe.",
          "boundary": "Uniqueness across systems cannot be proven by reversible comparison without creating risk; enforce generation and monitor exposure instead."
        },
        "zh": {
          "scope": "所有使用口令的账户都要与企业内其他账户及个人账户不复用，覆盖用户、本地管理员、设备、应用和破窗身份。",
          "build": "用身份平台/密码管理器生成、存储唯一秘密，拦截已泄露和默认口令，限制猜测，并把服务账户迁移到受管密钥或工作负载身份。",
          "proof": "在创建、修改、重置与导入路径安全测试短、已泄露和重复金丝雀口令，检查真实强制而非文档；确认 Helpdesk 与旧协议不能绕过长度或 MFA 前提。",
          "boundary": "不能为了证明跨系统唯一而做可逆比对，那会制造泄露风险；应通过生成策略和暴露监测控制。"
        }
      },
      "category_counts": {
        "outcome": 6,
        "scope": 6,
        "ownership": 6,
        "data": 6,
        "integration": 6,
        "control": 6,
        "timing": 6,
        "exception": 6,
        "evidence": 6,
        "security": 6,
        "testing": 6,
        "operations": 6
      },
      "requirement_count": 72,
      "requirements": [
        {
          "code": "CIS-5.2-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "5.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Use Unique Passwords; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“唯一口令”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-5.2-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "5.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 5.2, official Asset Class Users, Security Function Protect, and IG1 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 5.2、官方资产类别“用户与身份”、安全功能“保护”和首次出现的 IG1，并保存来源抓取日期。"
        },
        {
          "code": "CIS-5.2-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "5.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Every password-bearing account must use a secret not reused by another enterprise or personal account; cover users, local admins, devices, applications and break-glass identities.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“所有使用口令的账户都要与企业内其他账户及个人账户不复用，覆盖用户、本地管理员、设备、应用和破窗身份。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-5.2-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "5.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-5.2-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "5.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Use Unique Passwords to its operating object—human, administrative, service, workload, device, emergency, provider, and shared or default account identities—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“唯一口令”连接到其运营对象——人员、管理员、服务、工作负载、设备、紧急、提供商以及共享或默认账户身份——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-5.2-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "5.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "For Use Unique Passwords, express success as an observable decision over effective identity, authentication, authorization, privilege, session, and revocation state across every access path; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“唯一口令”，以 所有访问路径上的实际身份、认证、授权、权限、会话和撤销状态 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-5.2-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "5.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-5.2-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "5.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-5.2-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "5.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-5.2-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "5.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-5.2-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "5.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across dormant, orphaned, shared, default, break-glass, non-interactive, federated, cross-tenant, and ownerless accounts; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 休眠、孤儿、共享、默认、破窗、非交互、联邦、跨租户和无责任人账户 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-5.2-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "5.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Include shared and service identities, nested groups, direct grants, cached sessions, federation gaps, recovery channels, API keys, emergency access, and provider support in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 共享与服务身份、嵌套组、直接授权、缓存会话、联邦缺口、恢复通道、API 密钥、紧急访问和提供商支持 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-5.2-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "5.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-5.2-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "5.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-5.2-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "5.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-5.2-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "5.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-5.2-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "5.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind identity governance, HR, managers, application and platform owners, PAM operators, service owners, and security to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 身份治理、HR、直属经理、应用与平台责任人、PAM 运营方、服务责任人和安全团队 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-5.2-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "5.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Name who may transition requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-5.2-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "5.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-5.2-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "5.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-5.2-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "5.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV20, M1, M2, M3, M4, M5) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV20, M1, M2, M3, M4, M5）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-5.2-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "5.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-5.2-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "5.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the authoritative account inventory and identity lifecycle as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把权威账户清单与身份生命周期作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-5.2-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "5.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated.",
          "zh": "对生命周期“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-5.2-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "5.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for no explicit predecessor in the pinned CAS page; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 固定 CAS 页面没有列出显式前置项 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-5.2-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "5.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-5.2-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "5.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-5.2-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "5.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-5.2-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "5.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile HR/workforce systems, directories, IAM, cloud tenants, PAM, application databases, secrets platforms, provider consoles, and authentication logs and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 HR/人员系统、目录、IAM、云租户、PAM、应用数据库、密钥平台、提供商控制台和认证日志，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-5.2-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "5.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Require every connector carrying effective identity, authentication, authorization, privilege, session, and revocation state across every access path to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 所有访问路径上的实际身份、认证、授权、权限、会话和撤销状态 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-5.2-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "5.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Use an identity platform/password manager to generate and store unique secrets, block known-compromised and default passwords, rate-limit guessing, and migrate service accounts to managed keys or workload identity.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“用身份平台/密码管理器生成、存储唯一秘密，拦截已泄露和默认口令，限制猜测，并把服务账户迁移到受管密钥或工作负载身份。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-5.2-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "5.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-5.2-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "5.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-5.2-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "5.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-5.2-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "5.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the authoritative account inventory and identity lifecycle and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在权威账户清单与身份生命周期中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-5.2-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "5.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Implement the explicit state machine requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-5.2-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "5.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-5.2-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "5.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-5.2-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "5.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-5.2-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "5.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-5.2-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "5.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in human, administrative, service, workload, device, emergency, provider, and shared or default account identities; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 人员、管理员、服务、工作负载、设备、紧急、提供商以及共享或默认账户身份 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-5.2-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "5.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated; alert before each deadline becomes overdue.",
          "zh": "为“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-5.2-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "5.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “Uniqueness across systems cannot be proven by reversible comparison without creating risk; enforce generation and monitor exposure instead.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“不能为了证明跨系统唯一而做可逆比对，那会制造泄露风险；应通过生成策略和暴露监测控制。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-5.2-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "5.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-5.2-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "5.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-5.2-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "5.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-5.2-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "5.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat dormant, orphaned, shared, default, break-glass, non-interactive, federated, cross-tenant, and ownerless accounts as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 休眠、孤儿、共享、默认、破窗、非交互、联邦、跨租户和无责任人账户 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-5.2-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "5.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Treat shared and service identities, nested groups, direct grants, cached sessions, federation gaps, recovery channels, API keys, emergency access, and provider support as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 共享与服务身份、嵌套组、直接授权、缓存会话、联邦缺口、恢复通道、API 密钥、紧急访问和提供商支持 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-5.2-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "5.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Test policy at creation, change, reset and imported-account paths with short, known-breached and reused canary passwords where safe.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“在创建、修改、重置与导入路径安全测试短、已泄露和重复金丝雀口令，检查真实强制而非文档；确认 Helpdesk 与旧协议不能绕过长度或 MFA 前提。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-5.2-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "5.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-5.2-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "5.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 2 pinned CAS metric branch(es), 6 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 2 个指标分支、6 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-5.2-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "5.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-5.2-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "5.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the authoritative account inventory and identity lifecycle plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以权威账户清单与身份生命周期和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-5.2-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "5.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Publish requested, approved, effective, excessive, orphaned, stale, emergency, revoked-but-active, and independently reviewed rights with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 申请、批准、实际、过度、孤儿、陈旧、紧急、已撤销仍活跃及独立复核权限，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-5.2-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "5.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-5.2-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "5.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-5.2-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "5.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-5.2-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "5.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-5.2-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "5.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the authoritative account inventory and identity lifecycle; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护权威账户清单与身份生命周期的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-5.2-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "5.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Restrict authority to change requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-5.2-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "5.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-5.2-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "5.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-5.2-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "5.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-5.2-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "5.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-5.2-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "5.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise joiner, mover, leaver, dormant and orphan accounts, default credentials, privilege separation, secret rotation, and directory outage through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 入转离、休眠与孤儿账户、默认凭据、权限分离、密钥轮换和目录中断，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-5.2-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "5.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Run the positive control an authorized identity using the required assurance and least privilege; exercise negative, stale, duplicate, bypass, and outage controls including an unauthorized identity, missing factor, stale session, direct grant, inherited excess, revoked token, and recovery bypass.",
          "zh": "运行正向控制“使用所需保证级别和最小权限的授权身份”，并执行包含“未授权身份、缺失认证因子、陈旧会话、直接授权、继承过权、已撤销令牌和恢复绕过”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-5.2-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "5.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-5.2-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "5.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-5.2-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "5.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-5.2-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "5.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-5.2-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "5.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever HR/workforce systems, directories, IAM, cloud tenants, PAM, application databases, secrets platforms, provider consoles, and authentication logs change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 HR/人员系统、目录、IAM、云租户、PAM、应用数据库、密钥平台、提供商控制台和认证日志 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-5.2-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "5.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Use requested, approved, effective, excessive, orphaned, stale, emergency, revoked-but-active, and independently reviewed rights to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 申请、批准、实际、过度、孤儿、陈旧、紧急、已撤销仍活跃及独立复核权限 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "5.3",
      "control": 5,
      "title_en": "Disable Dormant Accounts",
      "title_zh": "休眠账户",
      "first_ig": 1,
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Users",
      "security_function": "Protect",
      "patterns": [
        "identity",
        "enforcement"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "5.1"
        ],
        "variables": [
          "GV22",
          "M1",
          "M2",
          "M3",
          "M4",
          "M5",
          "M6"
        ],
        "metric_branches": 2,
        "has_assumptions": true,
        "has_procedural_review": false
      },
      "official_cadence_terms": [
        "45 days"
      ],
      "implementation_contract": {
        "en": {
          "scope": "The population includes enabled human, administrative, guest, local, cloud, SaaS and service identities whose last meaningful activity can be determined.",
          "build": "Define activity per account type, calculate dormancy from reliable sign-in/use events, notify owners, disable before deletion and preserve audit links.",
          "proof": "Create a canary account, advance or simulate inactivity, and verify notification, disablement, session/token revocation and blocked sign-in.",
          "boundary": "A password change, background token refresh or failed login may falsely appear active; an account can also remain dangerous while never signing in."
        },
        "zh": {
          "scope": "包括启用的人、管理员、Guest、本地、云、SaaS 和服务身份，只要能可靠定义最后“有意义活动”。",
          "build": "按账户类型定义活动，使用可信登录/使用事件算休眠，通知责任人，先禁用后删除并保留审计关联。",
          "proof": "创建金丝雀账户，推进或模拟无活动，验证通知、禁用、会话/Token 撤销和登录阻断。",
          "boundary": "改口令、后台刷新 Token 或失败登录可能假装“活跃”，账户即使从未登录也可能危险。"
        }
      },
      "category_counts": {
        "outcome": 7,
        "scope": 7,
        "ownership": 7,
        "data": 7,
        "integration": 7,
        "control": 7,
        "timing": 7,
        "exception": 7,
        "evidence": 7,
        "security": 7,
        "testing": 7,
        "operations": 7
      },
      "requirement_count": 84,
      "requirements": [
        {
          "code": "CIS-5.3-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "5.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Disable Dormant Accounts; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“休眠账户”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-5.3-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "5.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 5.3, official Asset Class Users, Security Function Protect, and IG1 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 5.3、官方资产类别“用户与身份”、安全功能“保护”和首次出现的 IG1，并保存来源抓取日期。"
        },
        {
          "code": "CIS-5.3-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "5.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “The population includes enabled human, administrative, guest, local, cloud, SaaS and service identities whose last meaningful activity can be determined.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“包括启用的人、管理员、Guest、本地、云、SaaS 和服务身份，只要能可靠定义最后“有意义活动”。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-5.3-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "5.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-5.3-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "5.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Disable Dormant Accounts to its operating object—human, administrative, service, workload, device, emergency, provider, and shared or default account identities—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“休眠账户”连接到其运营对象——人员、管理员、服务、工作负载、设备、紧急、提供商以及共享或默认账户身份——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-5.3-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "5.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "For Disable Dormant Accounts, express success as an observable decision over effective identity, authentication, authorization, privilege, session, and revocation state across every access path; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“休眠账户”，以 所有访问路径上的实际身份、认证、授权、权限、会话和撤销状态 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-5.3-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "5.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "For Disable Dormant Accounts, express success as an observable decision over an enforceable allow, deny, contain, quarantine, require, remove, or transform decision at the closest reliable control point; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“休眠账户”，以 在最近可靠控制点执行允许、拒绝、遏制、隔离、强制、移除或转换决策 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-5.3-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "5.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-5.3-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "5.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-5.3-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "5.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-5.3-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "5.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-5.3-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "5.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across dormant, orphaned, shared, default, break-glass, non-interactive, federated, cross-tenant, and ownerless accounts; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 休眠、孤儿、共享、默认、破窗、非交互、联邦、跨租户和无责任人账户 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-5.3-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "5.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Include shared and service identities, nested groups, direct grants, cached sessions, federation gaps, recovery channels, API keys, emergency access, and provider support in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 共享与服务身份、嵌套组、直接授权、缓存会话、联邦缺口、恢复通道、API 密钥、紧急访问和提供商支持 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-5.3-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "5.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Include audit-only mode, unsupported platforms, local overrides, race conditions, cached state, alternate paths, fail-open behavior, and emergency bypass in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 仅审计模式、不支持平台、本地覆盖、竞态、缓存状态、替代路径、故障开放和紧急绕过 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-5.3-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "5.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-5.3-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "5.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-5.3-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "5.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-5.3-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "5.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-5.3-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "5.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind identity governance, HR, managers, application and platform owners, PAM operators, service owners, and security to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 身份治理、HR、直属经理、应用与平台责任人、PAM 运营方、服务责任人和安全团队 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-5.3-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "5.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Name who may transition requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-5.3-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "5.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Name who may transition observe → evaluate → decide → enforce → verify outcome → rollback/close, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-5.3-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "5.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-5.3-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "5.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-5.3-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "5.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV22, M1, M2, M3, M4, M5, M6) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV22, M1, M2, M3, M4, M5, M6）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-5.3-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "5.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-5.3-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "5.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the authoritative account inventory and identity lifecycle as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把权威账户清单与身份生命周期作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-5.3-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "5.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated.",
          "zh": "对生命周期“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-5.3-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "5.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle observe → evaluate → decide → enforce → verify outcome → rollback/close.",
          "zh": "对生命周期“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-5.3-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "5.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 5.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 5.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-5.3-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "5.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-5.3-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "5.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-5.3-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "5.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-5.3-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "5.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile HR/workforce systems, directories, IAM, cloud tenants, PAM, application databases, secrets platforms, provider consoles, and authentication logs and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 HR/人员系统、目录、IAM、云租户、PAM、应用数据库、密钥平台、提供商控制台和认证日志，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-5.3-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "5.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Require every connector carrying effective identity, authentication, authorization, privilege, session, and revocation state across every access path to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 所有访问路径上的实际身份、认证、授权、权限、会话和撤销状态 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-5.3-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "5.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Require every connector carrying an enforceable allow, deny, contain, quarantine, require, remove, or transform decision at the closest reliable control point to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 在最近可靠控制点执行允许、拒绝、遏制、隔离、强制、移除或转换决策 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-5.3-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "5.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Define activity per account type, calculate dormancy from reliable sign-in/use events, notify owners, disable before deletion and preserve audit links.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“按账户类型定义活动，使用可信登录/使用事件算休眠，通知责任人，先禁用后删除并保留审计关联。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-5.3-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "5.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-5.3-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "5.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-5.3-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "5.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-5.3-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "5.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the authoritative account inventory and identity lifecycle and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在权威账户清单与身份生命周期中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-5.3-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "5.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Implement the explicit state machine requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-5.3-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "5.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Implement the explicit state machine observe → evaluate → decide → enforce → verify outcome → rollback/close; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-5.3-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "5.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (45 days); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（45 days）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-5.3-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "5.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-5.3-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "5.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-5.3-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "5.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-5.3-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "5.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in human, administrative, service, workload, device, emergency, provider, and shared or default account identities; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 人员、管理员、服务、工作负载、设备、紧急、提供商以及共享或默认账户身份 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-5.3-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "5.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated; alert before each deadline becomes overdue.",
          "zh": "为“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-5.3-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "5.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for observe → evaluate → decide → enforce → verify outcome → rollback/close; alert before each deadline becomes overdue.",
          "zh": "为“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-5.3-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "5.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “A password change, background token refresh or failed login may falsely appear active; an account can also remain dangerous while never signing in.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“改口令、后台刷新 Token 或失败登录可能假装“活跃”，账户即使从未登录也可能危险。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-5.3-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "5.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-5.3-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "5.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-5.3-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "5.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-5.3-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "5.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat dormant, orphaned, shared, default, break-glass, non-interactive, federated, cross-tenant, and ownerless accounts as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 休眠、孤儿、共享、默认、破窗、非交互、联邦、跨租户和无责任人账户 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-5.3-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "5.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Treat shared and service identities, nested groups, direct grants, cached sessions, federation gaps, recovery channels, API keys, emergency access, and provider support as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 共享与服务身份、嵌套组、直接授权、缓存会话、联邦缺口、恢复通道、API 密钥、紧急访问和提供商支持 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-5.3-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "5.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Treat audit-only mode, unsupported platforms, local overrides, race conditions, cached state, alternate paths, fail-open behavior, and emergency bypass as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 仅审计模式、不支持平台、本地覆盖、竞态、缓存状态、替代路径、故障开放和紧急绕过 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-5.3-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "5.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Create a canary account, advance or simulate inactivity, and verify notification, disablement, session/token revocation and blocked sign-in.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“创建金丝雀账户，推进或模拟无活动，验证通知、禁用、会话/Token 撤销和登录阻断。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-5.3-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "5.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-5.3-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "5.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 2 pinned CAS metric branch(es), 7 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 2 个指标分支、7 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-5.3-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "5.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-5.3-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "5.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the authoritative account inventory and identity lifecycle plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以权威账户清单与身份生命周期和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-5.3-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "5.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Publish requested, approved, effective, excessive, orphaned, stale, emergency, revoked-but-active, and independently reviewed rights with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 申请、批准、实际、过度、孤儿、陈旧、紧急、已撤销仍活跃及独立复核权限，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-5.3-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "5.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Publish eligible, enforcing, audit-only, failed, bypassed, excepted, rolled-back, and outcome-verified populations with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 适用、已执行、仅审计、失败、被绕过、例外、已回滚和结果已验证总体，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-5.3-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "5.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-5.3-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "5.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-5.3-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "5.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-5.3-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "5.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-5.3-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "5.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the authoritative account inventory and identity lifecycle; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护权威账户清单与身份生命周期的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-5.3-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "5.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Restrict authority to change requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-5.3-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "5.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Restrict authority to change observe → evaluate → decide → enforce → verify outcome → rollback/close; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-5.3-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "5.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-5.3-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "5.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-5.3-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "5.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-5.3-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "5.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-5.3-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "5.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise joiner, mover, leaver, dormant and orphan accounts, default credentials, privilege separation, secret rotation, and directory outage through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 入转离、休眠与孤儿账户、默认凭据、权限分离、密钥轮换和目录中断，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-5.3-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "5.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Run the positive control an authorized identity using the required assurance and least privilege; exercise negative, stale, duplicate, bypass, and outage controls including an unauthorized identity, missing factor, stale session, direct grant, inherited excess, revoked token, and recovery bypass.",
          "zh": "运行正向控制“使用所需保证级别和最小权限的授权身份”，并执行包含“未授权身份、缺失认证因子、陈旧会话、直接授权、继承过权、已撤销令牌和恢复绕过”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-5.3-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "5.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Run the positive control an approved business action that completes through the enforced path; exercise negative, stale, duplicate, bypass, and outage controls including a prohibited action, alternate path, local override, stale policy, control outage, emergency bypass, and rollback failure.",
          "zh": "运行正向控制“通过受控路径完成的一项获批业务动作”，并执行包含“禁止动作、替代路径、本地覆盖、陈旧策略、控制中断、紧急绕过和回滚失败”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-5.3-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "5.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-5.3-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "5.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-5.3-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "5.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-5.3-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "5.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-5.3-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "5.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever HR/workforce systems, directories, IAM, cloud tenants, PAM, application databases, secrets platforms, provider consoles, and authentication logs change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 HR/人员系统、目录、IAM、云租户、PAM、应用数据库、密钥平台、提供商控制台和认证日志 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-5.3-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "5.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Use requested, approved, effective, excessive, orphaned, stale, emergency, revoked-but-active, and independently reviewed rights to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 申请、批准、实际、过度、孤儿、陈旧、紧急、已撤销仍活跃及独立复核权限 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-5.3-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "5.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Use eligible, enforcing, audit-only, failed, bypassed, excepted, rolled-back, and outcome-verified populations to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 适用、已执行、仅审计、失败、被绕过、例外、已回滚和结果已验证总体 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "5.4",
      "control": 5,
      "title_en": "Restrict Administrator Privileges to Dedicated Administrator Accounts",
      "title_zh": "专用管理员账户",
      "first_ig": 1,
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Users",
      "security_function": "Protect",
      "patterns": [
        "identity",
        "enforcement"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "5.1"
        ],
        "variables": [
          "GV22",
          "M1",
          "M2",
          "M3",
          "M4",
          "M5",
          "M6"
        ],
        "metric_branches": 2,
        "has_assumptions": true,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "Cover every human with elevated authority across endpoint, server, network, cloud, SaaS, database, CI/CD and security tooling.",
          "build": "Issue named dedicated admin accounts, require strong MFA and privileged workstations or paths, remove elevation from daily accounts, and use just-in-time or task-scoped privilege where possible.",
          "proof": "Attempt ordinary email/web access from an admin identity, administrative action from the daily identity, and cross-tier access; verify policy and alerts.",
          "boundary": "A dedicated username used on the same contaminated workstation offers limited separation."
        },
        "zh": {
          "scope": "覆盖终端、服务器、网络、云、SaaS、数据库、CI/CD 和安全工具上的每个人工高权限路径。",
          "build": "发放实名专用管理员账户，要求强 MFA 和特权工作站/路径，从日常账户移除提权；尽可能使用 JIT/任务级权限。",
          "proof": "从管理员身份尝试普通邮件/Web，从日常身份尝试管理，并测试跨层访问；验证策略和告警。",
          "boundary": "在同一已污染日常设备里换个用户名，隔离很弱。"
        }
      },
      "category_counts": {
        "outcome": 7,
        "scope": 7,
        "ownership": 7,
        "data": 7,
        "integration": 7,
        "control": 7,
        "timing": 7,
        "exception": 7,
        "evidence": 7,
        "security": 7,
        "testing": 7,
        "operations": 7
      },
      "requirement_count": 84,
      "requirements": [
        {
          "code": "CIS-5.4-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "5.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Restrict Administrator Privileges to Dedicated Administrator Accounts; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“专用管理员账户”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-5.4-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "5.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 5.4, official Asset Class Users, Security Function Protect, and IG1 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 5.4、官方资产类别“用户与身份”、安全功能“保护”和首次出现的 IG1，并保存来源抓取日期。"
        },
        {
          "code": "CIS-5.4-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "5.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Cover every human with elevated authority across endpoint, server, network, cloud, SaaS, database, CI/CD and security tooling.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“覆盖终端、服务器、网络、云、SaaS、数据库、CI/CD 和安全工具上的每个人工高权限路径。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-5.4-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "5.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-5.4-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "5.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Restrict Administrator Privileges to Dedicated Administrator Accounts to its operating object—human, administrative, service, workload, device, emergency, provider, and shared or default account identities—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“专用管理员账户”连接到其运营对象——人员、管理员、服务、工作负载、设备、紧急、提供商以及共享或默认账户身份——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-5.4-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "5.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "For Restrict Administrator Privileges to Dedicated Administrator Accounts, express success as an observable decision over effective identity, authentication, authorization, privilege, session, and revocation state across every access path; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“专用管理员账户”，以 所有访问路径上的实际身份、认证、授权、权限、会话和撤销状态 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-5.4-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "5.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "For Restrict Administrator Privileges to Dedicated Administrator Accounts, express success as an observable decision over an enforceable allow, deny, contain, quarantine, require, remove, or transform decision at the closest reliable control point; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“专用管理员账户”，以 在最近可靠控制点执行允许、拒绝、遏制、隔离、强制、移除或转换决策 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-5.4-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "5.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-5.4-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "5.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-5.4-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "5.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-5.4-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "5.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-5.4-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "5.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across dormant, orphaned, shared, default, break-glass, non-interactive, federated, cross-tenant, and ownerless accounts; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 休眠、孤儿、共享、默认、破窗、非交互、联邦、跨租户和无责任人账户 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-5.4-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "5.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Include shared and service identities, nested groups, direct grants, cached sessions, federation gaps, recovery channels, API keys, emergency access, and provider support in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 共享与服务身份、嵌套组、直接授权、缓存会话、联邦缺口、恢复通道、API 密钥、紧急访问和提供商支持 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-5.4-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "5.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Include audit-only mode, unsupported platforms, local overrides, race conditions, cached state, alternate paths, fail-open behavior, and emergency bypass in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 仅审计模式、不支持平台、本地覆盖、竞态、缓存状态、替代路径、故障开放和紧急绕过 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-5.4-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "5.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-5.4-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "5.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-5.4-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "5.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-5.4-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "5.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-5.4-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "5.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind identity governance, HR, managers, application and platform owners, PAM operators, service owners, and security to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 身份治理、HR、直属经理、应用与平台责任人、PAM 运营方、服务责任人和安全团队 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-5.4-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "5.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Name who may transition requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-5.4-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "5.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Name who may transition observe → evaluate → decide → enforce → verify outcome → rollback/close, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-5.4-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "5.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-5.4-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "5.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-5.4-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "5.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV22, M1, M2, M3, M4, M5, M6) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV22, M1, M2, M3, M4, M5, M6）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-5.4-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "5.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-5.4-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "5.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the authoritative account inventory and identity lifecycle as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把权威账户清单与身份生命周期作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-5.4-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "5.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated.",
          "zh": "对生命周期“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-5.4-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "5.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle observe → evaluate → decide → enforce → verify outcome → rollback/close.",
          "zh": "对生命周期“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-5.4-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "5.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 5.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 5.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-5.4-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "5.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-5.4-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "5.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-5.4-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "5.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-5.4-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "5.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile HR/workforce systems, directories, IAM, cloud tenants, PAM, application databases, secrets platforms, provider consoles, and authentication logs and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 HR/人员系统、目录、IAM、云租户、PAM、应用数据库、密钥平台、提供商控制台和认证日志，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-5.4-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "5.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Require every connector carrying effective identity, authentication, authorization, privilege, session, and revocation state across every access path to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 所有访问路径上的实际身份、认证、授权、权限、会话和撤销状态 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-5.4-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "5.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Require every connector carrying an enforceable allow, deny, contain, quarantine, require, remove, or transform decision at the closest reliable control point to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 在最近可靠控制点执行允许、拒绝、遏制、隔离、强制、移除或转换决策 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-5.4-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "5.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Issue named dedicated admin accounts, require strong MFA and privileged workstations or paths, remove elevation from daily accounts, and use just-in-time or task-scoped privilege where possible.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“发放实名专用管理员账户，要求强 MFA 和特权工作站/路径，从日常账户移除提权；尽可能使用 JIT/任务级权限。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-5.4-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "5.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-5.4-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "5.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-5.4-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "5.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-5.4-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "5.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the authoritative account inventory and identity lifecycle and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在权威账户清单与身份生命周期中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-5.4-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "5.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Implement the explicit state machine requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-5.4-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "5.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Implement the explicit state machine observe → evaluate → decide → enforce → verify outcome → rollback/close; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-5.4-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "5.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-5.4-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "5.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-5.4-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "5.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-5.4-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "5.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-5.4-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "5.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in human, administrative, service, workload, device, emergency, provider, and shared or default account identities; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 人员、管理员、服务、工作负载、设备、紧急、提供商以及共享或默认账户身份 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-5.4-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "5.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated; alert before each deadline becomes overdue.",
          "zh": "为“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-5.4-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "5.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for observe → evaluate → decide → enforce → verify outcome → rollback/close; alert before each deadline becomes overdue.",
          "zh": "为“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-5.4-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "5.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “A dedicated username used on the same contaminated workstation offers limited separation.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“在同一已污染日常设备里换个用户名，隔离很弱。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-5.4-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "5.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-5.4-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "5.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-5.4-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "5.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-5.4-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "5.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat dormant, orphaned, shared, default, break-glass, non-interactive, federated, cross-tenant, and ownerless accounts as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 休眠、孤儿、共享、默认、破窗、非交互、联邦、跨租户和无责任人账户 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-5.4-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "5.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Treat shared and service identities, nested groups, direct grants, cached sessions, federation gaps, recovery channels, API keys, emergency access, and provider support as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 共享与服务身份、嵌套组、直接授权、缓存会话、联邦缺口、恢复通道、API 密钥、紧急访问和提供商支持 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-5.4-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "5.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Treat audit-only mode, unsupported platforms, local overrides, race conditions, cached state, alternate paths, fail-open behavior, and emergency bypass as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 仅审计模式、不支持平台、本地覆盖、竞态、缓存状态、替代路径、故障开放和紧急绕过 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-5.4-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "5.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Attempt ordinary email/web access from an admin identity, administrative action from the daily identity, and cross-tier access; verify policy and alerts.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“从管理员身份尝试普通邮件/Web，从日常身份尝试管理，并测试跨层访问；验证策略和告警。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-5.4-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "5.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-5.4-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "5.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 2 pinned CAS metric branch(es), 7 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 2 个指标分支、7 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-5.4-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "5.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-5.4-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "5.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the authoritative account inventory and identity lifecycle plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以权威账户清单与身份生命周期和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-5.4-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "5.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Publish requested, approved, effective, excessive, orphaned, stale, emergency, revoked-but-active, and independently reviewed rights with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 申请、批准、实际、过度、孤儿、陈旧、紧急、已撤销仍活跃及独立复核权限，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-5.4-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "5.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Publish eligible, enforcing, audit-only, failed, bypassed, excepted, rolled-back, and outcome-verified populations with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 适用、已执行、仅审计、失败、被绕过、例外、已回滚和结果已验证总体，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-5.4-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "5.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-5.4-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "5.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-5.4-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "5.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-5.4-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "5.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-5.4-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "5.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the authoritative account inventory and identity lifecycle; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护权威账户清单与身份生命周期的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-5.4-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "5.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Restrict authority to change requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-5.4-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "5.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Restrict authority to change observe → evaluate → decide → enforce → verify outcome → rollback/close; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-5.4-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "5.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-5.4-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "5.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-5.4-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "5.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-5.4-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "5.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-5.4-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "5.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise joiner, mover, leaver, dormant and orphan accounts, default credentials, privilege separation, secret rotation, and directory outage through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 入转离、休眠与孤儿账户、默认凭据、权限分离、密钥轮换和目录中断，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-5.4-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "5.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Run the positive control an authorized identity using the required assurance and least privilege; exercise negative, stale, duplicate, bypass, and outage controls including an unauthorized identity, missing factor, stale session, direct grant, inherited excess, revoked token, and recovery bypass.",
          "zh": "运行正向控制“使用所需保证级别和最小权限的授权身份”，并执行包含“未授权身份、缺失认证因子、陈旧会话、直接授权、继承过权、已撤销令牌和恢复绕过”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-5.4-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "5.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Run the positive control an approved business action that completes through the enforced path; exercise negative, stale, duplicate, bypass, and outage controls including a prohibited action, alternate path, local override, stale policy, control outage, emergency bypass, and rollback failure.",
          "zh": "运行正向控制“通过受控路径完成的一项获批业务动作”，并执行包含“禁止动作、替代路径、本地覆盖、陈旧策略、控制中断、紧急绕过和回滚失败”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-5.4-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "5.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-5.4-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "5.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-5.4-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "5.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-5.4-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "5.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-5.4-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "5.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever HR/workforce systems, directories, IAM, cloud tenants, PAM, application databases, secrets platforms, provider consoles, and authentication logs change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 HR/人员系统、目录、IAM、云租户、PAM、应用数据库、密钥平台、提供商控制台和认证日志 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-5.4-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "5.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Use requested, approved, effective, excessive, orphaned, stale, emergency, revoked-but-active, and independently reviewed rights to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 申请、批准、实际、过度、孤儿、陈旧、紧急、已撤销仍活跃及独立复核权限 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-5.4-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "5.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Use eligible, enforcing, audit-only, failed, bypassed, excepted, rolled-back, and outcome-verified populations to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 适用、已执行、仅审计、失败、被绕过、例外、已回滚和结果已验证总体 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "5.5",
      "control": 5,
      "title_en": "Establish and Maintain an Inventory of Service Accounts",
      "title_zh": "服务账户总账",
      "first_ig": 2,
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Users",
      "security_function": "Identify",
      "patterns": [
        "identity",
        "inventory"
      ],
      "expanded_complexity": true,
      "cas_context": {
        "dependencies": [
          "6.6"
        ],
        "variables": [
          "GV23",
          "M1",
          "M2",
          "M3",
          "M4",
          "M5",
          "M6",
          "M7",
          "M8",
          "M9"
        ],
        "metric_branches": 2,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [
        "quarterly"
      ],
      "implementation_contract": {
        "en": {
          "scope": "Include non-human identities used by services, workloads, jobs, devices, integrations, bots, RPA, APIs and CI/CD across directories, clouds, SaaS and local systems, including certificates, API keys and federated workload roles.",
          "build": "Record owner/team, workload and environment, purpose, privilege, authentication system, credential type/location, creation, rotation/expiry, dependencies and quarterly review.",
          "proof": "Enumerate non-human identities and credentials from each authentication/secret system, compare to deployed workloads and owners, and rotate/revoke a canary without outage.",
          "boundary": "The current CAS repeats the invalid inventory formulas from 5.1 and even tests three required fields against four."
        },
        "zh": {
          "scope": "包括服务、工作负载、Job、设备、集成、Bot、RPA、API 与 CI/CD 在目录、云、SaaS 和本地使用的非人身份，包括证书、API Key 与联邦角色。",
          "build": "记录责任团队、工作负载/环境、用途、权限、认证系统、凭据类型/位置、创建、轮换/到期、依赖和季度复核；优先短期工作负载身份和自动轮换，发放绑定部署并随服务退役。",
          "proof": "从每个认证/秘密系统枚举非人身份和凭据，与部署工作负载/责任人对账；轮换或撤销金丝雀，确认旧秘密失效，错误工作负载/环境使用会告警。",
          "boundary": "CAS 重复 5.1 的无效公式，且三项必需字段却按四项算。"
        }
      },
      "category_counts": {
        "outcome": 8,
        "scope": 8,
        "ownership": 8,
        "data": 8,
        "integration": 8,
        "control": 8,
        "timing": 8,
        "exception": 8,
        "evidence": 8,
        "security": 8,
        "testing": 8,
        "operations": 8
      },
      "requirement_count": 96,
      "requirements": [
        {
          "code": "CIS-5.5-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "5.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Establish and Maintain an Inventory of Service Accounts; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“服务账户总账”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-5.5-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "5.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 5.5, official Asset Class Users, Security Function Identify, and IG2 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 5.5、官方资产类别“用户与身份”、安全功能“识别”和首次出现的 IG2，并保存来源抓取日期。"
        },
        {
          "code": "CIS-5.5-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "5.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Include non-human identities used by services, workloads, jobs, devices, integrations, bots, RPA, APIs and CI/CD across directories, clouds, SaaS and local systems, including certificates, API keys and federated workload roles.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“包括服务、工作负载、Job、设备、集成、Bot、RPA、API 与 CI/CD 在目录、云、SaaS 和本地使用的非人身份，包括证书、API Key 与联邦角色。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-5.5-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "5.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-5.5-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "5.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Establish and Maintain an Inventory of Service Accounts to its operating object—human, administrative, service, workload, device, emergency, provider, and shared or default account identities—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“服务账户总账”连接到其运营对象——人员、管理员、服务、工作负载、设备、紧急、提供商以及共享或默认账户身份——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-5.5-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "5.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "For Establish and Maintain an Inventory of Service Accounts, express success as an observable decision over effective identity, authentication, authorization, privilege, session, and revocation state across every access path; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“服务账户总账”，以 所有访问路径上的实际身份、认证、授权、权限、会话和撤销状态 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-5.5-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "5.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "For Establish and Maintain an Inventory of Service Accounts, express success as an observable decision over observed, approved, unapproved, ownerless, stale, duplicate, and retired object identity; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“服务账户总账”，以 已观测、已批准、未批准、无责任人、陈旧、重复和已退役对象身份 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-5.5-OUT-08",
          "local_code": "OUT-08",
          "display_code": "O08",
          "safeguard_id": "5.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "For the expanded Establish and Maintain an Inventory of Service Accounts scope, resolve conflicts among security, safety, privacy, legal, availability, customer, and operational objectives through an explicit risk decision.",
          "zh": "对“服务账户总账”的扩展范围，通过显式风险决策解决安全、安全生产、隐私、法律、可用性、客户和运营目标冲突。"
        },
        {
          "code": "CIS-5.5-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "5.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-5.5-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "5.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-5.5-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "5.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-5.5-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "5.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-5.5-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "5.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across dormant, orphaned, shared, default, break-glass, non-interactive, federated, cross-tenant, and ownerless accounts; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 休眠、孤儿、共享、默认、破窗、非交互、联邦、跨租户和无责任人账户 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-5.5-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "5.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Include shared and service identities, nested groups, direct grants, cached sessions, federation gaps, recovery channels, API keys, emergency access, and provider support in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 共享与服务身份、嵌套组、直接授权、缓存会话、联邦缺口、恢复通道、API 密钥、紧急访问和提供商支持 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-5.5-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "5.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Include dormant, ephemeral, disconnected, externally managed, provider-held, aliased, cloned, and cross-tenant objects in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 休眠、短生、离线、外部托管、提供商持有、别名、克隆和跨租户对象 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-5.5-SCP-08",
          "local_code": "SCP-08",
          "display_code": "P08",
          "safeguard_id": "5.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Define nested scope at enterprise, business service, tenant, environment, platform, object, identity, data set, and transaction levels; prohibit a parent result from hiding a failing child.",
          "zh": "按企业、业务服务、租户、环境、平台、对象、身份、数据集和交易定义嵌套范围，禁止父级结果遮蔽失败子级。"
        },
        {
          "code": "CIS-5.5-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "5.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-5.5-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "5.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-5.5-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "5.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-5.5-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "5.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-5.5-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "5.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind identity governance, HR, managers, application and platform owners, PAM operators, service owners, and security to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 身份治理、HR、直属经理、应用与平台责任人、PAM 运营方、服务责任人和安全团队 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-5.5-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "5.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Name who may transition requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-5.5-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "5.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Name who may transition discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-5.5-OWN-08",
          "local_code": "OWN-08",
          "display_code": "W08",
          "safeguard_id": "5.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Model delegated authority, quorum or dual approval where warranted, escalation deadlines, provider handoffs, conflict resolution, and executive risk acceptance.",
          "zh": "建模委派权限、必要时的双人或法定人数审批、升级期限、提供商交接、冲突解决和管理层风险接受。"
        },
        {
          "code": "CIS-5.5-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "5.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-5.5-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "5.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-5.5-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "5.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV23, M1, M2, M3, M4, M5, M6, M7, M8, M9) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV23, M1, M2, M3, M4, M5, M6, M7, M8, M9）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-5.5-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "5.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-5.5-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "5.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the authoritative account inventory and identity lifecycle as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把权威账户清单与身份生命周期作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-5.5-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "5.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated.",
          "zh": "对生命周期“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-5.5-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "5.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence.",
          "zh": "对生命周期“发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-5.5-DAT-08",
          "local_code": "DAT-08",
          "display_code": "D08",
          "safeguard_id": "5.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Version schemas and state transitions with migration, backfill, deduplication, lineage, historical denominator, deletion, and rollback semantics.",
          "zh": "对模式和状态转换做版本管理，定义迁移、回填、去重、血缘、历史分母、删除和回滚语义。"
        },
        {
          "code": "CIS-5.5-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "5.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 6.6; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 6.6 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-5.5-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "5.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-5.5-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "5.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-5.5-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "5.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-5.5-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "5.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile HR/workforce systems, directories, IAM, cloud tenants, PAM, application databases, secrets platforms, provider consoles, and authentication logs and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 HR/人员系统、目录、IAM、云租户、PAM、应用数据库、密钥平台、提供商控制台和认证日志，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-5.5-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "5.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Require every connector carrying effective identity, authentication, authorization, privilege, session, and revocation state across every access path to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 所有访问路径上的实际身份、认证、授权、权限、会话和撤销状态 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-5.5-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "5.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Require every connector carrying observed, approved, unapproved, ownerless, stale, duplicate, and retired object identity to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 已观测、已批准、未批准、无责任人、陈旧、重复和已退役对象身份 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-5.5-INT-08",
          "local_code": "INT-08",
          "display_code": "I08",
          "safeguard_id": "5.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Define consistency rules across disagreeing sources, source precedence, confidence, reconciliation queues, dead-letter handling, reprocessing, and end-to-end trace identity.",
          "zh": "定义冲突来源的一致性、优先级、置信度、对账队列、死信、重处理和端到端追踪身份。"
        },
        {
          "code": "CIS-5.5-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "5.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Record owner/team, workload and environment, purpose, privilege, authentication system, credential type/location, creation, rotation/expiry, dependencies and quarterly review.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“记录责任团队、工作负载/环境、用途、权限、认证系统、凭据类型/位置、创建、轮换/到期、依赖和季度复核；优先短期工作负载身份和自动轮换，发放绑定部署并随服务退役。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-5.5-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "5.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-5.5-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "5.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-5.5-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "5.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-5.5-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "5.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the authoritative account inventory and identity lifecycle and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在权威账户清单与身份生命周期中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-5.5-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "5.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Implement the explicit state machine requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-5.5-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "5.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Implement the explicit state machine discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-5.5-CTL-08",
          "local_code": "CTL-08",
          "display_code": "C08",
          "safeguard_id": "5.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Specify concurrent decisions, partial success, compensating transactions, repeated requests, stale policy, dependency outage, and recovery from an interrupted state transition.",
          "zh": "定义并发决策、部分成功、补偿事务、重复请求、陈旧策略、依赖中断和中途状态转换恢复。"
        },
        {
          "code": "CIS-5.5-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "5.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (quarterly); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（quarterly）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-5.5-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "5.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-5.5-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "5.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-5.5-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "5.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-5.5-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "5.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in human, administrative, service, workload, device, emergency, provider, and shared or default account identities; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 人员、管理员、服务、工作负载、设备、紧急、提供商以及共享或默认账户身份 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-5.5-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "5.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated; alert before each deadline becomes overdue.",
          "zh": "为“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-5.5-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "5.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence; alert before each deadline becomes overdue.",
          "zh": "为“发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-5.5-TIM-08",
          "local_code": "TIM-08",
          "display_code": "T08",
          "safeguard_id": "5.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Allocate an end-to-end SLO budget across discovery, collection, processing, approval, enforcement, verification, and closure; prioritize overdue work by consequence and exposure.",
          "zh": "把端到端 SLO 预算分配到发现、采集、处理、审批、执行、验证和关闭，并按后果与暴露排列逾期工作。"
        },
        {
          "code": "CIS-5.5-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "5.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “The current CAS repeats the invalid inventory formulas from 5.1 and even tests three required fields against four.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“CAS 重复 5.1 的无效公式，且三项必需字段却按四项算。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-5.5-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "5.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-5.5-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "5.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-5.5-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "5.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-5.5-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "5.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat dormant, orphaned, shared, default, break-glass, non-interactive, federated, cross-tenant, and ownerless accounts as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 休眠、孤儿、共享、默认、破窗、非交互、联邦、跨租户和无责任人账户 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-5.5-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "5.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Treat shared and service identities, nested groups, direct grants, cached sessions, federation gaps, recovery channels, API keys, emergency access, and provider support as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 共享与服务身份、嵌套组、直接授权、缓存会话、联邦缺口、恢复通道、API 密钥、紧急访问和提供商支持 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-5.5-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "5.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Treat dormant, ephemeral, disconnected, externally managed, provider-held, aliased, cloned, and cross-tenant objects as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 休眠、短生、离线、外部托管、提供商持有、别名、克隆和跨租户对象 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-5.5-EXC-08",
          "local_code": "EXC-08",
          "display_code": "X08",
          "safeguard_id": "5.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Exercise compound failures where an exception, stale source, provider outage, unavailable owner, and degraded control overlap; define one safe command and one accountable decision.",
          "zh": "演练例外、陈旧来源、提供商中断、责任人不可用和控制降级同时出现的复合故障，明确一条安全指令和一个责任决策。"
        },
        {
          "code": "CIS-5.5-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "5.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Enumerate non-human identities and credentials from each authentication/secret system, compare to deployed workloads and owners, and rotate/revoke a canary without outage.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“从每个认证/秘密系统枚举非人身份和凭据，与部署工作负载/责任人对账；轮换或撤销金丝雀，确认旧秘密失效，错误工作负载/环境使用会告警。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-5.5-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "5.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-5.5-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "5.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 2 pinned CAS metric branch(es), 10 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 2 个指标分支、10 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-5.5-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "5.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-5.5-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "5.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the authoritative account inventory and identity lifecycle plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以权威账户清单与身份生命周期和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-5.5-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "5.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Publish requested, approved, effective, excessive, orphaned, stale, emergency, revoked-but-active, and independently reviewed rights with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 申请、批准、实际、过度、孤儿、陈旧、紧急、已撤销仍活跃及独立复核权限，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-5.5-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "5.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Publish matched, missing, duplicate, stale, ownerless, unapproved, unevaluable, and retired-without-proof counts with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 匹配、缺失、重复、陈旧、无责任人、未批准、不可评估及无证明退役数量，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-5.5-EVD-08",
          "local_code": "EVD-08",
          "display_code": "E08",
          "safeguard_id": "5.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Require an independent party to reconstruct the decision from source receipts and reproduce the population, state transition, calculation, test result, exception, and final closure.",
          "zh": "要求独立人员使用来源回执重建决策，并复现总体、状态转换、计算、测试结果、例外和最终关闭。"
        },
        {
          "code": "CIS-5.5-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "5.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-5.5-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "5.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-5.5-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "5.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-5.5-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "5.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-5.5-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "5.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the authoritative account inventory and identity lifecycle; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护权威账户清单与身份生命周期的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-5.5-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "5.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Restrict authority to change requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-5.5-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "5.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Restrict authority to change discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-5.5-SEC-08",
          "local_code": "SEC-08",
          "display_code": "S08",
          "safeguard_id": "5.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Threat-model the implementation system itself: forged evidence, poisoned inventory, privilege abuse, cross-tenant confusion, policy rollback, audit deletion, denial of service, and recovery compromise.",
          "zh": "威胁建模实施系统自身：伪造证据、污染清单、权限滥用、跨租户混淆、策略回滚、审计删除、拒绝服务和恢复失陷。"
        },
        {
          "code": "CIS-5.5-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "5.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-5.5-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "5.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-5.5-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "5.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-5.5-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "5.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-5.5-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "5.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise joiner, mover, leaver, dormant and orphan accounts, default credentials, privilege separation, secret rotation, and directory outage through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 入转离、休眠与孤儿账户、默认凭据、权限分离、密钥轮换和目录中断，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-5.5-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "5.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Run the positive control an authorized identity using the required assurance and least privilege; exercise negative, stale, duplicate, bypass, and outage controls including an unauthorized identity, missing factor, stale session, direct grant, inherited excess, revoked token, and recovery bypass.",
          "zh": "运行正向控制“使用所需保证级别和最小权限的授权身份”，并执行包含“未授权身份、缺失认证因子、陈旧会话、直接授权、继承过权、已撤销令牌和恢复绕过”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-5.5-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "5.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Run the positive control a seeded approved object reconciled from two independent sources; exercise negative, stale, duplicate, bypass, and outage controls including an unknown object, duplicate identity, stale record, vanished object, failed source, and cross-tenant collision.",
          "zh": "运行正向控制“从两个独立来源对账的一项植入已批准对象”，并执行包含“未知对象、重复身份、陈旧记录、突然消失对象、失效来源和跨租户碰撞”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-5.5-TST-08",
          "local_code": "TST-08",
          "display_code": "V08",
          "safeguard_id": "5.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Build a pairwise platform-and-failure matrix, then add high-consequence multi-factor cases, historical regression, source substitution, red-team challenge, and assessor replay.",
          "zh": "建立平台—故障两两组合矩阵，再加入高后果多因素案例、历史回归、来源替换、红队挑战和评估方重放。"
        },
        {
          "code": "CIS-5.5-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "5.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-5.5-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "5.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-5.5-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "5.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-5.5-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "5.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-5.5-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "5.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever HR/workforce systems, directories, IAM, cloud tenants, PAM, application databases, secrets platforms, provider consoles, and authentication logs change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 HR/人员系统、目录、IAM、云租户、PAM、应用数据库、密钥平台、提供商控制台和认证日志 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-5.5-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "5.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Use requested, approved, effective, excessive, orphaned, stale, emergency, revoked-but-active, and independently reviewed rights to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 申请、批准、实际、过度、孤儿、陈旧、紧急、已撤销仍活跃及独立复核权限 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-5.5-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "5.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Use matched, missing, duplicate, stale, ownerless, unapproved, unevaluable, and retired-without-proof counts to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 匹配、缺失、重复、陈旧、无责任人、未批准、不可评估及无证明退役数量 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-5.5-OPS-08",
          "local_code": "OPS-08",
          "display_code": "R08",
          "safeguard_id": "5.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Use canary deployment, kill criteria, rollback, backlog burn-down, exception reduction, source-quality targets, quarterly design review, and a measurable retirement plan.",
          "zh": "采用金丝雀、停止标准、回滚、积压燃尽、例外缩减、来源质量目标、季度设计复核和可量化退役计划。"
        }
      ]
    },
    {
      "id": "5.6",
      "control": 5,
      "title_en": "Centralize Account Management",
      "title_zh": "集中账户管理",
      "first_ig": 2,
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Users",
      "security_function": "Govern",
      "patterns": [
        "identity"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "1.1",
          "2.1"
        ],
        "variables": [
          "GV1",
          "M1",
          "M2",
          "M3"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "Centralization applies to identities that supported systems can delegate to a directory or identity provider, across workforce, cloud and SaaS.",
          "build": "Select authoritative identity services, federate applications, automate lifecycle and group/role provisioning, restrict local account creation, and maintain resilient break-glass access.",
          "proof": "Inventory every authentication point, test central disablement and role change through representative applications, and try a local/login recovery bypass.",
          "boundary": "Legacy, OT and isolated systems may need local identities with compensating vaulting and reconciliation."
        },
        "zh": {
          "scope": "集中化适用于能委托目录/IdP 的 workforce、云和 SaaS 身份；不意味着所有信任层只有一个故障域，也不能以 SSO 磁贴证明本地账户和恢复路径受控。",
          "build": "选定权威身份服务，联邦应用，自动化生命周期与组/角色预配，限制本地账户创建，并维护弹性破窗。",
          "proof": "清点所有认证点，在代表应用测试中央禁用/调岗，并尝试本地登录和恢复旁路；指标包括强制联邦且生命周期可控的合格应用、残留本地账户和未集成系统，同时演练 IdP 故障与恢复。",
          "boundary": "旧系统、OT 和隔离环境可保留本地身份，但要密钥库和对账。"
        }
      },
      "category_counts": {
        "outcome": 6,
        "scope": 6,
        "ownership": 6,
        "data": 6,
        "integration": 6,
        "control": 6,
        "timing": 6,
        "exception": 6,
        "evidence": 6,
        "security": 6,
        "testing": 6,
        "operations": 6
      },
      "requirement_count": 72,
      "requirements": [
        {
          "code": "CIS-5.6-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "5.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Centralize Account Management; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“集中账户管理”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-5.6-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "5.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 5.6, official Asset Class Users, Security Function Govern, and IG2 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 5.6、官方资产类别“用户与身份”、安全功能“治理”和首次出现的 IG2，并保存来源抓取日期。"
        },
        {
          "code": "CIS-5.6-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "5.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Centralization applies to identities that supported systems can delegate to a directory or identity provider, across workforce, cloud and SaaS.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“集中化适用于能委托目录/IdP 的 workforce、云和 SaaS 身份；不意味着所有信任层只有一个故障域，也不能以 SSO 磁贴证明本地账户和恢复路径受控。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-5.6-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "5.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-5.6-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "5.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Centralize Account Management to its operating object—human, administrative, service, workload, device, emergency, provider, and shared or default account identities—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“集中账户管理”连接到其运营对象——人员、管理员、服务、工作负载、设备、紧急、提供商以及共享或默认账户身份——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-5.6-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "5.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "For Centralize Account Management, express success as an observable decision over effective identity, authentication, authorization, privilege, session, and revocation state across every access path; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“集中账户管理”，以 所有访问路径上的实际身份、认证、授权、权限、会话和撤销状态 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-5.6-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "5.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-5.6-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "5.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-5.6-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "5.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-5.6-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "5.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-5.6-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "5.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across dormant, orphaned, shared, default, break-glass, non-interactive, federated, cross-tenant, and ownerless accounts; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 休眠、孤儿、共享、默认、破窗、非交互、联邦、跨租户和无责任人账户 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-5.6-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "5.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Include shared and service identities, nested groups, direct grants, cached sessions, federation gaps, recovery channels, API keys, emergency access, and provider support in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 共享与服务身份、嵌套组、直接授权、缓存会话、联邦缺口、恢复通道、API 密钥、紧急访问和提供商支持 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-5.6-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "5.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-5.6-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "5.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-5.6-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "5.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-5.6-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "5.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-5.6-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "5.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind identity governance, HR, managers, application and platform owners, PAM operators, service owners, and security to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 身份治理、HR、直属经理、应用与平台责任人、PAM 运营方、服务责任人和安全团队 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-5.6-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "5.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Name who may transition requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-5.6-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "5.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-5.6-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "5.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-5.6-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "5.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV1, M1, M2, M3) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV1, M1, M2, M3）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-5.6-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "5.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-5.6-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "5.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the authoritative account inventory and identity lifecycle as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把权威账户清单与身份生命周期作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-5.6-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "5.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated.",
          "zh": "对生命周期“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-5.6-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "5.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 1.1, Safeguard 2.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 1.1、Safeguard 2.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-5.6-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "5.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-5.6-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "5.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-5.6-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "5.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-5.6-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "5.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile HR/workforce systems, directories, IAM, cloud tenants, PAM, application databases, secrets platforms, provider consoles, and authentication logs and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 HR/人员系统、目录、IAM、云租户、PAM、应用数据库、密钥平台、提供商控制台和认证日志，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-5.6-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "5.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Require every connector carrying effective identity, authentication, authorization, privilege, session, and revocation state across every access path to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 所有访问路径上的实际身份、认证、授权、权限、会话和撤销状态 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-5.6-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "5.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Select authoritative identity services, federate applications, automate lifecycle and group/role provisioning, restrict local account creation, and maintain resilient break-glass access.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“选定权威身份服务，联邦应用，自动化生命周期与组/角色预配，限制本地账户创建，并维护弹性破窗。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-5.6-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "5.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-5.6-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "5.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-5.6-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "5.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-5.6-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "5.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the authoritative account inventory and identity lifecycle and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在权威账户清单与身份生命周期中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-5.6-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "5.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Implement the explicit state machine requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-5.6-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "5.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-5.6-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "5.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-5.6-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "5.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-5.6-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "5.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-5.6-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "5.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in human, administrative, service, workload, device, emergency, provider, and shared or default account identities; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 人员、管理员、服务、工作负载、设备、紧急、提供商以及共享或默认账户身份 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-5.6-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "5.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated; alert before each deadline becomes overdue.",
          "zh": "为“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-5.6-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "5.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “Legacy, OT and isolated systems may need local identities with compensating vaulting and reconciliation.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“旧系统、OT 和隔离环境可保留本地身份，但要密钥库和对账。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-5.6-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "5.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-5.6-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "5.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-5.6-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "5.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-5.6-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "5.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat dormant, orphaned, shared, default, break-glass, non-interactive, federated, cross-tenant, and ownerless accounts as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 休眠、孤儿、共享、默认、破窗、非交互、联邦、跨租户和无责任人账户 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-5.6-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "5.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Treat shared and service identities, nested groups, direct grants, cached sessions, federation gaps, recovery channels, API keys, emergency access, and provider support as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 共享与服务身份、嵌套组、直接授权、缓存会话、联邦缺口、恢复通道、API 密钥、紧急访问和提供商支持 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-5.6-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "5.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Inventory every authentication point, test central disablement and role change through representative applications, and try a local/login recovery bypass.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“清点所有认证点，在代表应用测试中央禁用/调岗，并尝试本地登录和恢复旁路；指标包括强制联邦且生命周期可控的合格应用、残留本地账户和未集成系统，同时演练 IdP 故障与恢复。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-5.6-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "5.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-5.6-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "5.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 4 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、4 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-5.6-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "5.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-5.6-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "5.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the authoritative account inventory and identity lifecycle plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以权威账户清单与身份生命周期和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-5.6-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "5.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Publish requested, approved, effective, excessive, orphaned, stale, emergency, revoked-but-active, and independently reviewed rights with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 申请、批准、实际、过度、孤儿、陈旧、紧急、已撤销仍活跃及独立复核权限，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-5.6-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "5.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-5.6-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "5.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-5.6-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "5.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-5.6-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "5.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-5.6-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "5.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the authoritative account inventory and identity lifecycle; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护权威账户清单与身份生命周期的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-5.6-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "5.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Restrict authority to change requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-5.6-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "5.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-5.6-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "5.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-5.6-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "5.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-5.6-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "5.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-5.6-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "5.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise joiner, mover, leaver, dormant and orphan accounts, default credentials, privilege separation, secret rotation, and directory outage through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 入转离、休眠与孤儿账户、默认凭据、权限分离、密钥轮换和目录中断，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-5.6-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "5.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Run the positive control an authorized identity using the required assurance and least privilege; exercise negative, stale, duplicate, bypass, and outage controls including an unauthorized identity, missing factor, stale session, direct grant, inherited excess, revoked token, and recovery bypass.",
          "zh": "运行正向控制“使用所需保证级别和最小权限的授权身份”，并执行包含“未授权身份、缺失认证因子、陈旧会话、直接授权、继承过权、已撤销令牌和恢复绕过”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-5.6-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "5.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-5.6-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "5.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-5.6-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "5.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-5.6-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "5.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-5.6-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "5.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever HR/workforce systems, directories, IAM, cloud tenants, PAM, application databases, secrets platforms, provider consoles, and authentication logs change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 HR/人员系统、目录、IAM、云租户、PAM、应用数据库、密钥平台、提供商控制台和认证日志 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-5.6-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "5.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Use requested, approved, effective, excessive, orphaned, stale, emergency, revoked-but-active, and independently reviewed rights to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 申请、批准、实际、过度、孤儿、陈旧、紧急、已撤销仍活跃及独立复核权限 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "6.1",
      "control": 6,
      "title_en": "Establish an Access Granting Process",
      "title_zh": "访问授予流程",
      "first_ig": 1,
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Documentation",
      "security_function": "Govern",
      "patterns": [
        "identity",
        "governance"
      ],
      "expanded_complexity": true,
      "cas_context": {
        "dependencies": [],
        "variables": [
          "M1",
          "M2"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "The process covers employees, contractors, guests, partners, service identities and administrators gaining access through new hire, new workload, role or project change and emergency need.",
          "build": "Require identified requester, owner/manager approval, business purpose, role or entitlement, start/end time, segregation-of-duties check and target system; automate from authoritative events and make privileged or sensitive access expire by default.",
          "proof": "Run canary new-hire, transfer, temporary and emergency requests, then compare approved access with effective accounts, groups, roles, keys and sessions at the promised time.",
          "boundary": "A completed ticket is not a grant receipt, and group membership may yield hidden nested privilege."
        },
        "zh": {
          "scope": "覆盖员工、承包商、Guest、伙伴、服务身份和管理员在入职、新工作负载、调岗/项目变化和应急时获得访问，且要到达所有权威系统，包括中央预配之外的本地和服务商权限。",
          "build": "要求具名申请人、所有者/经理批准、业务目的、角色/权限、起止、职责冲突检查和目标系统；由权威事件自动化，高权或敏感访问默认到期。",
          "proof": "执行入职、调岗、临时和应急金丝雀请求，把批准访问与 SLO 时间点的真实账户、组、角色、密钥和会话比较；同时抽样拒绝与冲突请求，统计迟发、超权和手工旁路。",
          "boundary": "工单完成不等于授权送达，组嵌套可能带来隐藏权限。"
        }
      },
      "category_counts": {
        "outcome": 8,
        "scope": 8,
        "ownership": 8,
        "data": 8,
        "integration": 8,
        "control": 8,
        "timing": 8,
        "exception": 8,
        "evidence": 8,
        "security": 8,
        "testing": 8,
        "operations": 8
      },
      "requirement_count": 96,
      "requirements": [
        {
          "code": "CIS-6.1-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "6.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Establish an Access Granting Process; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“访问授予流程”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-6.1-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "6.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 6.1, official Asset Class Documentation, Security Function Govern, and IG1 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 6.1、官方资产类别“文档与治理”、安全功能“治理”和首次出现的 IG1，并保存来源抓取日期。"
        },
        {
          "code": "CIS-6.1-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "6.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “The process covers employees, contractors, guests, partners, service identities and administrators gaining access through new hire, new workload, role or project change and emergency need.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“覆盖员工、承包商、Guest、伙伴、服务身份和管理员在入职、新工作负载、调岗/项目变化和应急时获得访问，且要到达所有权威系统，包括中央预配之外的本地和服务商权限。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-6.1-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "6.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-6.1-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "6.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Establish an Access Granting Process to its operating object—effective entitlements for human, service, workload, provider, emergency, and delegated identities across every access path—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“访问授予流程”连接到其运营对象——人员、服务、工作负载、提供商、紧急和委派身份在所有访问路径上的实际权限——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-6.1-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "6.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "For Establish an Access Granting Process, express success as an observable decision over effective identity, authentication, authorization, privilege, session, and revocation state across every access path; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“访问授予流程”，以 所有访问路径上的实际身份、认证、授权、权限、会话和撤销状态 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-6.1-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "6.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "For Establish an Access Granting Process, express success as an observable decision over a documented decision system with policy, process, procedure, accountable owner, approval, and review; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“访问授予流程”，以 包含策略、流程、程序、责任人、审批和复核的文档化决策系统 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-6.1-OUT-08",
          "local_code": "OUT-08",
          "display_code": "O08",
          "safeguard_id": "6.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "For the expanded Establish an Access Granting Process scope, resolve conflicts among security, safety, privacy, legal, availability, customer, and operational objectives through an explicit risk decision.",
          "zh": "对“访问授予流程”的扩展范围，通过显式风险决策解决安全、安全生产、隐私、法律、可用性、客户和运营目标冲突。"
        },
        {
          "code": "CIS-6.1-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "6.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-6.1-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "6.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-6.1-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "6.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-6.1-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "6.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-6.1-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "6.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across direct grants, inherited rights, nested groups, cached sessions, local accounts, API keys, federation failure, unsupported MFA, and emergency access; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 直接授权、继承权限、嵌套组、缓存会话、本地账户、API 密钥、联邦失效、不支持 MFA 和紧急访问 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-6.1-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "6.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Include shared and service identities, nested groups, direct grants, cached sessions, federation gaps, recovery channels, API keys, emergency access, and provider support in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 共享与服务身份、嵌套组、直接授权、缓存会话、联邦缺口、恢复通道、API 密钥、紧急访问和提供商支持 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-6.1-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "6.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Include missing policy clauses, conflicting authorities, local deviations, obsolete documentation, and decisions made outside the governed workflow in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 策略条款缺失、权限冲突、本地偏离、文档过期及绕过治理流程的决策 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-6.1-SCP-08",
          "local_code": "SCP-08",
          "display_code": "P08",
          "safeguard_id": "6.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Define nested scope at enterprise, business service, tenant, environment, platform, object, identity, data set, and transaction levels; prohibit a parent result from hiding a failing child.",
          "zh": "按企业、业务服务、租户、环境、平台、对象、身份、数据集和交易定义嵌套范围，禁止父级结果遮蔽失败子级。"
        },
        {
          "code": "CIS-6.1-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "6.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-6.1-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "6.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-6.1-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "6.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-6.1-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "6.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-6.1-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "6.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind resource and data owners, managers, identity teams, platform operators, security, HR, and independent reviewers to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 资源与数据责任人、直属经理、身份团队、平台运营方、安全、HR 和独立复核人 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-6.1-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "6.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Name who may transition requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-6.1-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "6.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Name who may transition draft → reviewed → approved → effective → exception/withdrawn → superseded, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-6.1-OWN-08",
          "local_code": "OWN-08",
          "display_code": "W08",
          "safeguard_id": "6.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Model delegated authority, quorum or dual approval where warranted, escalation deadlines, provider handoffs, conflict resolution, and executive risk acceptance.",
          "zh": "建模委派权限、必要时的双人或法定人数审批、升级期限、提供商交接、冲突解决和管理层风险接受。"
        },
        {
          "code": "CIS-6.1-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "6.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-6.1-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "6.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-6.1-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "6.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (M1, M2) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（M1, M2）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-6.1-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "6.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-6.1-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "6.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the access request, approval, policy, and effective-permission authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把访问申请、审批、策略与有效权限权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-6.1-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "6.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated.",
          "zh": "对生命周期“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-6.1-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "6.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle draft → reviewed → approved → effective → exception/withdrawn → superseded.",
          "zh": "对生命周期“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-6.1-DAT-08",
          "local_code": "DAT-08",
          "display_code": "D08",
          "safeguard_id": "6.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Version schemas and state transitions with migration, backfill, deduplication, lineage, historical denominator, deletion, and rollback semantics.",
          "zh": "对模式和状态转换做版本管理，定义迁移、回填、去重、血缘、历史分母、删除和回滚语义。"
        },
        {
          "code": "CIS-6.1-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "6.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for no explicit predecessor in the pinned CAS page; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 固定 CAS 页面没有列出显式前置项 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-6.1-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "6.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-6.1-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "6.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-6.1-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "6.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-6.1-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "6.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile HR and ticket workflows, IAM/SSO, directories, application roles, cloud policies, PAM, network access, data ACLs, and provider controls and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 HR 与工单流程、IAM/SSO、目录、应用角色、云策略、PAM、网络访问、数据 ACL 和提供商控制，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-6.1-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "6.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Require every connector carrying effective identity, authentication, authorization, privilege, session, and revocation state across every access path to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 所有访问路径上的实际身份、认证、授权、权限、会话和撤销状态 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-6.1-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "6.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Require every connector carrying a documented decision system with policy, process, procedure, accountable owner, approval, and review to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 包含策略、流程、程序、责任人、审批和复核的文档化决策系统 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-6.1-INT-08",
          "local_code": "INT-08",
          "display_code": "I08",
          "safeguard_id": "6.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Define consistency rules across disagreeing sources, source precedence, confidence, reconciliation queues, dead-letter handling, reprocessing, and end-to-end trace identity.",
          "zh": "定义冲突来源的一致性、优先级、置信度、对账队列、死信、重处理和端到端追踪身份。"
        },
        {
          "code": "CIS-6.1-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "6.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Require identified requester, owner/manager approval, business purpose, role or entitlement, start/end time, segregation-of-duties check and target system; automate from authoritative events and make privileged or sensitive access expire by default.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“要求具名申请人、所有者/经理批准、业务目的、角色/权限、起止、职责冲突检查和目标系统；由权威事件自动化，高权或敏感访问默认到期。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-6.1-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "6.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-6.1-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "6.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-6.1-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "6.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-6.1-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "6.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the access request, approval, policy, and effective-permission authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在访问申请、审批、策略与有效权限权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-6.1-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "6.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Implement the explicit state machine requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-6.1-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "6.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Implement the explicit state machine draft → reviewed → approved → effective → exception/withdrawn → superseded; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-6.1-CTL-08",
          "local_code": "CTL-08",
          "display_code": "C08",
          "safeguard_id": "6.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Specify concurrent decisions, partial success, compensating transactions, repeated requests, stale policy, dependency outage, and recovery from an interrupted state transition.",
          "zh": "定义并发决策、部分成功、补偿事务、重复请求、陈旧策略、依赖中断和中途状态转换恢复。"
        },
        {
          "code": "CIS-6.1-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "6.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-6.1-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "6.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-6.1-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "6.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-6.1-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "6.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-6.1-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "6.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in effective entitlements for human, service, workload, provider, emergency, and delegated identities across every access path; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 人员、服务、工作负载、提供商、紧急和委派身份在所有访问路径上的实际权限 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-6.1-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "6.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated; alert before each deadline becomes overdue.",
          "zh": "为“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-6.1-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "6.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for draft → reviewed → approved → effective → exception/withdrawn → superseded; alert before each deadline becomes overdue.",
          "zh": "为“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-6.1-TIM-08",
          "local_code": "TIM-08",
          "display_code": "T08",
          "safeguard_id": "6.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Allocate an end-to-end SLO budget across discovery, collection, processing, approval, enforcement, verification, and closure; prioritize overdue work by consequence and exposure.",
          "zh": "把端到端 SLO 预算分配到发现、采集、处理、审批、执行、验证和关闭，并按后果与暴露排列逾期工作。"
        },
        {
          "code": "CIS-6.1-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "6.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “A completed ticket is not a grant receipt, and group membership may yield hidden nested privilege.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“工单完成不等于授权送达，组嵌套可能带来隐藏权限。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-6.1-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "6.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-6.1-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "6.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-6.1-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "6.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-6.1-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "6.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat direct grants, inherited rights, nested groups, cached sessions, local accounts, API keys, federation failure, unsupported MFA, and emergency access as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 直接授权、继承权限、嵌套组、缓存会话、本地账户、API 密钥、联邦失效、不支持 MFA 和紧急访问 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-6.1-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "6.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Treat shared and service identities, nested groups, direct grants, cached sessions, federation gaps, recovery channels, API keys, emergency access, and provider support as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 共享与服务身份、嵌套组、直接授权、缓存会话、联邦缺口、恢复通道、API 密钥、紧急访问和提供商支持 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-6.1-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "6.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Treat missing policy clauses, conflicting authorities, local deviations, obsolete documentation, and decisions made outside the governed workflow as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 策略条款缺失、权限冲突、本地偏离、文档过期及绕过治理流程的决策 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-6.1-EXC-08",
          "local_code": "EXC-08",
          "display_code": "X08",
          "safeguard_id": "6.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Exercise compound failures where an exception, stale source, provider outage, unavailable owner, and degraded control overlap; define one safe command and one accountable decision.",
          "zh": "演练例外、陈旧来源、提供商中断、责任人不可用和控制降级同时出现的复合故障，明确一条安全指令和一个责任决策。"
        },
        {
          "code": "CIS-6.1-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "6.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Run canary new-hire, transfer, temporary and emergency requests, then compare approved access with effective accounts, groups, roles, keys and sessions at the promised time.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“执行入职、调岗、临时和应急金丝雀请求，把批准访问与 SLO 时间点的真实账户、组、角色、密钥和会话比较；同时抽样拒绝与冲突请求，统计迟发、超权和手工旁路。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-6.1-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "6.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-6.1-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "6.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 2 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、2 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-6.1-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "6.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-6.1-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "6.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the access request, approval, policy, and effective-permission authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以访问申请、审批、策略与有效权限权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-6.1-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "6.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Publish requested, approved, effective, excessive, orphaned, stale, emergency, revoked-but-active, and independently reviewed rights with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 申请、批准、实际、过度、孤儿、陈旧、紧急、已撤销仍活跃及独立复核权限，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-6.1-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "6.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Publish clause coverage, owner and reviewer completeness, approval age, triggered reviews, deviations, overdue actions, and superseded versions still in use with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 条款覆盖、责任人与复核人完整性、批准年龄、触发式复核、偏离、逾期行动及仍在使用的旧版本，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-6.1-EVD-08",
          "local_code": "EVD-08",
          "display_code": "E08",
          "safeguard_id": "6.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Require an independent party to reconstruct the decision from source receipts and reproduce the population, state transition, calculation, test result, exception, and final closure.",
          "zh": "要求独立人员使用来源回执重建决策，并复现总体、状态转换、计算、测试结果、例外和最终关闭。"
        },
        {
          "code": "CIS-6.1-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "6.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-6.1-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "6.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-6.1-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "6.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-6.1-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "6.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-6.1-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "6.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the access request, approval, policy, and effective-permission authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护访问申请、审批、策略与有效权限权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-6.1-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "6.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Restrict authority to change requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-6.1-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "6.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Restrict authority to change draft → reviewed → approved → effective → exception/withdrawn → superseded; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-6.1-SEC-08",
          "local_code": "SEC-08",
          "display_code": "S08",
          "safeguard_id": "6.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Threat-model the implementation system itself: forged evidence, poisoned inventory, privilege abuse, cross-tenant confusion, policy rollback, audit deletion, denial of service, and recovery compromise.",
          "zh": "威胁建模实施系统自身：伪造证据、污染清单、权限滥用、跨租户混淆、策略回滚、审计删除、拒绝服务和恢复失陷。"
        },
        {
          "code": "CIS-6.1-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "6.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-6.1-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "6.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-6.1-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "6.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-6.1-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "6.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-6.1-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "6.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise allowed and denied identities, joiner/mover/leaver changes, step-up and recovery paths, session revocation, privilege escalation, and policy outage through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 允许与拒绝身份、入转离变更、升级认证与恢复路径、会话撤销、提权和策略中断，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-6.1-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "6.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Run the positive control an authorized identity using the required assurance and least privilege; exercise negative, stale, duplicate, bypass, and outage controls including an unauthorized identity, missing factor, stale session, direct grant, inherited excess, revoked token, and recovery bypass.",
          "zh": "运行正向控制“使用所需保证级别和最小权限的授权身份”，并执行包含“未授权身份、缺失认证因子、陈旧会话、直接授权、继承过权、已撤销令牌和恢复绕过”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-6.1-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "6.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Run the positive control an approved current process used for a representative decision; exercise negative, stale, duplicate, bypass, and outage controls including an obsolete version, missing approver, undocumented deviation, overdue review, and bypassed workflow.",
          "zh": "运行正向控制“使用当前获批流程完成一项代表性决策”，并执行包含“旧版本、审批人缺失、未记录偏离、逾期复核和绕过流程”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-6.1-TST-08",
          "local_code": "TST-08",
          "display_code": "V08",
          "safeguard_id": "6.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Build a pairwise platform-and-failure matrix, then add high-consequence multi-factor cases, historical regression, source substitution, red-team challenge, and assessor replay.",
          "zh": "建立平台—故障两两组合矩阵，再加入高后果多因素案例、历史回归、来源替换、红队挑战和评估方重放。"
        },
        {
          "code": "CIS-6.1-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "6.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-6.1-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "6.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-6.1-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "6.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-6.1-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "6.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-6.1-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "6.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever HR and ticket workflows, IAM/SSO, directories, application roles, cloud policies, PAM, network access, data ACLs, and provider controls change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 HR 与工单流程、IAM/SSO、目录、应用角色、云策略、PAM、网络访问、数据 ACL 和提供商控制 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-6.1-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "6.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Use requested, approved, effective, excessive, orphaned, stale, emergency, revoked-but-active, and independently reviewed rights to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 申请、批准、实际、过度、孤儿、陈旧、紧急、已撤销仍活跃及独立复核权限 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-6.1-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "6.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Use clause coverage, owner and reviewer completeness, approval age, triggered reviews, deviations, overdue actions, and superseded versions still in use to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 条款覆盖、责任人与复核人完整性、批准年龄、触发式复核、偏离、逾期行动及仍在使用的旧版本 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-6.1-OPS-08",
          "local_code": "OPS-08",
          "display_code": "R08",
          "safeguard_id": "6.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Use canary deployment, kill criteria, rollback, backlog burn-down, exception reduction, source-quality targets, quarterly design review, and a measurable retirement plan.",
          "zh": "采用金丝雀、停止标准、回滚、积压燃尽、例外缩减、来源质量目标、季度设计复核和可量化退役计划。"
        }
      ]
    },
    {
      "id": "6.2",
      "control": 6,
      "title_en": "Establish an Access Revoking Process",
      "title_zh": "访问撤销流程",
      "first_ig": 1,
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Documentation",
      "security_function": "Govern",
      "patterns": [
        "identity",
        "governance"
      ],
      "expanded_complexity": true,
      "cas_context": {
        "dependencies": [],
        "variables": [
          "M1",
          "M2"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [
        "immediately"
      ],
      "implementation_contract": {
        "en": {
          "scope": "Scope termination, contract end, role/project change, rights removal, compromise and emergency containment for accounts, groups, roles, sessions, tokens, keys, devices, sharing links and physical/remote paths.",
          "build": "Trigger immediate termination disablement and risk-based revocation SLOs, propagate to all authentication and authorization systems, revoke sessions/keys, recover assets and transfer ownership.",
          "proof": "Simulate termination and role change for federated, local, mobile, cloud and service access; verify sign-in, existing sessions, API tokens, group inheritance and recovery paths all fail or change on time.",
          "boundary": "Legal hold preserves data and logs, not access."
        },
        "zh": {
          "scope": "范围是离职、合同结束、调岗/项目变化、权利取消、账户受损和应急遏制，覆盖账户、组、角色、会话、Token、密钥、设备、分享链接与物理/远程路径。",
          "build": "离职立即禁用，按风险设撤权 SLO，传播到全部认证/授权系统，撤销会话/密钥、收回资产并转移所有权。",
          "proof": "模拟联邦、本地、移动、云和服务访问的离职/调岗，验证登录、存量会话、API Token、组继承和恢复路径按时失效或改变。",
          "boundary": "诉讼保全保存数据/日志，不保存访问。"
        }
      },
      "category_counts": {
        "outcome": 8,
        "scope": 8,
        "ownership": 8,
        "data": 8,
        "integration": 8,
        "control": 8,
        "timing": 8,
        "exception": 8,
        "evidence": 8,
        "security": 8,
        "testing": 8,
        "operations": 8
      },
      "requirement_count": 96,
      "requirements": [
        {
          "code": "CIS-6.2-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "6.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Establish an Access Revoking Process; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“访问撤销流程”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-6.2-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "6.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 6.2, official Asset Class Documentation, Security Function Govern, and IG1 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 6.2、官方资产类别“文档与治理”、安全功能“治理”和首次出现的 IG1，并保存来源抓取日期。"
        },
        {
          "code": "CIS-6.2-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "6.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Scope termination, contract end, role/project change, rights removal, compromise and emergency containment for accounts, groups, roles, sessions, tokens, keys, devices, sharing links and physical/remote paths.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“范围是离职、合同结束、调岗/项目变化、权利取消、账户受损和应急遏制，覆盖账户、组、角色、会话、Token、密钥、设备、分享链接与物理/远程路径。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-6.2-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "6.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-6.2-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "6.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Establish an Access Revoking Process to its operating object—effective entitlements for human, service, workload, provider, emergency, and delegated identities across every access path—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“访问撤销流程”连接到其运营对象——人员、服务、工作负载、提供商、紧急和委派身份在所有访问路径上的实际权限——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-6.2-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "6.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "For Establish an Access Revoking Process, express success as an observable decision over effective identity, authentication, authorization, privilege, session, and revocation state across every access path; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“访问撤销流程”，以 所有访问路径上的实际身份、认证、授权、权限、会话和撤销状态 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-6.2-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "6.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "For Establish an Access Revoking Process, express success as an observable decision over a documented decision system with policy, process, procedure, accountable owner, approval, and review; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“访问撤销流程”，以 包含策略、流程、程序、责任人、审批和复核的文档化决策系统 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-6.2-OUT-08",
          "local_code": "OUT-08",
          "display_code": "O08",
          "safeguard_id": "6.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "For the expanded Establish an Access Revoking Process scope, resolve conflicts among security, safety, privacy, legal, availability, customer, and operational objectives through an explicit risk decision.",
          "zh": "对“访问撤销流程”的扩展范围，通过显式风险决策解决安全、安全生产、隐私、法律、可用性、客户和运营目标冲突。"
        },
        {
          "code": "CIS-6.2-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "6.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-6.2-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "6.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-6.2-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "6.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-6.2-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "6.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-6.2-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "6.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across direct grants, inherited rights, nested groups, cached sessions, local accounts, API keys, federation failure, unsupported MFA, and emergency access; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 直接授权、继承权限、嵌套组、缓存会话、本地账户、API 密钥、联邦失效、不支持 MFA 和紧急访问 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-6.2-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "6.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Include shared and service identities, nested groups, direct grants, cached sessions, federation gaps, recovery channels, API keys, emergency access, and provider support in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 共享与服务身份、嵌套组、直接授权、缓存会话、联邦缺口、恢复通道、API 密钥、紧急访问和提供商支持 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-6.2-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "6.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Include missing policy clauses, conflicting authorities, local deviations, obsolete documentation, and decisions made outside the governed workflow in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 策略条款缺失、权限冲突、本地偏离、文档过期及绕过治理流程的决策 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-6.2-SCP-08",
          "local_code": "SCP-08",
          "display_code": "P08",
          "safeguard_id": "6.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Define nested scope at enterprise, business service, tenant, environment, platform, object, identity, data set, and transaction levels; prohibit a parent result from hiding a failing child.",
          "zh": "按企业、业务服务、租户、环境、平台、对象、身份、数据集和交易定义嵌套范围，禁止父级结果遮蔽失败子级。"
        },
        {
          "code": "CIS-6.2-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "6.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-6.2-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "6.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-6.2-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "6.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-6.2-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "6.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-6.2-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "6.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind resource and data owners, managers, identity teams, platform operators, security, HR, and independent reviewers to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 资源与数据责任人、直属经理、身份团队、平台运营方、安全、HR 和独立复核人 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-6.2-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "6.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Name who may transition requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-6.2-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "6.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Name who may transition draft → reviewed → approved → effective → exception/withdrawn → superseded, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-6.2-OWN-08",
          "local_code": "OWN-08",
          "display_code": "W08",
          "safeguard_id": "6.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Model delegated authority, quorum or dual approval where warranted, escalation deadlines, provider handoffs, conflict resolution, and executive risk acceptance.",
          "zh": "建模委派权限、必要时的双人或法定人数审批、升级期限、提供商交接、冲突解决和管理层风险接受。"
        },
        {
          "code": "CIS-6.2-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "6.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-6.2-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "6.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-6.2-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "6.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (M1, M2) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（M1, M2）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-6.2-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "6.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-6.2-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "6.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the access request, approval, policy, and effective-permission authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把访问申请、审批、策略与有效权限权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-6.2-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "6.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated.",
          "zh": "对生命周期“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-6.2-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "6.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle draft → reviewed → approved → effective → exception/withdrawn → superseded.",
          "zh": "对生命周期“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-6.2-DAT-08",
          "local_code": "DAT-08",
          "display_code": "D08",
          "safeguard_id": "6.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Version schemas and state transitions with migration, backfill, deduplication, lineage, historical denominator, deletion, and rollback semantics.",
          "zh": "对模式和状态转换做版本管理，定义迁移、回填、去重、血缘、历史分母、删除和回滚语义。"
        },
        {
          "code": "CIS-6.2-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "6.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for no explicit predecessor in the pinned CAS page; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 固定 CAS 页面没有列出显式前置项 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-6.2-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "6.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-6.2-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "6.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-6.2-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "6.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-6.2-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "6.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile HR and ticket workflows, IAM/SSO, directories, application roles, cloud policies, PAM, network access, data ACLs, and provider controls and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 HR 与工单流程、IAM/SSO、目录、应用角色、云策略、PAM、网络访问、数据 ACL 和提供商控制，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-6.2-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "6.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Require every connector carrying effective identity, authentication, authorization, privilege, session, and revocation state across every access path to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 所有访问路径上的实际身份、认证、授权、权限、会话和撤销状态 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-6.2-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "6.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Require every connector carrying a documented decision system with policy, process, procedure, accountable owner, approval, and review to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 包含策略、流程、程序、责任人、审批和复核的文档化决策系统 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-6.2-INT-08",
          "local_code": "INT-08",
          "display_code": "I08",
          "safeguard_id": "6.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Define consistency rules across disagreeing sources, source precedence, confidence, reconciliation queues, dead-letter handling, reprocessing, and end-to-end trace identity.",
          "zh": "定义冲突来源的一致性、优先级、置信度、对账队列、死信、重处理和端到端追踪身份。"
        },
        {
          "code": "CIS-6.2-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "6.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Trigger immediate termination disablement and risk-based revocation SLOs, propagate to all authentication and authorization systems, revoke sessions/keys, recover assets and transfer ownership.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“离职立即禁用，按风险设撤权 SLO，传播到全部认证/授权系统，撤销会话/密钥、收回资产并转移所有权。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-6.2-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "6.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-6.2-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "6.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-6.2-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "6.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-6.2-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "6.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the access request, approval, policy, and effective-permission authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在访问申请、审批、策略与有效权限权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-6.2-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "6.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Implement the explicit state machine requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-6.2-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "6.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Implement the explicit state machine draft → reviewed → approved → effective → exception/withdrawn → superseded; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-6.2-CTL-08",
          "local_code": "CTL-08",
          "display_code": "C08",
          "safeguard_id": "6.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Specify concurrent decisions, partial success, compensating transactions, repeated requests, stale policy, dependency outage, and recovery from an interrupted state transition.",
          "zh": "定义并发决策、部分成功、补偿事务、重复请求、陈旧策略、依赖中断和中途状态转换恢复。"
        },
        {
          "code": "CIS-6.2-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "6.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (immediately); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（immediately）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-6.2-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "6.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-6.2-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "6.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-6.2-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "6.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-6.2-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "6.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in effective entitlements for human, service, workload, provider, emergency, and delegated identities across every access path; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 人员、服务、工作负载、提供商、紧急和委派身份在所有访问路径上的实际权限 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-6.2-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "6.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated; alert before each deadline becomes overdue.",
          "zh": "为“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-6.2-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "6.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for draft → reviewed → approved → effective → exception/withdrawn → superseded; alert before each deadline becomes overdue.",
          "zh": "为“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-6.2-TIM-08",
          "local_code": "TIM-08",
          "display_code": "T08",
          "safeguard_id": "6.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Allocate an end-to-end SLO budget across discovery, collection, processing, approval, enforcement, verification, and closure; prioritize overdue work by consequence and exposure.",
          "zh": "把端到端 SLO 预算分配到发现、采集、处理、审批、执行、验证和关闭，并按后果与暴露排列逾期工作。"
        },
        {
          "code": "CIS-6.2-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "6.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “Legal hold preserves data and logs, not access.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“诉讼保全保存数据/日志，不保存访问。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-6.2-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "6.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-6.2-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "6.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-6.2-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "6.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-6.2-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "6.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat direct grants, inherited rights, nested groups, cached sessions, local accounts, API keys, federation failure, unsupported MFA, and emergency access as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 直接授权、继承权限、嵌套组、缓存会话、本地账户、API 密钥、联邦失效、不支持 MFA 和紧急访问 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-6.2-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "6.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Treat shared and service identities, nested groups, direct grants, cached sessions, federation gaps, recovery channels, API keys, emergency access, and provider support as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 共享与服务身份、嵌套组、直接授权、缓存会话、联邦缺口、恢复通道、API 密钥、紧急访问和提供商支持 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-6.2-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "6.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Treat missing policy clauses, conflicting authorities, local deviations, obsolete documentation, and decisions made outside the governed workflow as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 策略条款缺失、权限冲突、本地偏离、文档过期及绕过治理流程的决策 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-6.2-EXC-08",
          "local_code": "EXC-08",
          "display_code": "X08",
          "safeguard_id": "6.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Exercise compound failures where an exception, stale source, provider outage, unavailable owner, and degraded control overlap; define one safe command and one accountable decision.",
          "zh": "演练例外、陈旧来源、提供商中断、责任人不可用和控制降级同时出现的复合故障，明确一条安全指令和一个责任决策。"
        },
        {
          "code": "CIS-6.2-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "6.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Simulate termination and role change for federated, local, mobile, cloud and service access; verify sign-in, existing sessions, API tokens, group inheritance and recovery paths all fail or change on time.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“模拟联邦、本地、移动、云和服务访问的离职/调岗，验证登录、存量会话、API Token、组继承和恢复路径按时失效或改变。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-6.2-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "6.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-6.2-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "6.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 2 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、2 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-6.2-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "6.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-6.2-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "6.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the access request, approval, policy, and effective-permission authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以访问申请、审批、策略与有效权限权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-6.2-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "6.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Publish requested, approved, effective, excessive, orphaned, stale, emergency, revoked-but-active, and independently reviewed rights with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 申请、批准、实际、过度、孤儿、陈旧、紧急、已撤销仍活跃及独立复核权限，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-6.2-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "6.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Publish clause coverage, owner and reviewer completeness, approval age, triggered reviews, deviations, overdue actions, and superseded versions still in use with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 条款覆盖、责任人与复核人完整性、批准年龄、触发式复核、偏离、逾期行动及仍在使用的旧版本，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-6.2-EVD-08",
          "local_code": "EVD-08",
          "display_code": "E08",
          "safeguard_id": "6.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Require an independent party to reconstruct the decision from source receipts and reproduce the population, state transition, calculation, test result, exception, and final closure.",
          "zh": "要求独立人员使用来源回执重建决策，并复现总体、状态转换、计算、测试结果、例外和最终关闭。"
        },
        {
          "code": "CIS-6.2-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "6.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-6.2-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "6.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-6.2-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "6.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-6.2-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "6.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-6.2-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "6.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the access request, approval, policy, and effective-permission authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护访问申请、审批、策略与有效权限权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-6.2-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "6.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Restrict authority to change requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-6.2-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "6.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Restrict authority to change draft → reviewed → approved → effective → exception/withdrawn → superseded; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-6.2-SEC-08",
          "local_code": "SEC-08",
          "display_code": "S08",
          "safeguard_id": "6.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Threat-model the implementation system itself: forged evidence, poisoned inventory, privilege abuse, cross-tenant confusion, policy rollback, audit deletion, denial of service, and recovery compromise.",
          "zh": "威胁建模实施系统自身：伪造证据、污染清单、权限滥用、跨租户混淆、策略回滚、审计删除、拒绝服务和恢复失陷。"
        },
        {
          "code": "CIS-6.2-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "6.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-6.2-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "6.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-6.2-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "6.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-6.2-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "6.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-6.2-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "6.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise allowed and denied identities, joiner/mover/leaver changes, step-up and recovery paths, session revocation, privilege escalation, and policy outage through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 允许与拒绝身份、入转离变更、升级认证与恢复路径、会话撤销、提权和策略中断，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-6.2-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "6.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Run the positive control an authorized identity using the required assurance and least privilege; exercise negative, stale, duplicate, bypass, and outage controls including an unauthorized identity, missing factor, stale session, direct grant, inherited excess, revoked token, and recovery bypass.",
          "zh": "运行正向控制“使用所需保证级别和最小权限的授权身份”，并执行包含“未授权身份、缺失认证因子、陈旧会话、直接授权、继承过权、已撤销令牌和恢复绕过”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-6.2-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "6.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Run the positive control an approved current process used for a representative decision; exercise negative, stale, duplicate, bypass, and outage controls including an obsolete version, missing approver, undocumented deviation, overdue review, and bypassed workflow.",
          "zh": "运行正向控制“使用当前获批流程完成一项代表性决策”，并执行包含“旧版本、审批人缺失、未记录偏离、逾期复核和绕过流程”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-6.2-TST-08",
          "local_code": "TST-08",
          "display_code": "V08",
          "safeguard_id": "6.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Build a pairwise platform-and-failure matrix, then add high-consequence multi-factor cases, historical regression, source substitution, red-team challenge, and assessor replay.",
          "zh": "建立平台—故障两两组合矩阵，再加入高后果多因素案例、历史回归、来源替换、红队挑战和评估方重放。"
        },
        {
          "code": "CIS-6.2-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "6.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-6.2-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "6.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-6.2-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "6.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-6.2-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "6.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-6.2-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "6.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever HR and ticket workflows, IAM/SSO, directories, application roles, cloud policies, PAM, network access, data ACLs, and provider controls change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 HR 与工单流程、IAM/SSO、目录、应用角色、云策略、PAM、网络访问、数据 ACL 和提供商控制 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-6.2-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "6.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Use requested, approved, effective, excessive, orphaned, stale, emergency, revoked-but-active, and independently reviewed rights to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 申请、批准、实际、过度、孤儿、陈旧、紧急、已撤销仍活跃及独立复核权限 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-6.2-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "6.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Use clause coverage, owner and reviewer completeness, approval age, triggered reviews, deviations, overdue actions, and superseded versions still in use to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 条款覆盖、责任人与复核人完整性、批准年龄、触发式复核、偏离、逾期行动及仍在使用的旧版本 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-6.2-OPS-08",
          "local_code": "OPS-08",
          "display_code": "R08",
          "safeguard_id": "6.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Use canary deployment, kill criteria, rollback, backlog burn-down, exception reduction, source-quality targets, quarterly design review, and a measurable retirement plan.",
          "zh": "采用金丝雀、停止标准、回滚、积压燃尽、例外缩减、来源质量目标、季度设计复核和可量化退役计划。"
        }
      ]
    },
    {
      "id": "6.3",
      "control": 6,
      "title_en": "Require MFA for Externally-Exposed Applications",
      "title_zh": "外网应用多因素认证",
      "first_ig": 1,
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Users",
      "security_function": "Protect",
      "patterns": [
        "identity",
        "software_dev"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "2.1",
          "4.1",
          "5.1"
        ],
        "variables": [
          "GV3",
          "GV5",
          "GV22",
          "M1",
          "M2",
          "M3"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "Include every enterprise or third-party application reachable from the Internet and every human account path, including native login, SSO, API or app passwords, password reset, support/admin portals and legacy protocols.",
          "build": "Enforce phishing-resistant MFA where feasible through the application or IdP, disable bypass protocols, bind enrollment and recovery to strong identity proofing, and require step-up for sensitive actions.",
          "proof": "Test valid MFA, password-only, legacy protocol, recovery, remembered-device, new-device and federated fallback paths for ordinary and privileged users.",
          "boundary": "“Where supported” requires a replacement, gateway or risk-accepted isolation plan, not indefinite password-only access."
        },
        "zh": {
          "scope": "包括所有外网可达的企业/第三方应用及其人工账户路径：原生登录、SSO、API/App Password、重置、支持/管理门户和旧协议。",
          "build": "在应用或 IdP 强制 MFA，能用则优先抗钓鱼因素，关闭绕过协议，强身份核验注册/恢复，敏感操作 Step-up；按应用/账户管理例外，外网暴露取决于 MFA 准备度。",
          "proof": "对普通和高权用户测试有效 MFA、仅口令、旧协议、恢复、记住设备、新设备和联邦回退。",
          "boundary": "“支持时”意味着替换、网关或有期限的隔离计划，不是永久口令登录。"
        }
      },
      "category_counts": {
        "outcome": 7,
        "scope": 7,
        "ownership": 7,
        "data": 7,
        "integration": 7,
        "control": 7,
        "timing": 7,
        "exception": 7,
        "evidence": 7,
        "security": 7,
        "testing": 7,
        "operations": 7
      },
      "requirement_count": 84,
      "requirements": [
        {
          "code": "CIS-6.3-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "6.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Require MFA for Externally-Exposed Applications; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“外网应用多因素认证”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-6.3-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "6.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 6.3, official Asset Class Users, Security Function Protect, and IG1 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 6.3、官方资产类别“用户与身份”、安全功能“保护”和首次出现的 IG1，并保存来源抓取日期。"
        },
        {
          "code": "CIS-6.3-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "6.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Include every enterprise or third-party application reachable from the Internet and every human account path, including native login, SSO, API or app passwords, password reset, support/admin portals and legacy protocols.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“包括所有外网可达的企业/第三方应用及其人工账户路径：原生登录、SSO、API/App Password、重置、支持/管理门户和旧协议。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-6.3-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "6.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-6.3-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "6.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Require MFA for Externally-Exposed Applications to its operating object—effective entitlements for human, service, workload, provider, emergency, and delegated identities across every access path—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“外网应用多因素认证”连接到其运营对象——人员、服务、工作负载、提供商、紧急和委派身份在所有访问路径上的实际权限——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-6.3-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "6.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "For Require MFA for Externally-Exposed Applications, express success as an observable decision over effective identity, authentication, authorization, privilege, session, and revocation state across every access path; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“外网应用多因素认证”，以 所有访问路径上的实际身份、认证、授权、权限、会话和撤销状态 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-6.3-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "6.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "For Require MFA for Externally-Exposed Applications, express success as an observable decision over source-to-production software identity, design invariant, component trust, build provenance, test result, deployment state, runtime outcome, and vulnerability response; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“外网应用多因素认证”，以 从源码到生产的软件身份、设计不变量、组件信任、构建来源、测试结果、部署状态、运行结果和漏洞响应 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-6.3-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "6.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-6.3-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "6.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-6.3-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "6.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-6.3-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "6.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-6.3-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "6.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across direct grants, inherited rights, nested groups, cached sessions, local accounts, API keys, federation failure, unsupported MFA, and emergency access; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 直接授权、继承权限、嵌套组、缓存会话、本地账户、API 密钥、联邦失效、不支持 MFA 和紧急访问 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-6.3-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "6.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Include shared and service identities, nested groups, direct grants, cached sessions, federation gaps, recovery channels, API keys, emergency access, and provider support in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 共享与服务身份、嵌套组、直接授权、缓存会话、联邦缺口、恢复通道、API 密钥、紧急访问和提供商支持 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-6.3-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "6.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Include generated and copied code, forks, vendoring, transitive dependencies, mutable tags, build plugins, feature flags, tenant logic, secrets, emergency release, and provider components in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 生成与复制代码、分叉、vendoring、传递依赖、可变标签、构建插件、功能开关、租户逻辑、秘密、紧急发布和提供商组件 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-6.3-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "6.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-6.3-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "6.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-6.3-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "6.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-6.3-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "6.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-6.3-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "6.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind resource and data owners, managers, identity teams, platform operators, security, HR, and independent reviewers to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 资源与数据责任人、直属经理、身份团队、平台运营方、安全、HR 和独立复核人 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-6.3-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "6.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Name who may transition requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-6.3-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "6.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Name who may transition designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-6.3-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "6.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-6.3-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "6.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-6.3-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "6.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV3, GV5, GV22, M1, M2, M3) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV3, GV5, GV22, M1, M2, M3）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-6.3-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "6.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-6.3-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "6.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the access request, approval, policy, and effective-permission authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把访问申请、审批、策略与有效权限权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-6.3-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "6.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated.",
          "zh": "对生命周期“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-6.3-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "6.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired.",
          "zh": "对生命周期“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-6.3-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "6.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 2.1, Safeguard 4.1, Safeguard 5.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 2.1、Safeguard 4.1、Safeguard 5.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-6.3-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "6.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-6.3-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "6.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-6.3-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "6.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-6.3-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "6.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile HR and ticket workflows, IAM/SSO, directories, application roles, cloud policies, PAM, network access, data ACLs, and provider controls and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 HR 与工单流程、IAM/SSO、目录、应用角色、云策略、PAM、网络访问、数据 ACL 和提供商控制，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-6.3-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "6.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Require every connector carrying effective identity, authentication, authorization, privilege, session, and revocation state across every access path to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 所有访问路径上的实际身份、认证、授权、权限、会话和撤销状态 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-6.3-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "6.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Require every connector carrying source-to-production software identity, design invariant, component trust, build provenance, test result, deployment state, runtime outcome, and vulnerability response to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 从源码到生产的软件身份、设计不变量、组件信任、构建来源、测试结果、部署状态、运行结果和漏洞响应 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-6.3-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "6.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Enforce phishing-resistant MFA where feasible through the application or IdP, disable bypass protocols, bind enrollment and recovery to strong identity proofing, and require step-up for sensitive actions.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“在应用或 IdP 强制 MFA，能用则优先抗钓鱼因素，关闭绕过协议，强身份核验注册/恢复，敏感操作 Step-up；按应用/账户管理例外，外网暴露取决于 MFA 准备度。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-6.3-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "6.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-6.3-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "6.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-6.3-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "6.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-6.3-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "6.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the access request, approval, policy, and effective-permission authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在访问申请、审批、策略与有效权限权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-6.3-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "6.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Implement the explicit state machine requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-6.3-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "6.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Implement the explicit state machine designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-6.3-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "6.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-6.3-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "6.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-6.3-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "6.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-6.3-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "6.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-6.3-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "6.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in effective entitlements for human, service, workload, provider, emergency, and delegated identities across every access path; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 人员、服务、工作负载、提供商、紧急和委派身份在所有访问路径上的实际权限 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-6.3-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "6.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated; alert before each deadline becomes overdue.",
          "zh": "为“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-6.3-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "6.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; alert before each deadline becomes overdue.",
          "zh": "为“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-6.3-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "6.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: ““Where supported” requires a replacement, gateway or risk-accepted isolation plan, not indefinite password-only access.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：““支持时”意味着替换、网关或有期限的隔离计划，不是永久口令登录。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-6.3-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "6.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-6.3-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "6.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-6.3-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "6.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-6.3-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "6.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat direct grants, inherited rights, nested groups, cached sessions, local accounts, API keys, federation failure, unsupported MFA, and emergency access as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 直接授权、继承权限、嵌套组、缓存会话、本地账户、API 密钥、联邦失效、不支持 MFA 和紧急访问 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-6.3-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "6.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Treat shared and service identities, nested groups, direct grants, cached sessions, federation gaps, recovery channels, API keys, emergency access, and provider support as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 共享与服务身份、嵌套组、直接授权、缓存会话、联邦缺口、恢复通道、API 密钥、紧急访问和提供商支持 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-6.3-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "6.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Treat generated and copied code, forks, vendoring, transitive dependencies, mutable tags, build plugins, feature flags, tenant logic, secrets, emergency release, and provider components as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 生成与复制代码、分叉、vendoring、传递依赖、可变标签、构建插件、功能开关、租户逻辑、秘密、紧急发布和提供商组件 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-6.3-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "6.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Test valid MFA, password-only, legacy protocol, recovery, remembered-device, new-device and federated fallback paths for ordinary and privileged users.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“对普通和高权用户测试有效 MFA、仅口令、旧协议、恢复、记住设备、新设备和联邦回退。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-6.3-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "6.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-6.3-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "6.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 6 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、6 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-6.3-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "6.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-6.3-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "6.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the access request, approval, policy, and effective-permission authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以访问申请、审批、策略与有效权限权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-6.3-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "6.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Publish requested, approved, effective, excessive, orphaned, stale, emergency, revoked-but-active, and independently reviewed rights with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 申请、批准、实际、过度、孤儿、陈旧、紧急、已撤销仍活跃及独立复核权限，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-6.3-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "6.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Publish reviewed, unreviewed, reproducible, provenance-bound, vulnerable, test-failed, exception, deployed-unverified, drifted, rolled-back, and regression-protected releases with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已评审、未评审、可复现、来源绑定、存在漏洞、测试失败、例外、已部署未验证、漂移、已回滚和受回归保护发布物，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-6.3-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "6.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-6.3-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "6.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-6.3-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "6.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-6.3-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "6.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-6.3-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "6.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the access request, approval, policy, and effective-permission authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护访问申请、审批、策略与有效权限权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-6.3-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "6.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Restrict authority to change requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-6.3-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "6.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Restrict authority to change designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-6.3-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "6.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-6.3-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "6.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-6.3-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "6.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-6.3-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "6.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-6.3-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "6.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise allowed and denied identities, joiner/mover/leaver changes, step-up and recovery paths, session revocation, privilege escalation, and policy outage through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 允许与拒绝身份、入转离变更、升级认证与恢复路径、会话撤销、提权和策略中断，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-6.3-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "6.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Run the positive control an authorized identity using the required assurance and least privilege; exercise negative, stale, duplicate, bypass, and outage controls including an unauthorized identity, missing factor, stale session, direct grant, inherited excess, revoked token, and recovery bypass.",
          "zh": "运行正向控制“使用所需保证级别和最小权限的授权身份”，并执行包含“未授权身份、缺失认证因子、陈旧会话、直接授权、继承过权、已撤销令牌和恢复绕过”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-6.3-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "6.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Run the positive control a trusted build that preserves the security invariant through deployment and runtime; exercise negative, stale, duplicate, bypass, and outage controls including a substituted dependency, unreviewed change, poisoned build input, failed security test, bypass path, vulnerable release, rollback, and regression.",
          "zh": "运行正向控制“一个把安全不变量贯穿部署与运行的可信构建”，并执行包含“依赖替换、未评审变更、构建输入污染、安全测试失败、绕过路径、漏洞发布、回滚和回归”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-6.3-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "6.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-6.3-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "6.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-6.3-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "6.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-6.3-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "6.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-6.3-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "6.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever HR and ticket workflows, IAM/SSO, directories, application roles, cloud policies, PAM, network access, data ACLs, and provider controls change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 HR 与工单流程、IAM/SSO、目录、应用角色、云策略、PAM、网络访问、数据 ACL 和提供商控制 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-6.3-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "6.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Use requested, approved, effective, excessive, orphaned, stale, emergency, revoked-but-active, and independently reviewed rights to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 申请、批准、实际、过度、孤儿、陈旧、紧急、已撤销仍活跃及独立复核权限 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-6.3-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "6.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Use reviewed, unreviewed, reproducible, provenance-bound, vulnerable, test-failed, exception, deployed-unverified, drifted, rolled-back, and regression-protected releases to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已评审、未评审、可复现、来源绑定、存在漏洞、测试失败、例外、已部署未验证、漂移、已回滚和受回归保护发布物 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "6.4",
      "control": 6,
      "title_en": "Require MFA for Remote Network Access",
      "title_zh": "远程网络访问多因素认证",
      "first_ig": 1,
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Users",
      "security_function": "Protect",
      "patterns": [
        "identity",
        "network"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "1.1",
          "4.1"
        ],
        "variables": [
          "GV1",
          "GV3",
          "M1",
          "M2",
          "M3"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "The population is every human remote path into enterprise networks or equivalent private resources: VPN, ZTNA, VDI gateways, remote desktop, dial-up/management tunnels and vendor access.",
          "build": "Require MFA before network or resource access, bind the session to device and user context where appropriate, centrally authorize destinations and expire idle/maximum sessions.",
          "proof": "Attempt connection with password only, stolen/expired token, unenrolled device, alternate VPN protocol and existing session after account disablement.",
          "boundary": "Always-on device tunnels may authenticate machines before users and need a second user gate for sensitive resources."
        },
        "zh": {
          "scope": "总体是所有人工远程进入企业网络或等效私有资源的路径：VPN、ZTNA、VDI 网关、远程桌面、拨号/管理隧道和厂商访问。",
          "build": "网络或资源访问前强制 MFA，按需绑定设备/用户上下文，集中授权目的地并限制空闲/最长会话；分离厂商和管理员路径，关闭可绕过的分流/备用协议，记录姿态与因素决定。",
          "proof": "用仅口令、被盗/过期 Token、未注册设备、替代 VPN 协议，以及账户禁用后的现有会话连接，验证拒绝、目的范围、日志和会话撤销；独立枚举网关与账户。",
          "boundary": "Always-on 设备隧道可先认证机器，但敏感资源仍需用户关口。"
        }
      },
      "category_counts": {
        "outcome": 7,
        "scope": 7,
        "ownership": 7,
        "data": 7,
        "integration": 7,
        "control": 7,
        "timing": 7,
        "exception": 7,
        "evidence": 7,
        "security": 7,
        "testing": 7,
        "operations": 7
      },
      "requirement_count": 84,
      "requirements": [
        {
          "code": "CIS-6.4-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "6.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Require MFA for Remote Network Access; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“远程网络访问多因素认证”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-6.4-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "6.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 6.4, official Asset Class Users, Security Function Protect, and IG1 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 6.4、官方资产类别“用户与身份”、安全功能“保护”和首次出现的 IG1，并保存来源抓取日期。"
        },
        {
          "code": "CIS-6.4-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "6.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “The population is every human remote path into enterprise networks or equivalent private resources: VPN, ZTNA, VDI gateways, remote desktop, dial-up/management tunnels and vendor access.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“总体是所有人工远程进入企业网络或等效私有资源的路径：VPN、ZTNA、VDI 网关、远程桌面、拨号/管理隧道和厂商访问。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-6.4-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "6.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-6.4-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "6.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Require MFA for Remote Network Access to its operating object—effective entitlements for human, service, workload, provider, emergency, and delegated identities across every access path—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“远程网络访问多因素认证”连接到其运营对象——人员、服务、工作负载、提供商、紧急和委派身份在所有访问路径上的实际权限——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-6.4-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "6.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "For Require MFA for Remote Network Access, express success as an observable decision over effective identity, authentication, authorization, privilege, session, and revocation state across every access path; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“远程网络访问多因素认证”，以 所有访问路径上的实际身份、认证、授权、权限、会话和撤销状态 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-6.4-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "6.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "For Require MFA for Remote Network Access, express success as an observable decision over intended connectivity, trust zone, route, protocol, identity, management path, traffic decision, and observed outcome; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“远程网络访问多因素认证”，以 预期连接、信任区、路由、协议、身份、管理路径、流量决策和观察结果 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-6.4-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "6.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-6.4-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "6.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-6.4-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "6.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-6.4-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "6.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-6.4-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "6.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across direct grants, inherited rights, nested groups, cached sessions, local accounts, API keys, federation failure, unsupported MFA, and emergency access; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 直接授权、继承权限、嵌套组、缓存会话、本地账户、API 密钥、联邦失效、不支持 MFA 和紧急访问 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-6.4-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "6.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Include shared and service identities, nested groups, direct grants, cached sessions, federation gaps, recovery channels, API keys, emergency access, and provider support in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 共享与服务身份、嵌套组、直接授权、缓存会话、联邦缺口、恢复通道、API 密钥、紧急访问和提供商支持 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-6.4-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "6.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Include IPv6, overlays, east-west paths, remote and roaming devices, direct egress, alternate resolvers, QUIC, asymmetric routes, provider abstraction, and emergency consoles in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 IPv6、覆盖网络、东西向路径、远程与漫游设备、直接出口、替代解析器、QUIC、非对称路由、提供商抽象和紧急控制台 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-6.4-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "6.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-6.4-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "6.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-6.4-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "6.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-6.4-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "6.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-6.4-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "6.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind resource and data owners, managers, identity teams, platform operators, security, HR, and independent reviewers to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 资源与数据责任人、直属经理、身份团队、平台运营方、安全、HR 和独立复核人 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-6.4-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "6.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Name who may transition requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-6.4-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "6.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Name who may transition requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-6.4-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "6.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-6.4-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "6.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-6.4-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "6.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV1, GV3, M1, M2, M3) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV1, GV3, M1, M2, M3）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-6.4-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "6.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-6.4-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "6.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the access request, approval, policy, and effective-permission authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把访问申请、审批、策略与有效权限权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-6.4-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "6.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated.",
          "zh": "对生命周期“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-6.4-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "6.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired.",
          "zh": "对生命周期“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-6.4-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "6.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 1.1, Safeguard 4.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 1.1、Safeguard 4.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-6.4-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "6.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-6.4-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "6.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-6.4-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "6.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-6.4-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "6.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile HR and ticket workflows, IAM/SSO, directories, application roles, cloud policies, PAM, network access, data ACLs, and provider controls and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 HR 与工单流程、IAM/SSO、目录、应用角色、云策略、PAM、网络访问、数据 ACL 和提供商控制，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-6.4-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "6.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Require every connector carrying effective identity, authentication, authorization, privilege, session, and revocation state across every access path to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 所有访问路径上的实际身份、认证、授权、权限、会话和撤销状态 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-6.4-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "6.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Require every connector carrying intended connectivity, trust zone, route, protocol, identity, management path, traffic decision, and observed outcome to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 预期连接、信任区、路由、协议、身份、管理路径、流量决策和观察结果 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-6.4-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "6.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Require MFA before network or resource access, bind the session to device and user context where appropriate, centrally authorize destinations and expire idle/maximum sessions.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“网络或资源访问前强制 MFA，按需绑定设备/用户上下文，集中授权目的地并限制空闲/最长会话；分离厂商和管理员路径，关闭可绕过的分流/备用协议，记录姿态与因素决定。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-6.4-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "6.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-6.4-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "6.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-6.4-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "6.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-6.4-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "6.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the access request, approval, policy, and effective-permission authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在访问申请、审批、策略与有效权限权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-6.4-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "6.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Implement the explicit state machine requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-6.4-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "6.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Implement the explicit state machine requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-6.4-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "6.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-6.4-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "6.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-6.4-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "6.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-6.4-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "6.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-6.4-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "6.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in effective entitlements for human, service, workload, provider, emergency, and delegated identities across every access path; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 人员、服务、工作负载、提供商、紧急和委派身份在所有访问路径上的实际权限 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-6.4-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "6.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated; alert before each deadline becomes overdue.",
          "zh": "为“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-6.4-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "6.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; alert before each deadline becomes overdue.",
          "zh": "为“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-6.4-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "6.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “Always-on device tunnels may authenticate machines before users and need a second user gate for sensitive resources.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“Always-on 设备隧道可先认证机器，但敏感资源仍需用户关口。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-6.4-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "6.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-6.4-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "6.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-6.4-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "6.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-6.4-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "6.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat direct grants, inherited rights, nested groups, cached sessions, local accounts, API keys, federation failure, unsupported MFA, and emergency access as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 直接授权、继承权限、嵌套组、缓存会话、本地账户、API 密钥、联邦失效、不支持 MFA 和紧急访问 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-6.4-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "6.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Treat shared and service identities, nested groups, direct grants, cached sessions, federation gaps, recovery channels, API keys, emergency access, and provider support as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 共享与服务身份、嵌套组、直接授权、缓存会话、联邦缺口、恢复通道、API 密钥、紧急访问和提供商支持 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-6.4-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "6.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Treat IPv6, overlays, east-west paths, remote and roaming devices, direct egress, alternate resolvers, QUIC, asymmetric routes, provider abstraction, and emergency consoles as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 IPv6、覆盖网络、东西向路径、远程与漫游设备、直接出口、替代解析器、QUIC、非对称路由、提供商抽象和紧急控制台 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-6.4-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "6.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Attempt connection with password only, stolen/expired token, unenrolled device, alternate VPN protocol and existing session after account disablement.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“用仅口令、被盗/过期 Token、未注册设备、替代 VPN 协议，以及账户禁用后的现有会话连接，验证拒绝、目的范围、日志和会话撤销；独立枚举网关与账户。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-6.4-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "6.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-6.4-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "6.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 5 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、5 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-6.4-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "6.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-6.4-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "6.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the access request, approval, policy, and effective-permission authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以访问申请、审批、策略与有效权限权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-6.4-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "6.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Publish requested, approved, effective, excessive, orphaned, stale, emergency, revoked-but-active, and independently reviewed rights with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 申请、批准、实际、过度、孤儿、陈旧、紧急、已撤销仍活跃及独立复核权限，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-6.4-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "6.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Publish known, unknown, allowed, denied, shadow, bypassed, asymmetric, stale-rule, exception, and unobserved paths with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已知、未知、允许、拒绝、影子、绕过、非对称、陈旧规则、例外和未观测路径，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-6.4-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "6.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-6.4-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "6.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-6.4-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "6.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-6.4-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "6.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-6.4-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "6.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the access request, approval, policy, and effective-permission authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护访问申请、审批、策略与有效权限权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-6.4-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "6.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Restrict authority to change requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-6.4-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "6.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Restrict authority to change requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-6.4-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "6.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-6.4-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "6.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-6.4-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "6.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-6.4-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "6.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-6.4-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "6.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise allowed and denied identities, joiner/mover/leaver changes, step-up and recovery paths, session revocation, privilege escalation, and policy outage through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 允许与拒绝身份、入转离变更、升级认证与恢复路径、会话撤销、提权和策略中断，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-6.4-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "6.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Run the positive control an authorized identity using the required assurance and least privilege; exercise negative, stale, duplicate, bypass, and outage controls including an unauthorized identity, missing factor, stale session, direct grant, inherited excess, revoked token, and recovery bypass.",
          "zh": "运行正向控制“使用所需保证级别和最小权限的授权身份”，并执行包含“未授权身份、缺失认证因子、陈旧会话、直接授权、继承过权、已撤销令牌和恢复绕过”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-6.4-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "6.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Run the positive control an approved flow over the required secure management or business path; exercise negative, stale, duplicate, bypass, and outage controls including an unapproved route, protocol downgrade, direct egress, alternate DNS/QUIC path, segmentation bypass, AAA loss, stale rule, and rollback failure.",
          "zh": "运行正向控制“通过规定安全管理或业务路径的一项获批流量”，并执行包含“未批准路由、协议降级、直接出口、替代 DNS/QUIC 路径、分段绕过、AAA 丢失、陈旧规则和回滚失败”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-6.4-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "6.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-6.4-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "6.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-6.4-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "6.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-6.4-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "6.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-6.4-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "6.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever HR and ticket workflows, IAM/SSO, directories, application roles, cloud policies, PAM, network access, data ACLs, and provider controls change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 HR 与工单流程、IAM/SSO、目录、应用角色、云策略、PAM、网络访问、数据 ACL 和提供商控制 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-6.4-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "6.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Use requested, approved, effective, excessive, orphaned, stale, emergency, revoked-but-active, and independently reviewed rights to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 申请、批准、实际、过度、孤儿、陈旧、紧急、已撤销仍活跃及独立复核权限 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-6.4-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "6.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Use known, unknown, allowed, denied, shadow, bypassed, asymmetric, stale-rule, exception, and unobserved paths to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已知、未知、允许、拒绝、影子、绕过、非对称、陈旧规则、例外和未观测路径 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "6.5",
      "control": 6,
      "title_en": "Require MFA for Administrative Access",
      "title_zh": "管理访问多因素认证",
      "first_ig": 1,
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Users",
      "security_function": "Protect",
      "patterns": [
        "identity"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "4.1",
          "5.1"
        ],
        "variables": [
          "GV3",
          "GV22",
          "M1",
          "M2",
          "M3"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "Cover every human administrative path to assets and software, on-premises or provider-hosted: console, SSH/RDP, cloud control plane, SaaS admin, database, hypervisor, CI/CD and security tools.",
          "build": "Require strong MFA at the authoritative elevation or administrative session, prefer phishing-resistant factors, separate admin identities, protect enrollment/recovery, and eliminate protocols that accept only passwords.",
          "proof": "Test direct, federated, command-line, API-assisted, local/recovery and vendor-support paths with and without the second factor; verify a disabled factor or user kills active privilege.",
          "boundary": "Workload/service administration uses scoped machine credentials, not human MFA."
        },
        "zh": {
          "scope": "覆盖所有人工管理路径：Console、SSH/RDP、云控制面、SaaS 管理、数据库、虚拟化、CI/CD、安全工具以及服务商托管系统；支持的本地 Console 和恢复接口也在范围。",
          "build": "在权威提权或管理会话强制 MFA，优先抗钓鱼因素，分离管理身份，保护注册/恢复并淘汰仅口令协议。",
          "proof": "通过直连、联邦、命令行、API 辅助、本地/恢复和厂商支持路径，在有无第二因素情况下测试；禁用因素/用户后高权会话应失效。",
          "boundary": "工作负载管理用范围化机器凭据，不用人工 MFA。"
        }
      },
      "category_counts": {
        "outcome": 6,
        "scope": 6,
        "ownership": 6,
        "data": 6,
        "integration": 6,
        "control": 6,
        "timing": 6,
        "exception": 6,
        "evidence": 6,
        "security": 6,
        "testing": 6,
        "operations": 6
      },
      "requirement_count": 72,
      "requirements": [
        {
          "code": "CIS-6.5-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "6.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Require MFA for Administrative Access; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“管理访问多因素认证”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-6.5-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "6.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 6.5, official Asset Class Users, Security Function Protect, and IG1 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 6.5、官方资产类别“用户与身份”、安全功能“保护”和首次出现的 IG1，并保存来源抓取日期。"
        },
        {
          "code": "CIS-6.5-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "6.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Cover every human administrative path to assets and software, on-premises or provider-hosted: console, SSH/RDP, cloud control plane, SaaS admin, database, hypervisor, CI/CD and security tools.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“覆盖所有人工管理路径：Console、SSH/RDP、云控制面、SaaS 管理、数据库、虚拟化、CI/CD、安全工具以及服务商托管系统；支持的本地 Console 和恢复接口也在范围。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-6.5-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "6.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-6.5-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "6.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Require MFA for Administrative Access to its operating object—effective entitlements for human, service, workload, provider, emergency, and delegated identities across every access path—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“管理访问多因素认证”连接到其运营对象——人员、服务、工作负载、提供商、紧急和委派身份在所有访问路径上的实际权限——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-6.5-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "6.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "For Require MFA for Administrative Access, express success as an observable decision over effective identity, authentication, authorization, privilege, session, and revocation state across every access path; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“管理访问多因素认证”，以 所有访问路径上的实际身份、认证、授权、权限、会话和撤销状态 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-6.5-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "6.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-6.5-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "6.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-6.5-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "6.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-6.5-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "6.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-6.5-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "6.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across direct grants, inherited rights, nested groups, cached sessions, local accounts, API keys, federation failure, unsupported MFA, and emergency access; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 直接授权、继承权限、嵌套组、缓存会话、本地账户、API 密钥、联邦失效、不支持 MFA 和紧急访问 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-6.5-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "6.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Include shared and service identities, nested groups, direct grants, cached sessions, federation gaps, recovery channels, API keys, emergency access, and provider support in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 共享与服务身份、嵌套组、直接授权、缓存会话、联邦缺口、恢复通道、API 密钥、紧急访问和提供商支持 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-6.5-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "6.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-6.5-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "6.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-6.5-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "6.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-6.5-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "6.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-6.5-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "6.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind resource and data owners, managers, identity teams, platform operators, security, HR, and independent reviewers to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 资源与数据责任人、直属经理、身份团队、平台运营方、安全、HR 和独立复核人 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-6.5-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "6.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Name who may transition requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-6.5-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "6.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-6.5-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "6.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-6.5-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "6.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV3, GV22, M1, M2, M3) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV3, GV22, M1, M2, M3）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-6.5-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "6.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-6.5-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "6.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the access request, approval, policy, and effective-permission authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把访问申请、审批、策略与有效权限权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-6.5-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "6.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated.",
          "zh": "对生命周期“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-6.5-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "6.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 4.1, Safeguard 5.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 4.1、Safeguard 5.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-6.5-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "6.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-6.5-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "6.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-6.5-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "6.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-6.5-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "6.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile HR and ticket workflows, IAM/SSO, directories, application roles, cloud policies, PAM, network access, data ACLs, and provider controls and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 HR 与工单流程、IAM/SSO、目录、应用角色、云策略、PAM、网络访问、数据 ACL 和提供商控制，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-6.5-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "6.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Require every connector carrying effective identity, authentication, authorization, privilege, session, and revocation state across every access path to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 所有访问路径上的实际身份、认证、授权、权限、会话和撤销状态 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-6.5-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "6.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Require strong MFA at the authoritative elevation or administrative session, prefer phishing-resistant factors, separate admin identities, protect enrollment/recovery, and eliminate protocols that accept only passwords.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“在权威提权或管理会话强制 MFA，优先抗钓鱼因素，分离管理身份，保护注册/恢复并淘汰仅口令协议。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-6.5-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "6.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-6.5-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "6.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-6.5-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "6.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-6.5-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "6.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the access request, approval, policy, and effective-permission authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在访问申请、审批、策略与有效权限权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-6.5-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "6.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Implement the explicit state machine requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-6.5-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "6.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-6.5-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "6.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-6.5-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "6.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-6.5-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "6.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-6.5-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "6.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in effective entitlements for human, service, workload, provider, emergency, and delegated identities across every access path; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 人员、服务、工作负载、提供商、紧急和委派身份在所有访问路径上的实际权限 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-6.5-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "6.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated; alert before each deadline becomes overdue.",
          "zh": "为“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-6.5-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "6.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “Workload/service administration uses scoped machine credentials, not human MFA.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“工作负载管理用范围化机器凭据，不用人工 MFA。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-6.5-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "6.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-6.5-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "6.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-6.5-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "6.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-6.5-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "6.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat direct grants, inherited rights, nested groups, cached sessions, local accounts, API keys, federation failure, unsupported MFA, and emergency access as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 直接授权、继承权限、嵌套组、缓存会话、本地账户、API 密钥、联邦失效、不支持 MFA 和紧急访问 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-6.5-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "6.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Treat shared and service identities, nested groups, direct grants, cached sessions, federation gaps, recovery channels, API keys, emergency access, and provider support as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 共享与服务身份、嵌套组、直接授权、缓存会话、联邦缺口、恢复通道、API 密钥、紧急访问和提供商支持 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-6.5-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "6.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Test direct, federated, command-line, API-assisted, local/recovery and vendor-support paths with and without the second factor; verify a disabled factor or user kills active privilege.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“通过直连、联邦、命令行、API 辅助、本地/恢复和厂商支持路径，在有无第二因素情况下测试；禁用因素/用户后高权会话应失效。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-6.5-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "6.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-6.5-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "6.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 5 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、5 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-6.5-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "6.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-6.5-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "6.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the access request, approval, policy, and effective-permission authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以访问申请、审批、策略与有效权限权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-6.5-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "6.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Publish requested, approved, effective, excessive, orphaned, stale, emergency, revoked-but-active, and independently reviewed rights with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 申请、批准、实际、过度、孤儿、陈旧、紧急、已撤销仍活跃及独立复核权限，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-6.5-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "6.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-6.5-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "6.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-6.5-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "6.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-6.5-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "6.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-6.5-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "6.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the access request, approval, policy, and effective-permission authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护访问申请、审批、策略与有效权限权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-6.5-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "6.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Restrict authority to change requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-6.5-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "6.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-6.5-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "6.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-6.5-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "6.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-6.5-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "6.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-6.5-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "6.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise allowed and denied identities, joiner/mover/leaver changes, step-up and recovery paths, session revocation, privilege escalation, and policy outage through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 允许与拒绝身份、入转离变更、升级认证与恢复路径、会话撤销、提权和策略中断，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-6.5-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "6.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Run the positive control an authorized identity using the required assurance and least privilege; exercise negative, stale, duplicate, bypass, and outage controls including an unauthorized identity, missing factor, stale session, direct grant, inherited excess, revoked token, and recovery bypass.",
          "zh": "运行正向控制“使用所需保证级别和最小权限的授权身份”，并执行包含“未授权身份、缺失认证因子、陈旧会话、直接授权、继承过权、已撤销令牌和恢复绕过”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-6.5-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "6.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-6.5-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "6.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-6.5-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "6.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-6.5-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "6.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-6.5-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "6.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever HR and ticket workflows, IAM/SSO, directories, application roles, cloud policies, PAM, network access, data ACLs, and provider controls change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 HR 与工单流程、IAM/SSO、目录、应用角色、云策略、PAM、网络访问、数据 ACL 和提供商控制 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-6.5-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "6.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Use requested, approved, effective, excessive, orphaned, stale, emergency, revoked-but-active, and independently reviewed rights to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 申请、批准、实际、过度、孤儿、陈旧、紧急、已撤销仍活跃及独立复核权限 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "6.6",
      "control": 6,
      "title_en": "Establish and Maintain an Inventory of Authentication and Authorization Systems",
      "title_zh": "认证与授权系统总账",
      "first_ig": 2,
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Software",
      "security_function": "Identify",
      "patterns": [
        "identity",
        "inventory"
      ],
      "expanded_complexity": true,
      "cas_context": {
        "dependencies": [
          "1.1",
          "2.1"
        ],
        "variables": [
          "GV5",
          "GV23",
          "M1",
          "M2",
          "M3",
          "M4",
          "M5",
          "M6"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [
        "annually"
      ],
      "implementation_contract": {
        "en": {
          "scope": "Include directories, IdPs, MFA, PKI, PAM, SSO brokers, authorization engines, cloud IAM, local account stores, secrets managers and external providers that issue identities, credentials or decisions.",
          "build": "Record owner, purpose, tenants/regions, assurance methods, upstream/downstream trusts, admin and break-glass paths, data, availability/recovery, supported lifecycle and last review.",
          "proof": "Trace representative sign-in and authorization decisions end to end, then disable a link or test tenant to verify known dependencies and fail behavior.",
          "boundary": "The CAS denominator uses current inventory and omits authorized systems missing from that inventory, which can inflate the score."
        },
        "zh": {
          "scope": "包括目录、IdP、MFA、PKI、PAM、SSO Broker、授权引擎、云 IAM、本地账户库、秘密管理器和外部身份商；凡能发身份、凭据或决定都在范围。",
          "build": "记录责任人、用途、租户/地区、保证方式、上下游信任、管理/破窗路径、数据、可用/恢复、支持生命周期与复核日；至少每年及信任/服务商变化时与软件、云/SaaS、架构台账对账。",
          "proof": "端到端追踪代表登录和授权，再停一个测试信任链，验证依赖和故障模式；把实时联邦 Metadata、应用、证书签发者和秘密系统与台账比较，分母取独立发现的全部权威系统。",
          "boundary": "CAS 用“当前台账系统数”作分母，漏记系统反而会提高分数。"
        }
      },
      "category_counts": {
        "outcome": 8,
        "scope": 8,
        "ownership": 8,
        "data": 8,
        "integration": 8,
        "control": 8,
        "timing": 8,
        "exception": 8,
        "evidence": 8,
        "security": 8,
        "testing": 8,
        "operations": 8
      },
      "requirement_count": 96,
      "requirements": [
        {
          "code": "CIS-6.6-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "6.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Establish and Maintain an Inventory of Authentication and Authorization Systems; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“认证与授权系统总账”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-6.6-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "6.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 6.6, official Asset Class Software, Security Function Identify, and IG2 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 6.6、官方资产类别“软件”、安全功能“识别”和首次出现的 IG2，并保存来源抓取日期。"
        },
        {
          "code": "CIS-6.6-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "6.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Include directories, IdPs, MFA, PKI, PAM, SSO brokers, authorization engines, cloud IAM, local account stores, secrets managers and external providers that issue identities, credentials or decisions.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“包括目录、IdP、MFA、PKI、PAM、SSO Broker、授权引擎、云 IAM、本地账户库、秘密管理器和外部身份商；凡能发身份、凭据或决定都在范围。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-6.6-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "6.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-6.6-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "6.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Establish and Maintain an Inventory of Authentication and Authorization Systems to its operating object—effective entitlements for human, service, workload, provider, emergency, and delegated identities across every access path—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“认证与授权系统总账”连接到其运营对象——人员、服务、工作负载、提供商、紧急和委派身份在所有访问路径上的实际权限——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-6.6-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "6.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "For Establish and Maintain an Inventory of Authentication and Authorization Systems, express success as an observable decision over effective identity, authentication, authorization, privilege, session, and revocation state across every access path; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“认证与授权系统总账”，以 所有访问路径上的实际身份、认证、授权、权限、会话和撤销状态 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-6.6-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "6.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "For Establish and Maintain an Inventory of Authentication and Authorization Systems, express success as an observable decision over observed, approved, unapproved, ownerless, stale, duplicate, and retired object identity; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“认证与授权系统总账”，以 已观测、已批准、未批准、无责任人、陈旧、重复和已退役对象身份 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-6.6-OUT-08",
          "local_code": "OUT-08",
          "display_code": "O08",
          "safeguard_id": "6.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "For the expanded Establish and Maintain an Inventory of Authentication and Authorization Systems scope, resolve conflicts among security, safety, privacy, legal, availability, customer, and operational objectives through an explicit risk decision.",
          "zh": "对“认证与授权系统总账”的扩展范围，通过显式风险决策解决安全、安全生产、隐私、法律、可用性、客户和运营目标冲突。"
        },
        {
          "code": "CIS-6.6-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "6.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-6.6-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "6.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-6.6-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "6.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-6.6-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "6.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-6.6-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "6.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across direct grants, inherited rights, nested groups, cached sessions, local accounts, API keys, federation failure, unsupported MFA, and emergency access; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 直接授权、继承权限、嵌套组、缓存会话、本地账户、API 密钥、联邦失效、不支持 MFA 和紧急访问 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-6.6-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "6.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Include shared and service identities, nested groups, direct grants, cached sessions, federation gaps, recovery channels, API keys, emergency access, and provider support in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 共享与服务身份、嵌套组、直接授权、缓存会话、联邦缺口、恢复通道、API 密钥、紧急访问和提供商支持 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-6.6-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "6.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Include dormant, ephemeral, disconnected, externally managed, provider-held, aliased, cloned, and cross-tenant objects in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 休眠、短生、离线、外部托管、提供商持有、别名、克隆和跨租户对象 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-6.6-SCP-08",
          "local_code": "SCP-08",
          "display_code": "P08",
          "safeguard_id": "6.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Define nested scope at enterprise, business service, tenant, environment, platform, object, identity, data set, and transaction levels; prohibit a parent result from hiding a failing child.",
          "zh": "按企业、业务服务、租户、环境、平台、对象、身份、数据集和交易定义嵌套范围，禁止父级结果遮蔽失败子级。"
        },
        {
          "code": "CIS-6.6-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "6.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-6.6-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "6.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-6.6-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "6.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-6.6-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "6.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-6.6-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "6.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind resource and data owners, managers, identity teams, platform operators, security, HR, and independent reviewers to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 资源与数据责任人、直属经理、身份团队、平台运营方、安全、HR 和独立复核人 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-6.6-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "6.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Name who may transition requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-6.6-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "6.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Name who may transition discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-6.6-OWN-08",
          "local_code": "OWN-08",
          "display_code": "W08",
          "safeguard_id": "6.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Model delegated authority, quorum or dual approval where warranted, escalation deadlines, provider handoffs, conflict resolution, and executive risk acceptance.",
          "zh": "建模委派权限、必要时的双人或法定人数审批、升级期限、提供商交接、冲突解决和管理层风险接受。"
        },
        {
          "code": "CIS-6.6-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "6.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-6.6-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "6.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-6.6-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "6.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV5, GV23, M1, M2, M3, M4, M5, M6) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV5, GV23, M1, M2, M3, M4, M5, M6）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-6.6-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "6.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-6.6-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "6.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the access request, approval, policy, and effective-permission authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把访问申请、审批、策略与有效权限权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-6.6-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "6.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated.",
          "zh": "对生命周期“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-6.6-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "6.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence.",
          "zh": "对生命周期“发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-6.6-DAT-08",
          "local_code": "DAT-08",
          "display_code": "D08",
          "safeguard_id": "6.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Version schemas and state transitions with migration, backfill, deduplication, lineage, historical denominator, deletion, and rollback semantics.",
          "zh": "对模式和状态转换做版本管理，定义迁移、回填、去重、血缘、历史分母、删除和回滚语义。"
        },
        {
          "code": "CIS-6.6-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "6.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 1.1, Safeguard 2.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 1.1、Safeguard 2.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-6.6-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "6.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-6.6-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "6.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-6.6-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "6.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-6.6-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "6.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile HR and ticket workflows, IAM/SSO, directories, application roles, cloud policies, PAM, network access, data ACLs, and provider controls and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 HR 与工单流程、IAM/SSO、目录、应用角色、云策略、PAM、网络访问、数据 ACL 和提供商控制，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-6.6-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "6.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Require every connector carrying effective identity, authentication, authorization, privilege, session, and revocation state across every access path to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 所有访问路径上的实际身份、认证、授权、权限、会话和撤销状态 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-6.6-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "6.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Require every connector carrying observed, approved, unapproved, ownerless, stale, duplicate, and retired object identity to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 已观测、已批准、未批准、无责任人、陈旧、重复和已退役对象身份 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-6.6-INT-08",
          "local_code": "INT-08",
          "display_code": "I08",
          "safeguard_id": "6.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Define consistency rules across disagreeing sources, source precedence, confidence, reconciliation queues, dead-letter handling, reprocessing, and end-to-end trace identity.",
          "zh": "定义冲突来源的一致性、优先级、置信度、对账队列、死信、重处理和端到端追踪身份。"
        },
        {
          "code": "CIS-6.6-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "6.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Record owner, purpose, tenants/regions, assurance methods, upstream/downstream trusts, admin and break-glass paths, data, availability/recovery, supported lifecycle and last review.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“记录责任人、用途、租户/地区、保证方式、上下游信任、管理/破窗路径、数据、可用/恢复、支持生命周期与复核日；至少每年及信任/服务商变化时与软件、云/SaaS、架构台账对账。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-6.6-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "6.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-6.6-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "6.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-6.6-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "6.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-6.6-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "6.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the access request, approval, policy, and effective-permission authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在访问申请、审批、策略与有效权限权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-6.6-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "6.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Implement the explicit state machine requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-6.6-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "6.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Implement the explicit state machine discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-6.6-CTL-08",
          "local_code": "CTL-08",
          "display_code": "C08",
          "safeguard_id": "6.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Specify concurrent decisions, partial success, compensating transactions, repeated requests, stale policy, dependency outage, and recovery from an interrupted state transition.",
          "zh": "定义并发决策、部分成功、补偿事务、重复请求、陈旧策略、依赖中断和中途状态转换恢复。"
        },
        {
          "code": "CIS-6.6-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "6.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (annually); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（annually）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-6.6-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "6.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-6.6-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "6.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-6.6-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "6.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-6.6-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "6.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in effective entitlements for human, service, workload, provider, emergency, and delegated identities across every access path; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 人员、服务、工作负载、提供商、紧急和委派身份在所有访问路径上的实际权限 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-6.6-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "6.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated; alert before each deadline becomes overdue.",
          "zh": "为“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-6.6-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "6.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence; alert before each deadline becomes overdue.",
          "zh": "为“发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-6.6-TIM-08",
          "local_code": "TIM-08",
          "display_code": "T08",
          "safeguard_id": "6.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Allocate an end-to-end SLO budget across discovery, collection, processing, approval, enforcement, verification, and closure; prioritize overdue work by consequence and exposure.",
          "zh": "把端到端 SLO 预算分配到发现、采集、处理、审批、执行、验证和关闭，并按后果与暴露排列逾期工作。"
        },
        {
          "code": "CIS-6.6-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "6.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “The CAS denominator uses current inventory and omits authorized systems missing from that inventory, which can inflate the score.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“CAS 用“当前台账系统数”作分母，漏记系统反而会提高分数。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-6.6-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "6.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-6.6-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "6.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-6.6-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "6.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-6.6-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "6.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat direct grants, inherited rights, nested groups, cached sessions, local accounts, API keys, federation failure, unsupported MFA, and emergency access as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 直接授权、继承权限、嵌套组、缓存会话、本地账户、API 密钥、联邦失效、不支持 MFA 和紧急访问 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-6.6-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "6.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Treat shared and service identities, nested groups, direct grants, cached sessions, federation gaps, recovery channels, API keys, emergency access, and provider support as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 共享与服务身份、嵌套组、直接授权、缓存会话、联邦缺口、恢复通道、API 密钥、紧急访问和提供商支持 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-6.6-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "6.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Treat dormant, ephemeral, disconnected, externally managed, provider-held, aliased, cloned, and cross-tenant objects as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 休眠、短生、离线、外部托管、提供商持有、别名、克隆和跨租户对象 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-6.6-EXC-08",
          "local_code": "EXC-08",
          "display_code": "X08",
          "safeguard_id": "6.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Exercise compound failures where an exception, stale source, provider outage, unavailable owner, and degraded control overlap; define one safe command and one accountable decision.",
          "zh": "演练例外、陈旧来源、提供商中断、责任人不可用和控制降级同时出现的复合故障，明确一条安全指令和一个责任决策。"
        },
        {
          "code": "CIS-6.6-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "6.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Trace representative sign-in and authorization decisions end to end, then disable a link or test tenant to verify known dependencies and fail behavior.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“端到端追踪代表登录和授权，再停一个测试信任链，验证依赖和故障模式；把实时联邦 Metadata、应用、证书签发者和秘密系统与台账比较，分母取独立发现的全部权威系统。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-6.6-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "6.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-6.6-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "6.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 8 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、8 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-6.6-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "6.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-6.6-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "6.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the access request, approval, policy, and effective-permission authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以访问申请、审批、策略与有效权限权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-6.6-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "6.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Publish requested, approved, effective, excessive, orphaned, stale, emergency, revoked-but-active, and independently reviewed rights with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 申请、批准、实际、过度、孤儿、陈旧、紧急、已撤销仍活跃及独立复核权限，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-6.6-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "6.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Publish matched, missing, duplicate, stale, ownerless, unapproved, unevaluable, and retired-without-proof counts with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 匹配、缺失、重复、陈旧、无责任人、未批准、不可评估及无证明退役数量，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-6.6-EVD-08",
          "local_code": "EVD-08",
          "display_code": "E08",
          "safeguard_id": "6.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Require an independent party to reconstruct the decision from source receipts and reproduce the population, state transition, calculation, test result, exception, and final closure.",
          "zh": "要求独立人员使用来源回执重建决策，并复现总体、状态转换、计算、测试结果、例外和最终关闭。"
        },
        {
          "code": "CIS-6.6-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "6.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-6.6-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "6.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-6.6-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "6.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-6.6-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "6.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-6.6-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "6.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the access request, approval, policy, and effective-permission authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护访问申请、审批、策略与有效权限权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-6.6-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "6.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Restrict authority to change requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-6.6-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "6.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Restrict authority to change discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-6.6-SEC-08",
          "local_code": "SEC-08",
          "display_code": "S08",
          "safeguard_id": "6.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Threat-model the implementation system itself: forged evidence, poisoned inventory, privilege abuse, cross-tenant confusion, policy rollback, audit deletion, denial of service, and recovery compromise.",
          "zh": "威胁建模实施系统自身：伪造证据、污染清单、权限滥用、跨租户混淆、策略回滚、审计删除、拒绝服务和恢复失陷。"
        },
        {
          "code": "CIS-6.6-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "6.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-6.6-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "6.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-6.6-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "6.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-6.6-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "6.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-6.6-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "6.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise allowed and denied identities, joiner/mover/leaver changes, step-up and recovery paths, session revocation, privilege escalation, and policy outage through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 允许与拒绝身份、入转离变更、升级认证与恢复路径、会话撤销、提权和策略中断，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-6.6-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "6.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Run the positive control an authorized identity using the required assurance and least privilege; exercise negative, stale, duplicate, bypass, and outage controls including an unauthorized identity, missing factor, stale session, direct grant, inherited excess, revoked token, and recovery bypass.",
          "zh": "运行正向控制“使用所需保证级别和最小权限的授权身份”，并执行包含“未授权身份、缺失认证因子、陈旧会话、直接授权、继承过权、已撤销令牌和恢复绕过”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-6.6-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "6.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Run the positive control a seeded approved object reconciled from two independent sources; exercise negative, stale, duplicate, bypass, and outage controls including an unknown object, duplicate identity, stale record, vanished object, failed source, and cross-tenant collision.",
          "zh": "运行正向控制“从两个独立来源对账的一项植入已批准对象”，并执行包含“未知对象、重复身份、陈旧记录、突然消失对象、失效来源和跨租户碰撞”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-6.6-TST-08",
          "local_code": "TST-08",
          "display_code": "V08",
          "safeguard_id": "6.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Build a pairwise platform-and-failure matrix, then add high-consequence multi-factor cases, historical regression, source substitution, red-team challenge, and assessor replay.",
          "zh": "建立平台—故障两两组合矩阵，再加入高后果多因素案例、历史回归、来源替换、红队挑战和评估方重放。"
        },
        {
          "code": "CIS-6.6-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "6.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-6.6-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "6.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-6.6-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "6.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-6.6-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "6.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-6.6-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "6.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever HR and ticket workflows, IAM/SSO, directories, application roles, cloud policies, PAM, network access, data ACLs, and provider controls change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 HR 与工单流程、IAM/SSO、目录、应用角色、云策略、PAM、网络访问、数据 ACL 和提供商控制 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-6.6-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "6.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Use requested, approved, effective, excessive, orphaned, stale, emergency, revoked-but-active, and independently reviewed rights to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 申请、批准、实际、过度、孤儿、陈旧、紧急、已撤销仍活跃及独立复核权限 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-6.6-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "6.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Use matched, missing, duplicate, stale, ownerless, unapproved, unevaluable, and retired-without-proof counts to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 匹配、缺失、重复、陈旧、无责任人、未批准、不可评估及无证明退役数量 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-6.6-OPS-08",
          "local_code": "OPS-08",
          "display_code": "R08",
          "safeguard_id": "6.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Use canary deployment, kill criteria, rollback, backlog burn-down, exception reduction, source-quality targets, quarterly design review, and a measurable retirement plan.",
          "zh": "采用金丝雀、停止标准、回滚、积压燃尽、例外缩减、来源质量目标、季度设计复核和可量化退役计划。"
        }
      ]
    },
    {
      "id": "6.7",
      "control": 6,
      "title_en": "Centralize Access Control",
      "title_zh": "集中访问控制",
      "first_ig": 2,
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Users",
      "security_function": "Protect",
      "patterns": [
        "identity",
        "enforcement"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "1.1",
          "2.1"
        ],
        "variables": [
          "GV1",
          "GV5",
          "M1",
          "M2",
          "M3"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "The safeguard centralizes authorization where assets and software support a directory or SSO, while preserving resource-level enforcement.",
          "build": "Use central groups, roles, policy engines or identity-aware proxies to drive access; automate provisioning/deprovisioning, restrict local grants and reconcile effective permissions.",
          "proof": "Change a central role and verify access changes across representative systems, then attempt a local account, direct object permission and stale token bypass.",
          "boundary": "An IdP outage or compromise becomes systemic, requiring separated administration, resilient break-glass and tested recovery."
        },
        "zh": {
          "scope": "集中化适用于支持目录或 SSO 的资产与软件，同时仍要在资源层执法。",
          "build": "用中央组、角色、策略引擎或身份代理驱动访问，自动预配/撤销，限制本地授权并对账有效权限；明确哪些决定留在应用，以及中央身份、属性和资源策略如何组合。",
          "proof": "改变中央角色，验证代表系统访问同步变化；再尝试本地账户、直接对象权限和旧 Token 绕过。",
          "boundary": "IdP 故障或失陷会系统性扩散，需要分权管理、弹性破窗和恢复。"
        }
      },
      "category_counts": {
        "outcome": 7,
        "scope": 7,
        "ownership": 7,
        "data": 7,
        "integration": 7,
        "control": 7,
        "timing": 7,
        "exception": 7,
        "evidence": 7,
        "security": 7,
        "testing": 7,
        "operations": 7
      },
      "requirement_count": 84,
      "requirements": [
        {
          "code": "CIS-6.7-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "6.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Centralize Access Control; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“集中访问控制”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-6.7-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "6.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 6.7, official Asset Class Users, Security Function Protect, and IG2 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 6.7、官方资产类别“用户与身份”、安全功能“保护”和首次出现的 IG2，并保存来源抓取日期。"
        },
        {
          "code": "CIS-6.7-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "6.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “The safeguard centralizes authorization where assets and software support a directory or SSO, while preserving resource-level enforcement.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“集中化适用于支持目录或 SSO 的资产与软件，同时仍要在资源层执法。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-6.7-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "6.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-6.7-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "6.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Centralize Access Control to its operating object—effective entitlements for human, service, workload, provider, emergency, and delegated identities across every access path—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“集中访问控制”连接到其运营对象——人员、服务、工作负载、提供商、紧急和委派身份在所有访问路径上的实际权限——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-6.7-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "6.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "For Centralize Access Control, express success as an observable decision over effective identity, authentication, authorization, privilege, session, and revocation state across every access path; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“集中访问控制”，以 所有访问路径上的实际身份、认证、授权、权限、会话和撤销状态 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-6.7-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "6.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "For Centralize Access Control, express success as an observable decision over an enforceable allow, deny, contain, quarantine, require, remove, or transform decision at the closest reliable control point; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“集中访问控制”，以 在最近可靠控制点执行允许、拒绝、遏制、隔离、强制、移除或转换决策 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-6.7-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "6.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-6.7-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "6.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-6.7-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "6.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-6.7-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "6.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-6.7-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "6.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across direct grants, inherited rights, nested groups, cached sessions, local accounts, API keys, federation failure, unsupported MFA, and emergency access; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 直接授权、继承权限、嵌套组、缓存会话、本地账户、API 密钥、联邦失效、不支持 MFA 和紧急访问 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-6.7-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "6.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Include shared and service identities, nested groups, direct grants, cached sessions, federation gaps, recovery channels, API keys, emergency access, and provider support in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 共享与服务身份、嵌套组、直接授权、缓存会话、联邦缺口、恢复通道、API 密钥、紧急访问和提供商支持 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-6.7-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "6.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Include audit-only mode, unsupported platforms, local overrides, race conditions, cached state, alternate paths, fail-open behavior, and emergency bypass in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 仅审计模式、不支持平台、本地覆盖、竞态、缓存状态、替代路径、故障开放和紧急绕过 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-6.7-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "6.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-6.7-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "6.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-6.7-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "6.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-6.7-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "6.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-6.7-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "6.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind resource and data owners, managers, identity teams, platform operators, security, HR, and independent reviewers to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 资源与数据责任人、直属经理、身份团队、平台运营方、安全、HR 和独立复核人 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-6.7-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "6.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Name who may transition requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-6.7-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "6.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Name who may transition observe → evaluate → decide → enforce → verify outcome → rollback/close, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-6.7-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "6.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-6.7-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "6.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-6.7-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "6.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV1, GV5, M1, M2, M3) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV1, GV5, M1, M2, M3）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-6.7-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "6.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-6.7-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "6.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the access request, approval, policy, and effective-permission authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把访问申请、审批、策略与有效权限权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-6.7-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "6.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated.",
          "zh": "对生命周期“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-6.7-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "6.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle observe → evaluate → decide → enforce → verify outcome → rollback/close.",
          "zh": "对生命周期“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-6.7-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "6.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 1.1, Safeguard 2.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 1.1、Safeguard 2.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-6.7-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "6.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-6.7-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "6.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-6.7-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "6.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-6.7-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "6.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile HR and ticket workflows, IAM/SSO, directories, application roles, cloud policies, PAM, network access, data ACLs, and provider controls and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 HR 与工单流程、IAM/SSO、目录、应用角色、云策略、PAM、网络访问、数据 ACL 和提供商控制，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-6.7-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "6.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Require every connector carrying effective identity, authentication, authorization, privilege, session, and revocation state across every access path to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 所有访问路径上的实际身份、认证、授权、权限、会话和撤销状态 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-6.7-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "6.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Require every connector carrying an enforceable allow, deny, contain, quarantine, require, remove, or transform decision at the closest reliable control point to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 在最近可靠控制点执行允许、拒绝、遏制、隔离、强制、移除或转换决策 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-6.7-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "6.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Use central groups, roles, policy engines or identity-aware proxies to drive access; automate provisioning/deprovisioning, restrict local grants and reconcile effective permissions.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“用中央组、角色、策略引擎或身份代理驱动访问，自动预配/撤销，限制本地授权并对账有效权限；明确哪些决定留在应用，以及中央身份、属性和资源策略如何组合。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-6.7-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "6.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-6.7-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "6.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-6.7-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "6.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-6.7-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "6.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the access request, approval, policy, and effective-permission authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在访问申请、审批、策略与有效权限权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-6.7-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "6.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Implement the explicit state machine requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-6.7-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "6.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Implement the explicit state machine observe → evaluate → decide → enforce → verify outcome → rollback/close; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-6.7-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "6.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-6.7-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "6.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-6.7-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "6.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-6.7-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "6.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-6.7-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "6.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in effective entitlements for human, service, workload, provider, emergency, and delegated identities across every access path; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 人员、服务、工作负载、提供商、紧急和委派身份在所有访问路径上的实际权限 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-6.7-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "6.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated; alert before each deadline becomes overdue.",
          "zh": "为“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-6.7-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "6.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for observe → evaluate → decide → enforce → verify outcome → rollback/close; alert before each deadline becomes overdue.",
          "zh": "为“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-6.7-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "6.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “An IdP outage or compromise becomes systemic, requiring separated administration, resilient break-glass and tested recovery.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“IdP 故障或失陷会系统性扩散，需要分权管理、弹性破窗和恢复。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-6.7-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "6.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-6.7-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "6.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-6.7-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "6.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-6.7-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "6.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat direct grants, inherited rights, nested groups, cached sessions, local accounts, API keys, federation failure, unsupported MFA, and emergency access as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 直接授权、继承权限、嵌套组、缓存会话、本地账户、API 密钥、联邦失效、不支持 MFA 和紧急访问 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-6.7-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "6.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Treat shared and service identities, nested groups, direct grants, cached sessions, federation gaps, recovery channels, API keys, emergency access, and provider support as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 共享与服务身份、嵌套组、直接授权、缓存会话、联邦缺口、恢复通道、API 密钥、紧急访问和提供商支持 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-6.7-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "6.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Treat audit-only mode, unsupported platforms, local overrides, race conditions, cached state, alternate paths, fail-open behavior, and emergency bypass as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 仅审计模式、不支持平台、本地覆盖、竞态、缓存状态、替代路径、故障开放和紧急绕过 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-6.7-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "6.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Change a central role and verify access changes across representative systems, then attempt a local account, direct object permission and stale token bypass.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“改变中央角色，验证代表系统访问同步变化；再尝试本地账户、直接对象权限和旧 Token 绕过。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-6.7-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "6.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-6.7-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "6.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 5 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、5 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-6.7-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "6.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-6.7-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "6.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the access request, approval, policy, and effective-permission authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以访问申请、审批、策略与有效权限权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-6.7-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "6.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Publish requested, approved, effective, excessive, orphaned, stale, emergency, revoked-but-active, and independently reviewed rights with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 申请、批准、实际、过度、孤儿、陈旧、紧急、已撤销仍活跃及独立复核权限，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-6.7-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "6.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Publish eligible, enforcing, audit-only, failed, bypassed, excepted, rolled-back, and outcome-verified populations with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 适用、已执行、仅审计、失败、被绕过、例外、已回滚和结果已验证总体，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-6.7-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "6.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-6.7-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "6.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-6.7-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "6.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-6.7-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "6.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-6.7-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "6.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the access request, approval, policy, and effective-permission authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护访问申请、审批、策略与有效权限权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-6.7-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "6.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Restrict authority to change requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-6.7-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "6.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Restrict authority to change observe → evaluate → decide → enforce → verify outcome → rollback/close; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-6.7-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "6.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-6.7-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "6.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-6.7-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "6.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-6.7-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "6.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-6.7-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "6.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise allowed and denied identities, joiner/mover/leaver changes, step-up and recovery paths, session revocation, privilege escalation, and policy outage through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 允许与拒绝身份、入转离变更、升级认证与恢复路径、会话撤销、提权和策略中断，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-6.7-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "6.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Run the positive control an authorized identity using the required assurance and least privilege; exercise negative, stale, duplicate, bypass, and outage controls including an unauthorized identity, missing factor, stale session, direct grant, inherited excess, revoked token, and recovery bypass.",
          "zh": "运行正向控制“使用所需保证级别和最小权限的授权身份”，并执行包含“未授权身份、缺失认证因子、陈旧会话、直接授权、继承过权、已撤销令牌和恢复绕过”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-6.7-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "6.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Run the positive control an approved business action that completes through the enforced path; exercise negative, stale, duplicate, bypass, and outage controls including a prohibited action, alternate path, local override, stale policy, control outage, emergency bypass, and rollback failure.",
          "zh": "运行正向控制“通过受控路径完成的一项获批业务动作”，并执行包含“禁止动作、替代路径、本地覆盖、陈旧策略、控制中断、紧急绕过和回滚失败”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-6.7-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "6.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-6.7-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "6.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-6.7-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "6.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-6.7-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "6.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-6.7-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "6.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever HR and ticket workflows, IAM/SSO, directories, application roles, cloud policies, PAM, network access, data ACLs, and provider controls change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 HR 与工单流程、IAM/SSO、目录、应用角色、云策略、PAM、网络访问、数据 ACL 和提供商控制 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-6.7-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "6.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Use requested, approved, effective, excessive, orphaned, stale, emergency, revoked-but-active, and independently reviewed rights to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 申请、批准、实际、过度、孤儿、陈旧、紧急、已撤销仍活跃及独立复核权限 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-6.7-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "6.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Use eligible, enforcing, audit-only, failed, bypassed, excepted, rolled-back, and outcome-verified populations to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 适用、已执行、仅审计、失败、被绕过、例外、已回滚和结果已验证总体 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "6.8",
      "control": 6,
      "title_en": "Define and Maintain Role-Based Access Control",
      "title_zh": "基于角色的访问控制",
      "first_ig": 3,
      "implementation_groups": [
        3
      ],
      "asset_class": "Users",
      "security_function": "Govern",
      "patterns": [
        "identity",
        "enforcement"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "5.1"
        ],
        "variables": [
          "GV22",
          "M1",
          "M2",
          "M3",
          "M4",
          "M5"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [
        "annually"
      ],
      "implementation_contract": {
        "en": {
          "scope": "The role model covers human job functions and, where useful, workload functions across enterprise assets and data.",
          "build": "Define business-owned roles, permissions, eligibility, approval, segregation conflicts and lifecycle; separate base, elevated and temporary access.",
          "proof": "Test representative tasks for allowed and disallowed roles, inspect nested groups and direct grants, and verify role change removes old access.",
          "boundary": "RBAC alone handles context, attributes and object ownership poorly, so ABAC or relationship controls may supplement it under the same governance."
        },
        "zh": {
          "scope": "角色模型覆盖人工岗位，也可覆盖工作负载职能；角色必须表达必要权利与约束。",
          "build": "由业务定义角色、权限、资格、批准、职责冲突和生命周期，分开基础、提升与临时访问；账户映射角色，控制直接例外，至少每年审查有效权限，组织或系统变化时重构。",
          "proof": "用允许/不允许角色执行代表任务，检查嵌套组和直接授权，并验证调岗移除旧权。",
          "boundary": "RBAC 不擅长上下文、属性和对象关系，可由 ABAC/关系控制补充，但归同一治理。"
        }
      },
      "category_counts": {
        "outcome": 7,
        "scope": 7,
        "ownership": 7,
        "data": 7,
        "integration": 7,
        "control": 7,
        "timing": 7,
        "exception": 7,
        "evidence": 7,
        "security": 7,
        "testing": 7,
        "operations": 7
      },
      "requirement_count": 84,
      "requirements": [
        {
          "code": "CIS-6.8-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "6.8",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Define and Maintain Role-Based Access Control; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“基于角色的访问控制”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-6.8-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "6.8",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 6.8, official Asset Class Users, Security Function Govern, and IG3 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 6.8、官方资产类别“用户与身份”、安全功能“治理”和首次出现的 IG3，并保存来源抓取日期。"
        },
        {
          "code": "CIS-6.8-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "6.8",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “The role model covers human job functions and, where useful, workload functions across enterprise assets and data.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“角色模型覆盖人工岗位，也可覆盖工作负载职能；角色必须表达必要权利与约束。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-6.8-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "6.8",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-6.8-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "6.8",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Define and Maintain Role-Based Access Control to its operating object—effective entitlements for human, service, workload, provider, emergency, and delegated identities across every access path—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“基于角色的访问控制”连接到其运营对象——人员、服务、工作负载、提供商、紧急和委派身份在所有访问路径上的实际权限——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-6.8-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "6.8",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "For Define and Maintain Role-Based Access Control, express success as an observable decision over effective identity, authentication, authorization, privilege, session, and revocation state across every access path; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“基于角色的访问控制”，以 所有访问路径上的实际身份、认证、授权、权限、会话和撤销状态 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-6.8-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "6.8",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "For Define and Maintain Role-Based Access Control, express success as an observable decision over an enforceable allow, deny, contain, quarantine, require, remove, or transform decision at the closest reliable control point; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“基于角色的访问控制”，以 在最近可靠控制点执行允许、拒绝、遏制、隔离、强制、移除或转换决策 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-6.8-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "6.8",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-6.8-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "6.8",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-6.8-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "6.8",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-6.8-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "6.8",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-6.8-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "6.8",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across direct grants, inherited rights, nested groups, cached sessions, local accounts, API keys, federation failure, unsupported MFA, and emergency access; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 直接授权、继承权限、嵌套组、缓存会话、本地账户、API 密钥、联邦失效、不支持 MFA 和紧急访问 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-6.8-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "6.8",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Include shared and service identities, nested groups, direct grants, cached sessions, federation gaps, recovery channels, API keys, emergency access, and provider support in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 共享与服务身份、嵌套组、直接授权、缓存会话、联邦缺口、恢复通道、API 密钥、紧急访问和提供商支持 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-6.8-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "6.8",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Include audit-only mode, unsupported platforms, local overrides, race conditions, cached state, alternate paths, fail-open behavior, and emergency bypass in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 仅审计模式、不支持平台、本地覆盖、竞态、缓存状态、替代路径、故障开放和紧急绕过 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-6.8-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "6.8",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-6.8-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "6.8",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-6.8-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "6.8",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-6.8-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "6.8",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-6.8-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "6.8",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind resource and data owners, managers, identity teams, platform operators, security, HR, and independent reviewers to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 资源与数据责任人、直属经理、身份团队、平台运营方、安全、HR 和独立复核人 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-6.8-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "6.8",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Name who may transition requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-6.8-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "6.8",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Name who may transition observe → evaluate → decide → enforce → verify outcome → rollback/close, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-6.8-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "6.8",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-6.8-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "6.8",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-6.8-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "6.8",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV22, M1, M2, M3, M4, M5) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV22, M1, M2, M3, M4, M5）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-6.8-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "6.8",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-6.8-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "6.8",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the access request, approval, policy, and effective-permission authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把访问申请、审批、策略与有效权限权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-6.8-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "6.8",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated.",
          "zh": "对生命周期“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-6.8-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "6.8",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle observe → evaluate → decide → enforce → verify outcome → rollback/close.",
          "zh": "对生命周期“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-6.8-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "6.8",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 5.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 5.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-6.8-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "6.8",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-6.8-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "6.8",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-6.8-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "6.8",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-6.8-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "6.8",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile HR and ticket workflows, IAM/SSO, directories, application roles, cloud policies, PAM, network access, data ACLs, and provider controls and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 HR 与工单流程、IAM/SSO、目录、应用角色、云策略、PAM、网络访问、数据 ACL 和提供商控制，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-6.8-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "6.8",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Require every connector carrying effective identity, authentication, authorization, privilege, session, and revocation state across every access path to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 所有访问路径上的实际身份、认证、授权、权限、会话和撤销状态 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-6.8-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "6.8",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Require every connector carrying an enforceable allow, deny, contain, quarantine, require, remove, or transform decision at the closest reliable control point to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 在最近可靠控制点执行允许、拒绝、遏制、隔离、强制、移除或转换决策 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-6.8-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "6.8",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Define business-owned roles, permissions, eligibility, approval, segregation conflicts and lifecycle; separate base, elevated and temporary access.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“由业务定义角色、权限、资格、批准、职责冲突和生命周期，分开基础、提升与临时访问；账户映射角色，控制直接例外，至少每年审查有效权限，组织或系统变化时重构。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-6.8-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "6.8",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-6.8-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "6.8",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-6.8-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "6.8",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-6.8-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "6.8",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the access request, approval, policy, and effective-permission authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在访问申请、审批、策略与有效权限权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-6.8-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "6.8",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Implement the explicit state machine requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-6.8-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "6.8",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Implement the explicit state machine observe → evaluate → decide → enforce → verify outcome → rollback/close; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-6.8-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "6.8",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (annually); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（annually）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-6.8-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "6.8",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-6.8-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "6.8",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-6.8-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "6.8",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-6.8-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "6.8",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in effective entitlements for human, service, workload, provider, emergency, and delegated identities across every access path; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 人员、服务、工作负载、提供商、紧急和委派身份在所有访问路径上的实际权限 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-6.8-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "6.8",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated; alert before each deadline becomes overdue.",
          "zh": "为“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-6.8-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "6.8",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for observe → evaluate → decide → enforce → verify outcome → rollback/close; alert before each deadline becomes overdue.",
          "zh": "为“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-6.8-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "6.8",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “RBAC alone handles context, attributes and object ownership poorly, so ABAC or relationship controls may supplement it under the same governance.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“RBAC 不擅长上下文、属性和对象关系，可由 ABAC/关系控制补充，但归同一治理。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-6.8-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "6.8",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-6.8-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "6.8",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-6.8-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "6.8",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-6.8-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "6.8",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat direct grants, inherited rights, nested groups, cached sessions, local accounts, API keys, federation failure, unsupported MFA, and emergency access as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 直接授权、继承权限、嵌套组、缓存会话、本地账户、API 密钥、联邦失效、不支持 MFA 和紧急访问 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-6.8-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "6.8",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Treat shared and service identities, nested groups, direct grants, cached sessions, federation gaps, recovery channels, API keys, emergency access, and provider support as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 共享与服务身份、嵌套组、直接授权、缓存会话、联邦缺口、恢复通道、API 密钥、紧急访问和提供商支持 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-6.8-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "6.8",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Treat audit-only mode, unsupported platforms, local overrides, race conditions, cached state, alternate paths, fail-open behavior, and emergency bypass as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 仅审计模式、不支持平台、本地覆盖、竞态、缓存状态、替代路径、故障开放和紧急绕过 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-6.8-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "6.8",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Test representative tasks for allowed and disallowed roles, inspect nested groups and direct grants, and verify role change removes old access.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“用允许/不允许角色执行代表任务，检查嵌套组和直接授权，并验证调岗移除旧权。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-6.8-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "6.8",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-6.8-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "6.8",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 6 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、6 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-6.8-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "6.8",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-6.8-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "6.8",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the access request, approval, policy, and effective-permission authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以访问申请、审批、策略与有效权限权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-6.8-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "6.8",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Publish requested, approved, effective, excessive, orphaned, stale, emergency, revoked-but-active, and independently reviewed rights with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 申请、批准、实际、过度、孤儿、陈旧、紧急、已撤销仍活跃及独立复核权限，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-6.8-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "6.8",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Publish eligible, enforcing, audit-only, failed, bypassed, excepted, rolled-back, and outcome-verified populations with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 适用、已执行、仅审计、失败、被绕过、例外、已回滚和结果已验证总体，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-6.8-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "6.8",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-6.8-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "6.8",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-6.8-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "6.8",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-6.8-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "6.8",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-6.8-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "6.8",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the access request, approval, policy, and effective-permission authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护访问申请、审批、策略与有效权限权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-6.8-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "6.8",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Restrict authority to change requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-6.8-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "6.8",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Restrict authority to change observe → evaluate → decide → enforce → verify outcome → rollback/close; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-6.8-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "6.8",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-6.8-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "6.8",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-6.8-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "6.8",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-6.8-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "6.8",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-6.8-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "6.8",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise allowed and denied identities, joiner/mover/leaver changes, step-up and recovery paths, session revocation, privilege escalation, and policy outage through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 允许与拒绝身份、入转离变更、升级认证与恢复路径、会话撤销、提权和策略中断，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-6.8-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "6.8",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Run the positive control an authorized identity using the required assurance and least privilege; exercise negative, stale, duplicate, bypass, and outage controls including an unauthorized identity, missing factor, stale session, direct grant, inherited excess, revoked token, and recovery bypass.",
          "zh": "运行正向控制“使用所需保证级别和最小权限的授权身份”，并执行包含“未授权身份、缺失认证因子、陈旧会话、直接授权、继承过权、已撤销令牌和恢复绕过”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-6.8-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "6.8",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Run the positive control an approved business action that completes through the enforced path; exercise negative, stale, duplicate, bypass, and outage controls including a prohibited action, alternate path, local override, stale policy, control outage, emergency bypass, and rollback failure.",
          "zh": "运行正向控制“通过受控路径完成的一项获批业务动作”，并执行包含“禁止动作、替代路径、本地覆盖、陈旧策略、控制中断、紧急绕过和回滚失败”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-6.8-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "6.8",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-6.8-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "6.8",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-6.8-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "6.8",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-6.8-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "6.8",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-6.8-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "6.8",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever HR and ticket workflows, IAM/SSO, directories, application roles, cloud policies, PAM, network access, data ACLs, and provider controls change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 HR 与工单流程、IAM/SSO、目录、应用角色、云策略、PAM、网络访问、数据 ACL 和提供商控制 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-6.8-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "6.8",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Use requested, approved, effective, excessive, orphaned, stale, emergency, revoked-but-active, and independently reviewed rights to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 申请、批准、实际、过度、孤儿、陈旧、紧急、已撤销仍活跃及独立复核权限 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-6.8-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "6.8",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Use eligible, enforcing, audit-only, failed, bypassed, excepted, rolled-back, and outcome-verified populations to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 适用、已执行、仅审计、失败、被绕过、例外、已回滚和结果已验证总体 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "7.1",
      "control": 7,
      "title_en": "Establish and Maintain a Vulnerability Management Process",
      "title_zh": "漏洞管理流程",
      "first_ig": 1,
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Documentation",
      "security_function": "Govern",
      "patterns": [
        "vulnerability",
        "governance"
      ],
      "expanded_complexity": true,
      "cas_context": {
        "dependencies": [],
        "variables": [
          "M1",
          "M2"
        ],
        "metric_branches": 0,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [
        "annually"
      ],
      "implementation_contract": {
        "en": {
          "scope": "The process covers vulnerabilities and material misconfigurations across inventoried assets, software, firmware, cloud/SaaS, containers, applications and dependencies from discovery through ownership, prioritization, treatment, verification and closure.",
          "build": "Define accountable owners, approved scanners and intelligence, authenticated/unauthenticated methods, cadence, severity and exposure inputs, ticketing, exception, disclosure, emergency action and metrics.",
          "proof": "Walk one finding from source identity and affected asset through triage, owner, due date, remediation, rescan and closure, plus one false positive and one accepted risk.",
          "boundary": "A CVE count is not risk, and absence of a scanner result is not absence of vulnerability."
        },
        "zh": {
          "scope": "覆盖台账内资产、软件、固件、云/SaaS、容器、应用和依赖中的漏洞与重要错误配置，从发现一直到认领、排序、处置、验证、关闭；同时写明各数据源看不到哪些总体或缺陷类型。",
          "build": "定义责任人、批准扫描器/情报、有/无凭据方法、周期、严重度与暴露输入、工单、例外、披露、应急和指标。",
          "proof": "把一个发现从来源身份、受影响资产一路追到分诊、责任人、到期、修复、复扫和关闭，再追一个误报和一个风险接受；检查陈旧队列、漏资产、扫描失败和重开，并说明怎样合并来源/资产身份。",
          "boundary": "CVE 数量不等于风险，扫描没结果不等于没漏洞。"
        }
      },
      "category_counts": {
        "outcome": 8,
        "scope": 8,
        "ownership": 8,
        "data": 8,
        "integration": 8,
        "control": 8,
        "timing": 8,
        "exception": 8,
        "evidence": 8,
        "security": 8,
        "testing": 8,
        "operations": 8
      },
      "requirement_count": 96,
      "requirements": [
        {
          "code": "CIS-7.1-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "7.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Establish and Maintain a Vulnerability Management Process; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“漏洞管理流程”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-7.1-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "7.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 7.1, official Asset Class Documentation, Security Function Govern, and IG1 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 7.1、官方资产类别“文档与治理”、安全功能“治理”和首次出现的 IG1，并保存来源抓取日期。"
        },
        {
          "code": "CIS-7.1-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "7.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “The process covers vulnerabilities and material misconfigurations across inventoried assets, software, firmware, cloud/SaaS, containers, applications and dependencies from discovery through ownership, prioritization, treatment, verification and closure.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“覆盖台账内资产、软件、固件、云/SaaS、容器、应用和依赖中的漏洞与重要错误配置，从发现一直到认领、排序、处置、验证、关闭；同时写明各数据源看不到哪些总体或缺陷类型。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-7.1-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "7.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-7.1-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "7.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Establish and Maintain a Vulnerability Management Process to its operating object—vulnerabilities, affected artifacts and deployments, exploitability context, remediation decisions, patches, mitigations, and residual exposure—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“漏洞管理流程”连接到其运营对象——漏洞、受影响制品与部署、可利用性上下文、修复决策、补丁、缓解措施和残余暴露——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-7.1-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "7.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "For Establish and Maintain a Vulnerability Management Process, express success as an observable decision over affected artifact identity, exploitability, business consequence, remediation choice, deployed fix, compensating control, and residual exposure; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“漏洞管理流程”，以 受影响制品身份、可利用性、业务后果、修复选择、已部署修复、补偿控制和残余暴露 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-7.1-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "7.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "For Establish and Maintain a Vulnerability Management Process, express success as an observable decision over a documented decision system with policy, process, procedure, accountable owner, approval, and review; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“漏洞管理流程”，以 包含策略、流程、程序、责任人、审批和复核的文档化决策系统 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-7.1-OUT-08",
          "local_code": "OUT-08",
          "display_code": "O08",
          "safeguard_id": "7.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "For the expanded Establish and Maintain a Vulnerability Management Process scope, resolve conflicts among security, safety, privacy, legal, availability, customer, and operational objectives through an explicit risk decision.",
          "zh": "对“漏洞管理流程”的扩展范围，通过显式风险决策解决安全、安全生产、隐私、法律、可用性、客户和运营目标冲突。"
        },
        {
          "code": "CIS-7.1-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "7.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-7.1-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "7.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-7.1-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "7.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-7.1-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "7.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-7.1-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "7.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across unscannable assets, stale inventories, false positives, vendor backlog, compensating controls, superseded findings, ephemeral workloads, and failed patches; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 不可扫描资产、陈旧清单、误报、厂商积压、补偿控制、被取代发现、短生工作负载和失败补丁 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-7.1-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "7.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Include unknown versions, false positives, unavailable fixes, vendor lag, ephemeral workloads, unscannable platforms, inherited dependencies, mitigation-only states, and recurrence in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 未知版本、误报、无可用修复、厂商滞后、短生工作负载、不可扫描平台、继承依赖、仅缓解状态和复发 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-7.1-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "7.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Include missing policy clauses, conflicting authorities, local deviations, obsolete documentation, and decisions made outside the governed workflow in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 策略条款缺失、权限冲突、本地偏离、文档过期及绕过治理流程的决策 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-7.1-SCP-08",
          "local_code": "SCP-08",
          "display_code": "P08",
          "safeguard_id": "7.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Define nested scope at enterprise, business service, tenant, environment, platform, object, identity, data set, and transaction levels; prohibit a parent result from hiding a failing child.",
          "zh": "按企业、业务服务、租户、环境、平台、对象、身份、数据集和交易定义嵌套范围，禁止父级结果遮蔽失败子级。"
        },
        {
          "code": "CIS-7.1-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "7.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-7.1-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "7.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-7.1-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "7.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-7.1-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "7.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-7.1-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "7.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind asset and application owners, vulnerability management, engineering, change management, threat intelligence, and risk owners to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 资产与应用责任人、漏洞管理、工程、变更管理、威胁情报和风险责任人 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-7.1-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "7.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Name who may transition discovered → validated → prioritized → assigned → fixed/mitigated/excepted → deployed → retested → closed/reopened, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 发现 → 验证 → 定级 → 分派 → 修复/缓解/例外 → 部署 → 复测 → 关闭/重开，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-7.1-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "7.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Name who may transition draft → reviewed → approved → effective → exception/withdrawn → superseded, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-7.1-OWN-08",
          "local_code": "OWN-08",
          "display_code": "W08",
          "safeguard_id": "7.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Model delegated authority, quorum or dual approval where warranted, escalation deadlines, provider handoffs, conflict resolution, and executive risk acceptance.",
          "zh": "建模委派权限、必要时的双人或法定人数审批、升级期限、提供商交接、冲突解决和管理层风险接受。"
        },
        {
          "code": "CIS-7.1-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "7.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-7.1-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "7.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-7.1-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "7.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (M1, M2) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（M1, M2）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-7.1-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "7.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-7.1-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "7.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the vulnerability finding and remediation authority linked to asset and software identity as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把与资产和软件身份关联的漏洞发现与修复权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-7.1-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "7.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle discovered → validated → prioritized → assigned → fixed/mitigated/excepted → deployed → retested → closed/reopened.",
          "zh": "对生命周期“发现 → 验证 → 定级 → 分派 → 修复/缓解/例外 → 部署 → 复测 → 关闭/重开”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-7.1-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "7.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle draft → reviewed → approved → effective → exception/withdrawn → superseded.",
          "zh": "对生命周期“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-7.1-DAT-08",
          "local_code": "DAT-08",
          "display_code": "D08",
          "safeguard_id": "7.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Version schemas and state transitions with migration, backfill, deduplication, lineage, historical denominator, deletion, and rollback semantics.",
          "zh": "对模式和状态转换做版本管理，定义迁移、回填、去重、血缘、历史分母、删除和回滚语义。"
        },
        {
          "code": "CIS-7.1-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "7.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for no explicit predecessor in the pinned CAS page; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 固定 CAS 页面没有列出显式前置项 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-7.1-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "7.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-7.1-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "7.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-7.1-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "7.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-7.1-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "7.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile authenticated and unauthenticated scanners, package and image analysis, advisories, SBOMs, cloud findings, penetration tests, tickets, and deployment evidence and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 认证与非认证扫描、包与镜像分析、公告、SBOM、云发现、渗透测试、工单和部署证据，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-7.1-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "7.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Require every connector carrying affected artifact identity, exploitability, business consequence, remediation choice, deployed fix, compensating control, and residual exposure to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 受影响制品身份、可利用性、业务后果、修复选择、已部署修复、补偿控制和残余暴露 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-7.1-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "7.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Require every connector carrying a documented decision system with policy, process, procedure, accountable owner, approval, and review to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 包含策略、流程、程序、责任人、审批和复核的文档化决策系统 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-7.1-INT-08",
          "local_code": "INT-08",
          "display_code": "I08",
          "safeguard_id": "7.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Define consistency rules across disagreeing sources, source precedence, confidence, reconciliation queues, dead-letter handling, reprocessing, and end-to-end trace identity.",
          "zh": "定义冲突来源的一致性、优先级、置信度、对账队列、死信、重处理和端到端追踪身份。"
        },
        {
          "code": "CIS-7.1-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "7.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Define accountable owners, approved scanners and intelligence, authenticated/unauthenticated methods, cadence, severity and exposure inputs, ticketing, exception, disclosure, emergency action and metrics.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“定义责任人、批准扫描器/情报、有/无凭据方法、周期、严重度与暴露输入、工单、例外、披露、应急和指标。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-7.1-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "7.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-7.1-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "7.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-7.1-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "7.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-7.1-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "7.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the vulnerability finding and remediation authority linked to asset and software identity and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在与资产和软件身份关联的漏洞发现与修复权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-7.1-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "7.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Implement the explicit state machine discovered → validated → prioritized → assigned → fixed/mitigated/excepted → deployed → retested → closed/reopened; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“发现 → 验证 → 定级 → 分派 → 修复/缓解/例外 → 部署 → 复测 → 关闭/重开”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-7.1-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "7.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Implement the explicit state machine draft → reviewed → approved → effective → exception/withdrawn → superseded; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-7.1-CTL-08",
          "local_code": "CTL-08",
          "display_code": "C08",
          "safeguard_id": "7.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Specify concurrent decisions, partial success, compensating transactions, repeated requests, stale policy, dependency outage, and recovery from an interrupted state transition.",
          "zh": "定义并发决策、部分成功、补偿事务、重复请求、陈旧策略、依赖中断和中途状态转换恢复。"
        },
        {
          "code": "CIS-7.1-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "7.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (annually); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（annually）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-7.1-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "7.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-7.1-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "7.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-7.1-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "7.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-7.1-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "7.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in vulnerabilities, affected artifacts and deployments, exploitability context, remediation decisions, patches, mitigations, and residual exposure; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 漏洞、受影响制品与部署、可利用性上下文、修复决策、补丁、缓解措施和残余暴露 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-7.1-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "7.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for discovered → validated → prioritized → assigned → fixed/mitigated/excepted → deployed → retested → closed/reopened; alert before each deadline becomes overdue.",
          "zh": "为“发现 → 验证 → 定级 → 分派 → 修复/缓解/例外 → 部署 → 复测 → 关闭/重开”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-7.1-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "7.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for draft → reviewed → approved → effective → exception/withdrawn → superseded; alert before each deadline becomes overdue.",
          "zh": "为“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-7.1-TIM-08",
          "local_code": "TIM-08",
          "display_code": "T08",
          "safeguard_id": "7.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Allocate an end-to-end SLO budget across discovery, collection, processing, approval, enforcement, verification, and closure; prioritize overdue work by consequence and exposure.",
          "zh": "把端到端 SLO 预算分配到发现、采集、处理、审批、执行、验证和关闭，并按后果与暴露排列逾期工作。"
        },
        {
          "code": "CIS-7.1-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "7.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “A CVE count is not risk, and absence of a scanner result is not absence of vulnerability.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“CVE 数量不等于风险，扫描没结果不等于没漏洞。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-7.1-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "7.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-7.1-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "7.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-7.1-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "7.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-7.1-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "7.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat unscannable assets, stale inventories, false positives, vendor backlog, compensating controls, superseded findings, ephemeral workloads, and failed patches as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 不可扫描资产、陈旧清单、误报、厂商积压、补偿控制、被取代发现、短生工作负载和失败补丁 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-7.1-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "7.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Treat unknown versions, false positives, unavailable fixes, vendor lag, ephemeral workloads, unscannable platforms, inherited dependencies, mitigation-only states, and recurrence as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 未知版本、误报、无可用修复、厂商滞后、短生工作负载、不可扫描平台、继承依赖、仅缓解状态和复发 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-7.1-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "7.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Treat missing policy clauses, conflicting authorities, local deviations, obsolete documentation, and decisions made outside the governed workflow as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 策略条款缺失、权限冲突、本地偏离、文档过期及绕过治理流程的决策 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-7.1-EXC-08",
          "local_code": "EXC-08",
          "display_code": "X08",
          "safeguard_id": "7.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Exercise compound failures where an exception, stale source, provider outage, unavailable owner, and degraded control overlap; define one safe command and one accountable decision.",
          "zh": "演练例外、陈旧来源、提供商中断、责任人不可用和控制降级同时出现的复合故障，明确一条安全指令和一个责任决策。"
        },
        {
          "code": "CIS-7.1-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "7.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Walk one finding from source identity and affected asset through triage, owner, due date, remediation, rescan and closure, plus one false positive and one accepted risk.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“把一个发现从来源身份、受影响资产一路追到分诊、责任人、到期、修复、复扫和关闭，再追一个误报和一个风险接受；检查陈旧队列、漏资产、扫描失败和重开，并说明怎样合并来源/资产身份。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-7.1-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "7.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-7.1-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "7.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 0 pinned CAS metric branch(es), 2 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 0 个指标分支、2 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-7.1-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "7.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-7.1-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "7.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the vulnerability finding and remediation authority linked to asset and software identity plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以与资产和软件身份关联的漏洞发现与修复权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-7.1-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "7.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Publish open, validated, false-positive, overdue, mitigated, excepted, deployed-unverified, retest-failed, reopened, and exposure-weighted findings with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 开放、已验证、误报、逾期、已缓解、例外、已部署未验证、复测失败、重开和暴露加权发现，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-7.1-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "7.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Publish clause coverage, owner and reviewer completeness, approval age, triggered reviews, deviations, overdue actions, and superseded versions still in use with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 条款覆盖、责任人与复核人完整性、批准年龄、触发式复核、偏离、逾期行动及仍在使用的旧版本，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-7.1-EVD-08",
          "local_code": "EVD-08",
          "display_code": "E08",
          "safeguard_id": "7.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Require an independent party to reconstruct the decision from source receipts and reproduce the population, state transition, calculation, test result, exception, and final closure.",
          "zh": "要求独立人员使用来源回执重建决策，并复现总体、状态转换、计算、测试结果、例外和最终关闭。"
        },
        {
          "code": "CIS-7.1-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "7.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-7.1-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "7.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-7.1-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "7.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-7.1-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "7.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-7.1-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "7.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the vulnerability finding and remediation authority linked to asset and software identity; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护与资产和软件身份关联的漏洞发现与修复权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-7.1-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "7.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Restrict authority to change discovered → validated → prioritized → assigned → fixed/mitigated/excepted → deployed → retested → closed/reopened; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“发现 → 验证 → 定级 → 分派 → 修复/缓解/例外 → 部署 → 复测 → 关闭/重开”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-7.1-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "7.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Restrict authority to change draft → reviewed → approved → effective → exception/withdrawn → superseded; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-7.1-SEC-08",
          "local_code": "SEC-08",
          "display_code": "S08",
          "safeguard_id": "7.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Threat-model the implementation system itself: forged evidence, poisoned inventory, privilege abuse, cross-tenant confusion, policy rollback, audit deletion, denial of service, and recovery compromise.",
          "zh": "威胁建模实施系统自身：伪造证据、污染清单、权限滥用、跨租户混淆、策略回滚、审计删除、拒绝服务和恢复失陷。"
        },
        {
          "code": "CIS-7.1-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "7.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-7.1-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "7.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-7.1-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "7.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-7.1-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "7.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-7.1-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "7.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise known vulnerable and fixed artifacts, credential failure, false-positive review, patch rollback, recurrence, external exposure, and mitigation bypass through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 已知漏洞与已修复制品、凭据失败、误报复核、补丁回滚、复发、外部暴露和缓解绕过，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-7.1-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "7.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Run the positive control a known vulnerable artifact repaired and independently retested; exercise negative, stale, duplicate, bypass, and outage controls including credential failure, wrong version match, unavailable fix, mitigation bypass, failed deployment, rollback, recurring finding, and exposed unowned asset.",
          "zh": "运行正向控制“一项已知漏洞制品完成修复并独立复测”，并执行包含“凭据失败、版本误配、无可用修复、缓解绕过、部署失败、回滚、问题复发和外露无主资产”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-7.1-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "7.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Run the positive control an approved current process used for a representative decision; exercise negative, stale, duplicate, bypass, and outage controls including an obsolete version, missing approver, undocumented deviation, overdue review, and bypassed workflow.",
          "zh": "运行正向控制“使用当前获批流程完成一项代表性决策”，并执行包含“旧版本、审批人缺失、未记录偏离、逾期复核和绕过流程”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-7.1-TST-08",
          "local_code": "TST-08",
          "display_code": "V08",
          "safeguard_id": "7.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Build a pairwise platform-and-failure matrix, then add high-consequence multi-factor cases, historical regression, source substitution, red-team challenge, and assessor replay.",
          "zh": "建立平台—故障两两组合矩阵，再加入高后果多因素案例、历史回归、来源替换、红队挑战和评估方重放。"
        },
        {
          "code": "CIS-7.1-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "7.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-7.1-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "7.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-7.1-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "7.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-7.1-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "7.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-7.1-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "7.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever authenticated and unauthenticated scanners, package and image analysis, advisories, SBOMs, cloud findings, penetration tests, tickets, and deployment evidence change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 认证与非认证扫描、包与镜像分析、公告、SBOM、云发现、渗透测试、工单和部署证据 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-7.1-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "7.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Use open, validated, false-positive, overdue, mitigated, excepted, deployed-unverified, retest-failed, reopened, and exposure-weighted findings to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 开放、已验证、误报、逾期、已缓解、例外、已部署未验证、复测失败、重开和暴露加权发现 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-7.1-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "7.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Use clause coverage, owner and reviewer completeness, approval age, triggered reviews, deviations, overdue actions, and superseded versions still in use to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 条款覆盖、责任人与复核人完整性、批准年龄、触发式复核、偏离、逾期行动及仍在使用的旧版本 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-7.1-OPS-08",
          "local_code": "OPS-08",
          "display_code": "R08",
          "safeguard_id": "7.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Use canary deployment, kill criteria, rollback, backlog burn-down, exception reduction, source-quality targets, quarterly design review, and a measurable retirement plan.",
          "zh": "采用金丝雀、停止标准、回滚、积压燃尽、例外缩减、来源质量目标、季度设计复核和可量化退役计划。"
        }
      ]
    },
    {
      "id": "7.2",
      "control": 7,
      "title_en": "Establish and Maintain a Remediation Process",
      "title_zh": "风险化修复流程",
      "first_ig": 1,
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Documentation",
      "security_function": "Govern",
      "patterns": [
        "vulnerability",
        "governance"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [],
        "variables": [
          "GV18",
          "M1",
          "M2",
          "M3"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [
        "monthly"
      ],
      "implementation_contract": {
        "en": {
          "scope": "The remediation strategy covers patches, upgrades, configuration changes, compensating controls, removal, isolation and accepted risk for every finding source.",
          "build": "Set treatment and verification SLOs by risk, establish emergency lanes, dependency and outage handling, change ownership, exception expiry and executive escalation.",
          "proof": "Use historical findings to compare discovery-to-triage, ownership, treatment, verification and overdue times by risk and asset class.",
          "boundary": "An exception is an owned treatment with evidence, compensating controls, expiry and re-evaluation, not “business accepted.” Vendor patch absence does not stop isolation or exposure reduction."
        },
        "zh": {
          "scope": "修复策略覆盖补丁、升级、配置、补偿、移除、隔离和风险接受，适用于全部发现来源。",
          "build": "按风险设处置与验证 SLO、应急车道、依赖/停机处理、变更责任、例外到期和高层升级。",
          "proof": "用历史发现拆解发现到分诊、认领、处置、验证和逾期的时间，按风险/资产类别看分布。",
          "boundary": "例外是有证据、有补偿、有到期和复评的具名处置，不是“业务接受”四个字。"
        }
      },
      "category_counts": {
        "outcome": 7,
        "scope": 7,
        "ownership": 7,
        "data": 7,
        "integration": 7,
        "control": 7,
        "timing": 7,
        "exception": 7,
        "evidence": 7,
        "security": 7,
        "testing": 7,
        "operations": 7
      },
      "requirement_count": 84,
      "requirements": [
        {
          "code": "CIS-7.2-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "7.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Establish and Maintain a Remediation Process; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“风险化修复流程”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-7.2-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "7.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 7.2, official Asset Class Documentation, Security Function Govern, and IG1 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 7.2、官方资产类别“文档与治理”、安全功能“治理”和首次出现的 IG1，并保存来源抓取日期。"
        },
        {
          "code": "CIS-7.2-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "7.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “The remediation strategy covers patches, upgrades, configuration changes, compensating controls, removal, isolation and accepted risk for every finding source.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“修复策略覆盖补丁、升级、配置、补偿、移除、隔离和风险接受，适用于全部发现来源。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-7.2-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "7.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-7.2-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "7.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Establish and Maintain a Remediation Process to its operating object—vulnerabilities, affected artifacts and deployments, exploitability context, remediation decisions, patches, mitigations, and residual exposure—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“风险化修复流程”连接到其运营对象——漏洞、受影响制品与部署、可利用性上下文、修复决策、补丁、缓解措施和残余暴露——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-7.2-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "7.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "For Establish and Maintain a Remediation Process, express success as an observable decision over affected artifact identity, exploitability, business consequence, remediation choice, deployed fix, compensating control, and residual exposure; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“风险化修复流程”，以 受影响制品身份、可利用性、业务后果、修复选择、已部署修复、补偿控制和残余暴露 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-7.2-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "7.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "For Establish and Maintain a Remediation Process, express success as an observable decision over a documented decision system with policy, process, procedure, accountable owner, approval, and review; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“风险化修复流程”，以 包含策略、流程、程序、责任人、审批和复核的文档化决策系统 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-7.2-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "7.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-7.2-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "7.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-7.2-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "7.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-7.2-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "7.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-7.2-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "7.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across unscannable assets, stale inventories, false positives, vendor backlog, compensating controls, superseded findings, ephemeral workloads, and failed patches; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 不可扫描资产、陈旧清单、误报、厂商积压、补偿控制、被取代发现、短生工作负载和失败补丁 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-7.2-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "7.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Include unknown versions, false positives, unavailable fixes, vendor lag, ephemeral workloads, unscannable platforms, inherited dependencies, mitigation-only states, and recurrence in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 未知版本、误报、无可用修复、厂商滞后、短生工作负载、不可扫描平台、继承依赖、仅缓解状态和复发 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-7.2-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "7.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Include missing policy clauses, conflicting authorities, local deviations, obsolete documentation, and decisions made outside the governed workflow in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 策略条款缺失、权限冲突、本地偏离、文档过期及绕过治理流程的决策 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-7.2-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "7.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-7.2-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "7.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-7.2-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "7.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-7.2-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "7.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-7.2-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "7.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind asset and application owners, vulnerability management, engineering, change management, threat intelligence, and risk owners to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 资产与应用责任人、漏洞管理、工程、变更管理、威胁情报和风险责任人 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-7.2-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "7.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Name who may transition discovered → validated → prioritized → assigned → fixed/mitigated/excepted → deployed → retested → closed/reopened, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 发现 → 验证 → 定级 → 分派 → 修复/缓解/例外 → 部署 → 复测 → 关闭/重开，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-7.2-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "7.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Name who may transition draft → reviewed → approved → effective → exception/withdrawn → superseded, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-7.2-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "7.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-7.2-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "7.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-7.2-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "7.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV18, M1, M2, M3) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV18, M1, M2, M3）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-7.2-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "7.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-7.2-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "7.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the vulnerability finding and remediation authority linked to asset and software identity as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把与资产和软件身份关联的漏洞发现与修复权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-7.2-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "7.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle discovered → validated → prioritized → assigned → fixed/mitigated/excepted → deployed → retested → closed/reopened.",
          "zh": "对生命周期“发现 → 验证 → 定级 → 分派 → 修复/缓解/例外 → 部署 → 复测 → 关闭/重开”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-7.2-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "7.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle draft → reviewed → approved → effective → exception/withdrawn → superseded.",
          "zh": "对生命周期“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-7.2-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "7.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for no explicit predecessor in the pinned CAS page; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 固定 CAS 页面没有列出显式前置项 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-7.2-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "7.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-7.2-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "7.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-7.2-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "7.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-7.2-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "7.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile authenticated and unauthenticated scanners, package and image analysis, advisories, SBOMs, cloud findings, penetration tests, tickets, and deployment evidence and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 认证与非认证扫描、包与镜像分析、公告、SBOM、云发现、渗透测试、工单和部署证据，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-7.2-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "7.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Require every connector carrying affected artifact identity, exploitability, business consequence, remediation choice, deployed fix, compensating control, and residual exposure to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 受影响制品身份、可利用性、业务后果、修复选择、已部署修复、补偿控制和残余暴露 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-7.2-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "7.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Require every connector carrying a documented decision system with policy, process, procedure, accountable owner, approval, and review to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 包含策略、流程、程序、责任人、审批和复核的文档化决策系统 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-7.2-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "7.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Set treatment and verification SLOs by risk, establish emergency lanes, dependency and outage handling, change ownership, exception expiry and executive escalation.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“按风险设处置与验证 SLO、应急车道、依赖/停机处理、变更责任、例外到期和高层升级。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-7.2-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "7.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-7.2-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "7.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-7.2-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "7.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-7.2-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "7.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the vulnerability finding and remediation authority linked to asset and software identity and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在与资产和软件身份关联的漏洞发现与修复权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-7.2-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "7.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Implement the explicit state machine discovered → validated → prioritized → assigned → fixed/mitigated/excepted → deployed → retested → closed/reopened; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“发现 → 验证 → 定级 → 分派 → 修复/缓解/例外 → 部署 → 复测 → 关闭/重开”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-7.2-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "7.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Implement the explicit state machine draft → reviewed → approved → effective → exception/withdrawn → superseded; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-7.2-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "7.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (monthly); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（monthly）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-7.2-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "7.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-7.2-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "7.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-7.2-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "7.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-7.2-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "7.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in vulnerabilities, affected artifacts and deployments, exploitability context, remediation decisions, patches, mitigations, and residual exposure; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 漏洞、受影响制品与部署、可利用性上下文、修复决策、补丁、缓解措施和残余暴露 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-7.2-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "7.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for discovered → validated → prioritized → assigned → fixed/mitigated/excepted → deployed → retested → closed/reopened; alert before each deadline becomes overdue.",
          "zh": "为“发现 → 验证 → 定级 → 分派 → 修复/缓解/例外 → 部署 → 复测 → 关闭/重开”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-7.2-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "7.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for draft → reviewed → approved → effective → exception/withdrawn → superseded; alert before each deadline becomes overdue.",
          "zh": "为“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-7.2-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "7.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “An exception is an owned treatment with evidence, compensating controls, expiry and re-evaluation, not “business accepted.” Vendor patch absence does not stop isolation or exposure reduction.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“例外是有证据、有补偿、有到期和复评的具名处置，不是“业务接受”四个字。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-7.2-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "7.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-7.2-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "7.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-7.2-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "7.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-7.2-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "7.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat unscannable assets, stale inventories, false positives, vendor backlog, compensating controls, superseded findings, ephemeral workloads, and failed patches as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 不可扫描资产、陈旧清单、误报、厂商积压、补偿控制、被取代发现、短生工作负载和失败补丁 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-7.2-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "7.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Treat unknown versions, false positives, unavailable fixes, vendor lag, ephemeral workloads, unscannable platforms, inherited dependencies, mitigation-only states, and recurrence as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 未知版本、误报、无可用修复、厂商滞后、短生工作负载、不可扫描平台、继承依赖、仅缓解状态和复发 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-7.2-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "7.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Treat missing policy clauses, conflicting authorities, local deviations, obsolete documentation, and decisions made outside the governed workflow as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 策略条款缺失、权限冲突、本地偏离、文档过期及绕过治理流程的决策 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-7.2-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "7.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Use historical findings to compare discovery-to-triage, ownership, treatment, verification and overdue times by risk and asset class.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“用历史发现拆解发现到分诊、认领、处置、验证和逾期的时间，按风险/资产类别看分布。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-7.2-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "7.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-7.2-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "7.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 4 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、4 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-7.2-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "7.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-7.2-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "7.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the vulnerability finding and remediation authority linked to asset and software identity plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以与资产和软件身份关联的漏洞发现与修复权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-7.2-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "7.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Publish open, validated, false-positive, overdue, mitigated, excepted, deployed-unverified, retest-failed, reopened, and exposure-weighted findings with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 开放、已验证、误报、逾期、已缓解、例外、已部署未验证、复测失败、重开和暴露加权发现，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-7.2-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "7.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Publish clause coverage, owner and reviewer completeness, approval age, triggered reviews, deviations, overdue actions, and superseded versions still in use with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 条款覆盖、责任人与复核人完整性、批准年龄、触发式复核、偏离、逾期行动及仍在使用的旧版本，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-7.2-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "7.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-7.2-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "7.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-7.2-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "7.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-7.2-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "7.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-7.2-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "7.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the vulnerability finding and remediation authority linked to asset and software identity; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护与资产和软件身份关联的漏洞发现与修复权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-7.2-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "7.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Restrict authority to change discovered → validated → prioritized → assigned → fixed/mitigated/excepted → deployed → retested → closed/reopened; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“发现 → 验证 → 定级 → 分派 → 修复/缓解/例外 → 部署 → 复测 → 关闭/重开”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-7.2-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "7.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Restrict authority to change draft → reviewed → approved → effective → exception/withdrawn → superseded; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-7.2-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "7.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-7.2-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "7.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-7.2-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "7.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-7.2-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "7.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-7.2-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "7.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise known vulnerable and fixed artifacts, credential failure, false-positive review, patch rollback, recurrence, external exposure, and mitigation bypass through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 已知漏洞与已修复制品、凭据失败、误报复核、补丁回滚、复发、外部暴露和缓解绕过，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-7.2-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "7.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Run the positive control a known vulnerable artifact repaired and independently retested; exercise negative, stale, duplicate, bypass, and outage controls including credential failure, wrong version match, unavailable fix, mitigation bypass, failed deployment, rollback, recurring finding, and exposed unowned asset.",
          "zh": "运行正向控制“一项已知漏洞制品完成修复并独立复测”，并执行包含“凭据失败、版本误配、无可用修复、缓解绕过、部署失败、回滚、问题复发和外露无主资产”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-7.2-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "7.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Run the positive control an approved current process used for a representative decision; exercise negative, stale, duplicate, bypass, and outage controls including an obsolete version, missing approver, undocumented deviation, overdue review, and bypassed workflow.",
          "zh": "运行正向控制“使用当前获批流程完成一项代表性决策”，并执行包含“旧版本、审批人缺失、未记录偏离、逾期复核和绕过流程”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-7.2-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "7.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-7.2-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "7.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-7.2-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "7.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-7.2-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "7.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-7.2-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "7.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever authenticated and unauthenticated scanners, package and image analysis, advisories, SBOMs, cloud findings, penetration tests, tickets, and deployment evidence change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 认证与非认证扫描、包与镜像分析、公告、SBOM、云发现、渗透测试、工单和部署证据 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-7.2-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "7.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Use open, validated, false-positive, overdue, mitigated, excepted, deployed-unverified, retest-failed, reopened, and exposure-weighted findings to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 开放、已验证、误报、逾期、已缓解、例外、已部署未验证、复测失败、重开和暴露加权发现 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-7.2-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "7.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Use clause coverage, owner and reviewer completeness, approval age, triggered reviews, deviations, overdue actions, and superseded versions still in use to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 条款覆盖、责任人与复核人完整性、批准年龄、触发式复核、偏离、逾期行动及仍在使用的旧版本 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "7.3",
      "control": 7,
      "title_en": "Perform Automated Operating System Patch Management",
      "title_zh": "操作系统自动补丁",
      "first_ig": 1,
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Software",
      "security_function": "Protect",
      "patterns": [
        "vulnerability"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "1.1",
          "2.1",
          "4.1"
        ],
        "variables": [
          "GV1",
          "GV3",
          "GV5",
          "M1",
          "M2",
          "M3",
          "M4",
          "M5",
          "M6",
          "M7",
          "M8",
          "M9",
          "M10"
        ],
        "metric_branches": 4,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [
        "monthly"
      ],
      "implementation_contract": {
        "en": {
          "scope": "Include every OS and firmware-like platform layer that the enterprise operates on endpoints, servers, cloud images, hypervisors and appliances where automated updating is supported.",
          "build": "Use centrally governed rings, tested repositories and maintenance windows to deploy at least monthly, with faster emergency release, health checks and rollback.",
          "proof": "Deploy a signed test update through pilot and broad rings, verify install, reboot or activation, application health, rollback and inventory state.",
          "boundary": "Counting an out-of-date OS with an exception as “up to date,” as CAS effectiveness does, merges risk acceptance with remediation."
        },
        "zh": {
          "scope": "包括企业运营的终端、服务器、云镜像、虚拟化和设备中可自动更新的 OS/固件层。",
          "build": "用中央管理的分批、可信仓库和维护窗至少每月部署，紧急风险更快，并有健康检查/回滚。",
          "proof": "经试点和广泛分批部署签名测试更新，验证安装、重启/激活、应用健康和回滚。",
          "boundary": "CAS 把“有例外的过期 OS”算作更新有效，把风险接受与修复混为一谈。"
        }
      },
      "category_counts": {
        "outcome": 6,
        "scope": 6,
        "ownership": 6,
        "data": 6,
        "integration": 6,
        "control": 6,
        "timing": 6,
        "exception": 6,
        "evidence": 6,
        "security": 6,
        "testing": 6,
        "operations": 6
      },
      "requirement_count": 72,
      "requirements": [
        {
          "code": "CIS-7.3-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "7.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Perform Automated Operating System Patch Management; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“操作系统自动补丁”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-7.3-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "7.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 7.3, official Asset Class Software, Security Function Protect, and IG1 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 7.3、官方资产类别“软件”、安全功能“保护”和首次出现的 IG1，并保存来源抓取日期。"
        },
        {
          "code": "CIS-7.3-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "7.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Include every OS and firmware-like platform layer that the enterprise operates on endpoints, servers, cloud images, hypervisors and appliances where automated updating is supported.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“包括企业运营的终端、服务器、云镜像、虚拟化和设备中可自动更新的 OS/固件层。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-7.3-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "7.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-7.3-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "7.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Perform Automated Operating System Patch Management to its operating object—vulnerabilities, affected artifacts and deployments, exploitability context, remediation decisions, patches, mitigations, and residual exposure—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“操作系统自动补丁”连接到其运营对象——漏洞、受影响制品与部署、可利用性上下文、修复决策、补丁、缓解措施和残余暴露——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-7.3-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "7.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "For Perform Automated Operating System Patch Management, express success as an observable decision over affected artifact identity, exploitability, business consequence, remediation choice, deployed fix, compensating control, and residual exposure; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“操作系统自动补丁”，以 受影响制品身份、可利用性、业务后果、修复选择、已部署修复、补偿控制和残余暴露 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-7.3-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "7.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-7.3-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "7.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-7.3-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "7.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-7.3-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "7.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-7.3-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "7.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across unscannable assets, stale inventories, false positives, vendor backlog, compensating controls, superseded findings, ephemeral workloads, and failed patches; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 不可扫描资产、陈旧清单、误报、厂商积压、补偿控制、被取代发现、短生工作负载和失败补丁 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-7.3-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "7.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Include unknown versions, false positives, unavailable fixes, vendor lag, ephemeral workloads, unscannable platforms, inherited dependencies, mitigation-only states, and recurrence in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 未知版本、误报、无可用修复、厂商滞后、短生工作负载、不可扫描平台、继承依赖、仅缓解状态和复发 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-7.3-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "7.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-7.3-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "7.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-7.3-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "7.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-7.3-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "7.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-7.3-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "7.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind asset and application owners, vulnerability management, engineering, change management, threat intelligence, and risk owners to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 资产与应用责任人、漏洞管理、工程、变更管理、威胁情报和风险责任人 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-7.3-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "7.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Name who may transition discovered → validated → prioritized → assigned → fixed/mitigated/excepted → deployed → retested → closed/reopened, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 发现 → 验证 → 定级 → 分派 → 修复/缓解/例外 → 部署 → 复测 → 关闭/重开，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-7.3-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "7.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-7.3-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "7.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-7.3-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "7.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV1, GV3, GV5, M1, M2, M3, M4, M5, M6, M7, M8, M9, and 1 more) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV1, GV3, GV5, M1, M2, M3, M4, M5, M6, M7, M8, M9, and 1 more）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-7.3-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "7.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-7.3-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "7.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the vulnerability finding and remediation authority linked to asset and software identity as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把与资产和软件身份关联的漏洞发现与修复权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-7.3-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "7.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle discovered → validated → prioritized → assigned → fixed/mitigated/excepted → deployed → retested → closed/reopened.",
          "zh": "对生命周期“发现 → 验证 → 定级 → 分派 → 修复/缓解/例外 → 部署 → 复测 → 关闭/重开”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-7.3-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "7.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 1.1, Safeguard 2.1, Safeguard 4.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 1.1、Safeguard 2.1、Safeguard 4.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-7.3-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "7.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-7.3-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "7.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-7.3-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "7.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-7.3-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "7.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile authenticated and unauthenticated scanners, package and image analysis, advisories, SBOMs, cloud findings, penetration tests, tickets, and deployment evidence and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 认证与非认证扫描、包与镜像分析、公告、SBOM、云发现、渗透测试、工单和部署证据，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-7.3-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "7.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Require every connector carrying affected artifact identity, exploitability, business consequence, remediation choice, deployed fix, compensating control, and residual exposure to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 受影响制品身份、可利用性、业务后果、修复选择、已部署修复、补偿控制和残余暴露 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-7.3-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "7.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Use centrally governed rings, tested repositories and maintenance windows to deploy at least monthly, with faster emergency release, health checks and rollback.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“用中央管理的分批、可信仓库和维护窗至少每月部署，紧急风险更快，并有健康检查/回滚。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-7.3-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "7.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-7.3-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "7.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-7.3-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "7.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-7.3-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "7.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the vulnerability finding and remediation authority linked to asset and software identity and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在与资产和软件身份关联的漏洞发现与修复权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-7.3-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "7.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Implement the explicit state machine discovered → validated → prioritized → assigned → fixed/mitigated/excepted → deployed → retested → closed/reopened; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“发现 → 验证 → 定级 → 分派 → 修复/缓解/例外 → 部署 → 复测 → 关闭/重开”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-7.3-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "7.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (monthly); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（monthly）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-7.3-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "7.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-7.3-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "7.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-7.3-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "7.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-7.3-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "7.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in vulnerabilities, affected artifacts and deployments, exploitability context, remediation decisions, patches, mitigations, and residual exposure; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 漏洞、受影响制品与部署、可利用性上下文、修复决策、补丁、缓解措施和残余暴露 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-7.3-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "7.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for discovered → validated → prioritized → assigned → fixed/mitigated/excepted → deployed → retested → closed/reopened; alert before each deadline becomes overdue.",
          "zh": "为“发现 → 验证 → 定级 → 分派 → 修复/缓解/例外 → 部署 → 复测 → 关闭/重开”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-7.3-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "7.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “Counting an out-of-date OS with an exception as “up to date,” as CAS effectiveness does, merges risk acceptance with remediation.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“CAS 把“有例外的过期 OS”算作更新有效，把风险接受与修复混为一谈。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-7.3-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "7.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-7.3-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "7.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-7.3-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "7.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-7.3-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "7.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat unscannable assets, stale inventories, false positives, vendor backlog, compensating controls, superseded findings, ephemeral workloads, and failed patches as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 不可扫描资产、陈旧清单、误报、厂商积压、补偿控制、被取代发现、短生工作负载和失败补丁 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-7.3-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "7.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Treat unknown versions, false positives, unavailable fixes, vendor lag, ephemeral workloads, unscannable platforms, inherited dependencies, mitigation-only states, and recurrence as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 未知版本、误报、无可用修复、厂商滞后、短生工作负载、不可扫描平台、继承依赖、仅缓解状态和复发 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-7.3-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "7.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Deploy a signed test update through pilot and broad rings, verify install, reboot or activation, application health, rollback and inventory state.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“经试点和广泛分批部署签名测试更新，验证安装、重启/激活、应用健康和回滚。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-7.3-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "7.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-7.3-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "7.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 4 pinned CAS metric branch(es), 13 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 4 个指标分支、13 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-7.3-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "7.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-7.3-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "7.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the vulnerability finding and remediation authority linked to asset and software identity plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以与资产和软件身份关联的漏洞发现与修复权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-7.3-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "7.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Publish open, validated, false-positive, overdue, mitigated, excepted, deployed-unverified, retest-failed, reopened, and exposure-weighted findings with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 开放、已验证、误报、逾期、已缓解、例外、已部署未验证、复测失败、重开和暴露加权发现，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-7.3-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "7.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-7.3-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "7.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-7.3-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "7.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-7.3-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "7.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-7.3-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "7.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the vulnerability finding and remediation authority linked to asset and software identity; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护与资产和软件身份关联的漏洞发现与修复权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-7.3-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "7.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Restrict authority to change discovered → validated → prioritized → assigned → fixed/mitigated/excepted → deployed → retested → closed/reopened; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“发现 → 验证 → 定级 → 分派 → 修复/缓解/例外 → 部署 → 复测 → 关闭/重开”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-7.3-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "7.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-7.3-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "7.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-7.3-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "7.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-7.3-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "7.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-7.3-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "7.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise known vulnerable and fixed artifacts, credential failure, false-positive review, patch rollback, recurrence, external exposure, and mitigation bypass through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 已知漏洞与已修复制品、凭据失败、误报复核、补丁回滚、复发、外部暴露和缓解绕过，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-7.3-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "7.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Run the positive control a known vulnerable artifact repaired and independently retested; exercise negative, stale, duplicate, bypass, and outage controls including credential failure, wrong version match, unavailable fix, mitigation bypass, failed deployment, rollback, recurring finding, and exposed unowned asset.",
          "zh": "运行正向控制“一项已知漏洞制品完成修复并独立复测”，并执行包含“凭据失败、版本误配、无可用修复、缓解绕过、部署失败、回滚、问题复发和外露无主资产”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-7.3-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "7.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-7.3-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "7.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-7.3-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "7.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-7.3-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "7.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-7.3-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "7.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever authenticated and unauthenticated scanners, package and image analysis, advisories, SBOMs, cloud findings, penetration tests, tickets, and deployment evidence change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 认证与非认证扫描、包与镜像分析、公告、SBOM、云发现、渗透测试、工单和部署证据 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-7.3-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "7.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Use open, validated, false-positive, overdue, mitigated, excepted, deployed-unverified, retest-failed, reopened, and exposure-weighted findings to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 开放、已验证、误报、逾期、已缓解、例外、已部署未验证、复测失败、重开和暴露加权发现 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "7.4",
      "control": 7,
      "title_en": "Perform Automated Application Patch Management",
      "title_zh": "应用自动补丁",
      "first_ig": 1,
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Software",
      "security_function": "Protect",
      "patterns": [
        "vulnerability",
        "software_dev"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "1.1",
          "2.1",
          "4.1"
        ],
        "variables": [
          "GV1",
          "GV3",
          "GV5",
          "GV24",
          "M1",
          "M2",
          "M3",
          "M4",
          "M5",
          "M6",
          "M7",
          "M8",
          "M9",
          "M10"
        ],
        "metric_branches": 4,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [
        "monthly"
      ],
      "implementation_contract": {
        "en": {
          "scope": "The population includes managed desktop/server applications, browsers, runtimes, agents, databases, plugins and packaged services; libraries and internally developed application components also require Control 16 pipelines.",
          "build": "Use vendor or trusted repositories, packaging and deployment rings to update at least monthly and faster for exploited risk.",
          "proof": "Push a test update and verify package authenticity, version, service health, rollback and restart across representative platforms.",
          "boundary": "An application can report the new package while an old vulnerable process or plugin still runs."
        },
        "zh": {
          "scope": "总体包括受管桌面/服务器应用、浏览器、Runtime、Agent、数据库、插件和打包服务；库与自研组件还要走 Control 16。",
          "build": "使用厂商/可信仓库与分批部署，至少每月更新，活跃利用时更快。",
          "proof": "推送测试更新，验证包真实性、版本、服务健康、回滚和各平台重启；覆盖率按 SLO 内已更新的部署实例算，不能按产品名或工具配置算，并以便携/休眠安装作负控。",
          "boundary": "包显示更新后，旧易受害进程或插件仍可能运行。"
        }
      },
      "category_counts": {
        "outcome": 7,
        "scope": 7,
        "ownership": 7,
        "data": 7,
        "integration": 7,
        "control": 7,
        "timing": 7,
        "exception": 7,
        "evidence": 7,
        "security": 7,
        "testing": 7,
        "operations": 7
      },
      "requirement_count": 84,
      "requirements": [
        {
          "code": "CIS-7.4-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "7.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Perform Automated Application Patch Management; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“应用自动补丁”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-7.4-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "7.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 7.4, official Asset Class Software, Security Function Protect, and IG1 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 7.4、官方资产类别“软件”、安全功能“保护”和首次出现的 IG1，并保存来源抓取日期。"
        },
        {
          "code": "CIS-7.4-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "7.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “The population includes managed desktop/server applications, browsers, runtimes, agents, databases, plugins and packaged services; libraries and internally developed application components also require Control 16 pipelines.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“总体包括受管桌面/服务器应用、浏览器、Runtime、Agent、数据库、插件和打包服务；库与自研组件还要走 Control 16。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-7.4-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "7.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-7.4-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "7.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Perform Automated Application Patch Management to its operating object—vulnerabilities, affected artifacts and deployments, exploitability context, remediation decisions, patches, mitigations, and residual exposure—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“应用自动补丁”连接到其运营对象——漏洞、受影响制品与部署、可利用性上下文、修复决策、补丁、缓解措施和残余暴露——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-7.4-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "7.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "For Perform Automated Application Patch Management, express success as an observable decision over affected artifact identity, exploitability, business consequence, remediation choice, deployed fix, compensating control, and residual exposure; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“应用自动补丁”，以 受影响制品身份、可利用性、业务后果、修复选择、已部署修复、补偿控制和残余暴露 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-7.4-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "7.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "For Perform Automated Application Patch Management, express success as an observable decision over source-to-production software identity, design invariant, component trust, build provenance, test result, deployment state, runtime outcome, and vulnerability response; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“应用自动补丁”，以 从源码到生产的软件身份、设计不变量、组件信任、构建来源、测试结果、部署状态、运行结果和漏洞响应 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-7.4-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "7.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-7.4-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "7.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-7.4-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "7.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-7.4-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "7.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-7.4-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "7.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across unscannable assets, stale inventories, false positives, vendor backlog, compensating controls, superseded findings, ephemeral workloads, and failed patches; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 不可扫描资产、陈旧清单、误报、厂商积压、补偿控制、被取代发现、短生工作负载和失败补丁 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-7.4-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "7.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Include unknown versions, false positives, unavailable fixes, vendor lag, ephemeral workloads, unscannable platforms, inherited dependencies, mitigation-only states, and recurrence in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 未知版本、误报、无可用修复、厂商滞后、短生工作负载、不可扫描平台、继承依赖、仅缓解状态和复发 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-7.4-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "7.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Include generated and copied code, forks, vendoring, transitive dependencies, mutable tags, build plugins, feature flags, tenant logic, secrets, emergency release, and provider components in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 生成与复制代码、分叉、vendoring、传递依赖、可变标签、构建插件、功能开关、租户逻辑、秘密、紧急发布和提供商组件 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-7.4-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "7.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-7.4-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "7.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-7.4-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "7.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-7.4-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "7.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-7.4-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "7.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind asset and application owners, vulnerability management, engineering, change management, threat intelligence, and risk owners to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 资产与应用责任人、漏洞管理、工程、变更管理、威胁情报和风险责任人 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-7.4-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "7.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Name who may transition discovered → validated → prioritized → assigned → fixed/mitigated/excepted → deployed → retested → closed/reopened, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 发现 → 验证 → 定级 → 分派 → 修复/缓解/例外 → 部署 → 复测 → 关闭/重开，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-7.4-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "7.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Name who may transition designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-7.4-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "7.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-7.4-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "7.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-7.4-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "7.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV1, GV3, GV5, GV24, M1, M2, M3, M4, M5, M6, M7, M8, and 2 more) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV1, GV3, GV5, GV24, M1, M2, M3, M4, M5, M6, M7, M8, and 2 more）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-7.4-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "7.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-7.4-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "7.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the vulnerability finding and remediation authority linked to asset and software identity as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把与资产和软件身份关联的漏洞发现与修复权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-7.4-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "7.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle discovered → validated → prioritized → assigned → fixed/mitigated/excepted → deployed → retested → closed/reopened.",
          "zh": "对生命周期“发现 → 验证 → 定级 → 分派 → 修复/缓解/例外 → 部署 → 复测 → 关闭/重开”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-7.4-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "7.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired.",
          "zh": "对生命周期“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-7.4-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "7.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 1.1, Safeguard 2.1, Safeguard 4.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 1.1、Safeguard 2.1、Safeguard 4.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-7.4-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "7.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-7.4-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "7.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-7.4-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "7.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-7.4-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "7.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile authenticated and unauthenticated scanners, package and image analysis, advisories, SBOMs, cloud findings, penetration tests, tickets, and deployment evidence and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 认证与非认证扫描、包与镜像分析、公告、SBOM、云发现、渗透测试、工单和部署证据，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-7.4-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "7.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Require every connector carrying affected artifact identity, exploitability, business consequence, remediation choice, deployed fix, compensating control, and residual exposure to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 受影响制品身份、可利用性、业务后果、修复选择、已部署修复、补偿控制和残余暴露 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-7.4-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "7.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Require every connector carrying source-to-production software identity, design invariant, component trust, build provenance, test result, deployment state, runtime outcome, and vulnerability response to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 从源码到生产的软件身份、设计不变量、组件信任、构建来源、测试结果、部署状态、运行结果和漏洞响应 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-7.4-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "7.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Use vendor or trusted repositories, packaging and deployment rings to update at least monthly and faster for exploited risk.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“使用厂商/可信仓库与分批部署，至少每月更新，活跃利用时更快。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-7.4-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "7.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-7.4-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "7.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-7.4-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "7.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-7.4-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "7.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the vulnerability finding and remediation authority linked to asset and software identity and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在与资产和软件身份关联的漏洞发现与修复权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-7.4-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "7.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Implement the explicit state machine discovered → validated → prioritized → assigned → fixed/mitigated/excepted → deployed → retested → closed/reopened; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“发现 → 验证 → 定级 → 分派 → 修复/缓解/例外 → 部署 → 复测 → 关闭/重开”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-7.4-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "7.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Implement the explicit state machine designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-7.4-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "7.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (monthly); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（monthly）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-7.4-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "7.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-7.4-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "7.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-7.4-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "7.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-7.4-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "7.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in vulnerabilities, affected artifacts and deployments, exploitability context, remediation decisions, patches, mitigations, and residual exposure; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 漏洞、受影响制品与部署、可利用性上下文、修复决策、补丁、缓解措施和残余暴露 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-7.4-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "7.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for discovered → validated → prioritized → assigned → fixed/mitigated/excepted → deployed → retested → closed/reopened; alert before each deadline becomes overdue.",
          "zh": "为“发现 → 验证 → 定级 → 分派 → 修复/缓解/例外 → 部署 → 复测 → 关闭/重开”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-7.4-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "7.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; alert before each deadline becomes overdue.",
          "zh": "为“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-7.4-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "7.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “An application can report the new package while an old vulnerable process or plugin still runs.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“包显示更新后，旧易受害进程或插件仍可能运行。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-7.4-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "7.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-7.4-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "7.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-7.4-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "7.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-7.4-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "7.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat unscannable assets, stale inventories, false positives, vendor backlog, compensating controls, superseded findings, ephemeral workloads, and failed patches as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 不可扫描资产、陈旧清单、误报、厂商积压、补偿控制、被取代发现、短生工作负载和失败补丁 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-7.4-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "7.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Treat unknown versions, false positives, unavailable fixes, vendor lag, ephemeral workloads, unscannable platforms, inherited dependencies, mitigation-only states, and recurrence as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 未知版本、误报、无可用修复、厂商滞后、短生工作负载、不可扫描平台、继承依赖、仅缓解状态和复发 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-7.4-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "7.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Treat generated and copied code, forks, vendoring, transitive dependencies, mutable tags, build plugins, feature flags, tenant logic, secrets, emergency release, and provider components as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 生成与复制代码、分叉、vendoring、传递依赖、可变标签、构建插件、功能开关、租户逻辑、秘密、紧急发布和提供商组件 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-7.4-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "7.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Push a test update and verify package authenticity, version, service health, rollback and restart across representative platforms.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“推送测试更新，验证包真实性、版本、服务健康、回滚和各平台重启；覆盖率按 SLO 内已更新的部署实例算，不能按产品名或工具配置算，并以便携/休眠安装作负控。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-7.4-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "7.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-7.4-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "7.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 4 pinned CAS metric branch(es), 14 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 4 个指标分支、14 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-7.4-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "7.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-7.4-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "7.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the vulnerability finding and remediation authority linked to asset and software identity plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以与资产和软件身份关联的漏洞发现与修复权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-7.4-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "7.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Publish open, validated, false-positive, overdue, mitigated, excepted, deployed-unverified, retest-failed, reopened, and exposure-weighted findings with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 开放、已验证、误报、逾期、已缓解、例外、已部署未验证、复测失败、重开和暴露加权发现，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-7.4-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "7.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Publish reviewed, unreviewed, reproducible, provenance-bound, vulnerable, test-failed, exception, deployed-unverified, drifted, rolled-back, and regression-protected releases with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已评审、未评审、可复现、来源绑定、存在漏洞、测试失败、例外、已部署未验证、漂移、已回滚和受回归保护发布物，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-7.4-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "7.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-7.4-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "7.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-7.4-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "7.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-7.4-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "7.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-7.4-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "7.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the vulnerability finding and remediation authority linked to asset and software identity; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护与资产和软件身份关联的漏洞发现与修复权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-7.4-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "7.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Restrict authority to change discovered → validated → prioritized → assigned → fixed/mitigated/excepted → deployed → retested → closed/reopened; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“发现 → 验证 → 定级 → 分派 → 修复/缓解/例外 → 部署 → 复测 → 关闭/重开”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-7.4-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "7.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Restrict authority to change designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-7.4-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "7.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-7.4-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "7.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-7.4-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "7.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-7.4-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "7.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-7.4-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "7.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise known vulnerable and fixed artifacts, credential failure, false-positive review, patch rollback, recurrence, external exposure, and mitigation bypass through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 已知漏洞与已修复制品、凭据失败、误报复核、补丁回滚、复发、外部暴露和缓解绕过，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-7.4-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "7.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Run the positive control a known vulnerable artifact repaired and independently retested; exercise negative, stale, duplicate, bypass, and outage controls including credential failure, wrong version match, unavailable fix, mitigation bypass, failed deployment, rollback, recurring finding, and exposed unowned asset.",
          "zh": "运行正向控制“一项已知漏洞制品完成修复并独立复测”，并执行包含“凭据失败、版本误配、无可用修复、缓解绕过、部署失败、回滚、问题复发和外露无主资产”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-7.4-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "7.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Run the positive control a trusted build that preserves the security invariant through deployment and runtime; exercise negative, stale, duplicate, bypass, and outage controls including a substituted dependency, unreviewed change, poisoned build input, failed security test, bypass path, vulnerable release, rollback, and regression.",
          "zh": "运行正向控制“一个把安全不变量贯穿部署与运行的可信构建”，并执行包含“依赖替换、未评审变更、构建输入污染、安全测试失败、绕过路径、漏洞发布、回滚和回归”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-7.4-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "7.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-7.4-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "7.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-7.4-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "7.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-7.4-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "7.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-7.4-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "7.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever authenticated and unauthenticated scanners, package and image analysis, advisories, SBOMs, cloud findings, penetration tests, tickets, and deployment evidence change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 认证与非认证扫描、包与镜像分析、公告、SBOM、云发现、渗透测试、工单和部署证据 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-7.4-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "7.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Use open, validated, false-positive, overdue, mitigated, excepted, deployed-unverified, retest-failed, reopened, and exposure-weighted findings to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 开放、已验证、误报、逾期、已缓解、例外、已部署未验证、复测失败、重开和暴露加权发现 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-7.4-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "7.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Use reviewed, unreviewed, reproducible, provenance-bound, vulnerable, test-failed, exception, deployed-unverified, drifted, rolled-back, and regression-protected releases to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已评审、未评审、可复现、来源绑定、存在漏洞、测试失败、例外、已部署未验证、漂移、已回滚和受回归保护发布物 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "7.5",
      "control": 7,
      "title_en": "Perform Automated Vulnerability Scans of Internal Enterprise Assets",
      "title_zh": "内部资产自动漏洞扫描",
      "first_ig": 2,
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Software",
      "security_function": "Identify",
      "patterns": [
        "vulnerability",
        "discovery"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "1.1",
          "2.1",
          "4.1"
        ],
        "variables": [
          "GV1",
          "GV3",
          "GV5",
          "GV25",
          "M1",
          "M2",
          "M3",
          "M4",
          "M5",
          "M6",
          "M7",
          "M8",
          "M9",
          "M10",
          "M11"
        ],
        "metric_branches": 4,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [
        "quarterly"
      ],
      "implementation_contract": {
        "en": {
          "scope": "Scope all internal enterprise assets and reachable services across campuses, remote networks, data centers, cloud accounts, containers and management planes, with both authenticated and unauthenticated perspectives at least quarterly.",
          "build": "Schedule scanners from representative zones, use least-privilege protected credentials, monitor job/engine/feed health, tune fragile assets and normalize findings to asset/software identities.",
          "proof": "Seed a safe known-vulnerable fixture and a missing credential, then verify discovery, authenticated evidence, failure alert and ticket flow.",
          "boundary": "A scanner installed or scheduled is not coverage when routing, credentials or exclusions prevent completion."
        },
        "zh": {
          "scope": "覆盖园区、远程网、数据中心、云账号、容器和管理面的内部资产与服务，至少季度做有凭据和无凭据两种视角；声明资产适用性、凭据深度和安全限制。",
          "build": "从代表网段调度扫描器，保护最小权限凭据，监测任务/引擎/Feed 健康，对脆弱资产调优，并把发现归一到资产/软件身份。",
          "proof": "放置安全的已知漏洞 Fixture 和一个失效凭据，验证发现、有凭据证据、失败告警和工单。",
          "boundary": "装了或排了扫描器不等于覆盖，路由、凭据、排除会使任务失效。"
        }
      },
      "category_counts": {
        "outcome": 7,
        "scope": 7,
        "ownership": 7,
        "data": 7,
        "integration": 7,
        "control": 7,
        "timing": 7,
        "exception": 7,
        "evidence": 7,
        "security": 7,
        "testing": 7,
        "operations": 7
      },
      "requirement_count": 84,
      "requirements": [
        {
          "code": "CIS-7.5-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "7.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Perform Automated Vulnerability Scans of Internal Enterprise Assets; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“内部资产自动漏洞扫描”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-7.5-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "7.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 7.5, official Asset Class Software, Security Function Identify, and IG2 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 7.5、官方资产类别“软件”、安全功能“识别”和首次出现的 IG2，并保存来源抓取日期。"
        },
        {
          "code": "CIS-7.5-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "7.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Scope all internal enterprise assets and reachable services across campuses, remote networks, data centers, cloud accounts, containers and management planes, with both authenticated and unauthenticated perspectives at least quarterly.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“覆盖园区、远程网、数据中心、云账号、容器和管理面的内部资产与服务，至少季度做有凭据和无凭据两种视角；声明资产适用性、凭据深度和安全限制。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-7.5-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "7.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-7.5-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "7.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Perform Automated Vulnerability Scans of Internal Enterprise Assets to its operating object—vulnerabilities, affected artifacts and deployments, exploitability context, remediation decisions, patches, mitigations, and residual exposure—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“内部资产自动漏洞扫描”连接到其运营对象——漏洞、受影响制品与部署、可利用性上下文、修复决策、补丁、缓解措施和残余暴露——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-7.5-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "7.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "For Perform Automated Vulnerability Scans of Internal Enterprise Assets, express success as an observable decision over affected artifact identity, exploitability, business consequence, remediation choice, deployed fix, compensating control, and residual exposure; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“内部资产自动漏洞扫描”，以 受影响制品身份、可利用性、业务后果、修复选择、已部署修复、补偿控制和残余暴露 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-7.5-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "7.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "For Perform Automated Vulnerability Scans of Internal Enterprise Assets, express success as an observable decision over coverage of every intended discovery vantage point, source, job, parser, and reconciliation path; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“内部资产自动漏洞扫描”，以 所有预期发现视角、来源、任务、解析器和对账路径的覆盖 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-7.5-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "7.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-7.5-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "7.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-7.5-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "7.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-7.5-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "7.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-7.5-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "7.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across unscannable assets, stale inventories, false positives, vendor backlog, compensating controls, superseded findings, ephemeral workloads, and failed patches; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 不可扫描资产、陈旧清单、误报、厂商积压、补偿控制、被取代发现、短生工作负载和失败补丁 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-7.5-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "7.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Include unknown versions, false positives, unavailable fixes, vendor lag, ephemeral workloads, unscannable platforms, inherited dependencies, mitigation-only states, and recurrence in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 未知版本、误报、无可用修复、厂商滞后、短生工作负载、不可扫描平台、继承依赖、仅缓解状态和复发 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-7.5-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "7.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Include unreachable zones, short-lived objects, blind spots, rate limits, credential failure, encrypted or proprietary protocols, and silent sensors in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 不可达区域、短生对象、盲区、限流、凭据失败、加密或专有协议和静默传感器 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-7.5-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "7.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-7.5-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "7.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-7.5-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "7.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-7.5-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "7.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-7.5-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "7.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind asset and application owners, vulnerability management, engineering, change management, threat intelligence, and risk owners to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 资产与应用责任人、漏洞管理、工程、变更管理、威胁情报和风险责任人 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-7.5-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "7.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Name who may transition discovered → validated → prioritized → assigned → fixed/mitigated/excepted → deployed → retested → closed/reopened, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 发现 → 验证 → 定级 → 分派 → 修复/缓解/例外 → 部署 → 复测 → 关闭/重开，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-7.5-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "7.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Name who may transition scheduled → started → observed → normalized → reconciled → dispositioned, with explicit partial and failed states, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 计划 → 启动 → 观测 → 归一化 → 对账 → 处置，并显式保留部分与失败状态，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-7.5-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "7.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-7.5-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "7.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-7.5-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "7.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV1, GV3, GV5, GV25, M1, M2, M3, M4, M5, M6, M7, M8, and 3 more) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV1, GV3, GV5, GV25, M1, M2, M3, M4, M5, M6, M7, M8, and 3 more）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-7.5-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "7.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-7.5-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "7.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the vulnerability finding and remediation authority linked to asset and software identity as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把与资产和软件身份关联的漏洞发现与修复权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-7.5-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "7.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle discovered → validated → prioritized → assigned → fixed/mitigated/excepted → deployed → retested → closed/reopened.",
          "zh": "对生命周期“发现 → 验证 → 定级 → 分派 → 修复/缓解/例外 → 部署 → 复测 → 关闭/重开”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-7.5-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "7.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle scheduled → started → observed → normalized → reconciled → dispositioned, with explicit partial and failed states.",
          "zh": "对生命周期“计划 → 启动 → 观测 → 归一化 → 对账 → 处置，并显式保留部分与失败状态”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-7.5-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "7.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 1.1, Safeguard 2.1, Safeguard 4.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 1.1、Safeguard 2.1、Safeguard 4.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-7.5-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "7.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-7.5-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "7.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-7.5-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "7.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-7.5-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "7.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile authenticated and unauthenticated scanners, package and image analysis, advisories, SBOMs, cloud findings, penetration tests, tickets, and deployment evidence and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 认证与非认证扫描、包与镜像分析、公告、SBOM、云发现、渗透测试、工单和部署证据，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-7.5-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "7.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Require every connector carrying affected artifact identity, exploitability, business consequence, remediation choice, deployed fix, compensating control, and residual exposure to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 受影响制品身份、可利用性、业务后果、修复选择、已部署修复、补偿控制和残余暴露 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-7.5-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "7.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Require every connector carrying coverage of every intended discovery vantage point, source, job, parser, and reconciliation path to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 所有预期发现视角、来源、任务、解析器和对账路径的覆盖 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-7.5-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "7.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Schedule scanners from representative zones, use least-privilege protected credentials, monitor job/engine/feed health, tune fragile assets and normalize findings to asset/software identities.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“从代表网段调度扫描器，保护最小权限凭据，监测任务/引擎/Feed 健康，对脆弱资产调优，并把发现归一到资产/软件身份。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-7.5-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "7.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-7.5-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "7.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-7.5-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "7.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-7.5-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "7.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the vulnerability finding and remediation authority linked to asset and software identity and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在与资产和软件身份关联的漏洞发现与修复权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-7.5-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "7.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Implement the explicit state machine discovered → validated → prioritized → assigned → fixed/mitigated/excepted → deployed → retested → closed/reopened; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“发现 → 验证 → 定级 → 分派 → 修复/缓解/例外 → 部署 → 复测 → 关闭/重开”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-7.5-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "7.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Implement the explicit state machine scheduled → started → observed → normalized → reconciled → dispositioned, with explicit partial and failed states; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“计划 → 启动 → 观测 → 归一化 → 对账 → 处置，并显式保留部分与失败状态”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-7.5-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "7.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (quarterly); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（quarterly）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-7.5-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "7.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-7.5-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "7.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-7.5-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "7.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-7.5-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "7.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in vulnerabilities, affected artifacts and deployments, exploitability context, remediation decisions, patches, mitigations, and residual exposure; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 漏洞、受影响制品与部署、可利用性上下文、修复决策、补丁、缓解措施和残余暴露 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-7.5-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "7.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for discovered → validated → prioritized → assigned → fixed/mitigated/excepted → deployed → retested → closed/reopened; alert before each deadline becomes overdue.",
          "zh": "为“发现 → 验证 → 定级 → 分派 → 修复/缓解/例外 → 部署 → 复测 → 关闭/重开”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-7.5-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "7.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for scheduled → started → observed → normalized → reconciled → dispositioned, with explicit partial and failed states; alert before each deadline becomes overdue.",
          "zh": "为“计划 → 启动 → 观测 → 归一化 → 对账 → 处置，并显式保留部分与失败状态”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-7.5-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "7.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “A scanner installed or scheduled is not coverage when routing, credentials or exclusions prevent completion.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“装了或排了扫描器不等于覆盖，路由、凭据、排除会使任务失效。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-7.5-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "7.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-7.5-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "7.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-7.5-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "7.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-7.5-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "7.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat unscannable assets, stale inventories, false positives, vendor backlog, compensating controls, superseded findings, ephemeral workloads, and failed patches as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 不可扫描资产、陈旧清单、误报、厂商积压、补偿控制、被取代发现、短生工作负载和失败补丁 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-7.5-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "7.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Treat unknown versions, false positives, unavailable fixes, vendor lag, ephemeral workloads, unscannable platforms, inherited dependencies, mitigation-only states, and recurrence as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 未知版本、误报、无可用修复、厂商滞后、短生工作负载、不可扫描平台、继承依赖、仅缓解状态和复发 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-7.5-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "7.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Treat unreachable zones, short-lived objects, blind spots, rate limits, credential failure, encrypted or proprietary protocols, and silent sensors as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 不可达区域、短生对象、盲区、限流、凭据失败、加密或专有协议和静默传感器 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-7.5-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "7.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Seed a safe known-vulnerable fixture and a missing credential, then verify discovery, authenticated evidence, failure alert and ticket flow.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“放置安全的已知漏洞 Fixture 和一个失效凭据，验证发现、有凭据证据、失败告警和工单。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-7.5-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "7.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-7.5-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "7.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 4 pinned CAS metric branch(es), 15 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 4 个指标分支、15 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-7.5-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "7.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-7.5-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "7.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the vulnerability finding and remediation authority linked to asset and software identity plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以与资产和软件身份关联的漏洞发现与修复权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-7.5-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "7.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Publish open, validated, false-positive, overdue, mitigated, excepted, deployed-unverified, retest-failed, reopened, and exposure-weighted findings with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 开放、已验证、误报、逾期、已缓解、例外、已部署未验证、复测失败、重开和暴露加权发现，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-7.5-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "7.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Publish scheduled, successful, partial, failed, stale, blind, newly discovered, unmatched, and reconciled observations with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 计划、成功、部分、失败、陈旧、盲区、新发现、未匹配和已对账观测，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-7.5-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "7.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-7.5-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "7.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-7.5-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "7.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-7.5-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "7.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-7.5-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "7.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the vulnerability finding and remediation authority linked to asset and software identity; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护与资产和软件身份关联的漏洞发现与修复权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-7.5-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "7.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Restrict authority to change discovered → validated → prioritized → assigned → fixed/mitigated/excepted → deployed → retested → closed/reopened; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“发现 → 验证 → 定级 → 分派 → 修复/缓解/例外 → 部署 → 复测 → 关闭/重开”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-7.5-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "7.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Restrict authority to change scheduled → started → observed → normalized → reconciled → dispositioned, with explicit partial and failed states; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“计划 → 启动 → 观测 → 归一化 → 对账 → 处置，并显式保留部分与失败状态”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-7.5-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "7.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-7.5-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "7.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-7.5-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "7.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-7.5-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "7.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-7.5-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "7.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise known vulnerable and fixed artifacts, credential failure, false-positive review, patch rollback, recurrence, external exposure, and mitigation bypass through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 已知漏洞与已修复制品、凭据失败、误报复核、补丁回滚、复发、外部暴露和缓解绕过，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-7.5-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "7.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Run the positive control a known vulnerable artifact repaired and independently retested; exercise negative, stale, duplicate, bypass, and outage controls including credential failure, wrong version match, unavailable fix, mitigation bypass, failed deployment, rollback, recurring finding, and exposed unowned asset.",
          "zh": "运行正向控制“一项已知漏洞制品完成修复并独立复测”，并执行包含“凭据失败、版本误配、无可用修复、缓解绕过、部署失败、回滚、问题复发和外露无主资产”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-7.5-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "7.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Run the positive control a known object visible from each representative vantage point; exercise negative, stale, duplicate, bypass, and outage controls including an unknown and short-lived object, failed credential, blocked scan, silent sensor, parser drift, and uncovered segment.",
          "zh": "运行正向控制“从每个代表性视角可见的一项已知对象”，并执行包含“未知与短生对象、凭据失败、扫描受阻、传感器静默、解析漂移和未覆盖网段”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-7.5-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "7.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-7.5-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "7.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-7.5-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "7.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-7.5-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "7.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-7.5-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "7.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever authenticated and unauthenticated scanners, package and image analysis, advisories, SBOMs, cloud findings, penetration tests, tickets, and deployment evidence change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 认证与非认证扫描、包与镜像分析、公告、SBOM、云发现、渗透测试、工单和部署证据 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-7.5-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "7.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Use open, validated, false-positive, overdue, mitigated, excepted, deployed-unverified, retest-failed, reopened, and exposure-weighted findings to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 开放、已验证、误报、逾期、已缓解、例外、已部署未验证、复测失败、重开和暴露加权发现 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-7.5-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "7.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Use scheduled, successful, partial, failed, stale, blind, newly discovered, unmatched, and reconciled observations to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 计划、成功、部分、失败、陈旧、盲区、新发现、未匹配和已对账观测 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "7.6",
      "control": 7,
      "title_en": "Perform Automated Vulnerability Scans of Externally-Exposed Enterprise Assets",
      "title_zh": "外网资产自动漏洞扫描",
      "first_ig": 2,
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Software",
      "security_function": "Identify",
      "patterns": [
        "vulnerability",
        "discovery"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "1.1",
          "2.1",
          "4.1"
        ],
        "variables": [
          "GV1",
          "GV3",
          "GV25",
          "M1",
          "M2",
          "M3",
          "M4",
          "M5",
          "M6"
        ],
        "metric_branches": 2,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [
        "monthly"
      ],
      "implementation_contract": {
        "en": {
          "scope": "The denominator is every Internet-reachable domain, IP, service, cloud endpoint, application gateway, API and provider-hosted tenant the enterprise owns or authorizes, including shadow and transient exposure.",
          "build": "Continuously reconcile DNS, certificates, cloud inventory, routing and external attack-surface discovery, then run safe authenticated or unauthenticated tests appropriate to each service.",
          "proof": "Publish a benign exposed test service and vulnerable fixture, confirm discovery and scan, then remove them and verify disappearance only after inventory closure.",
          "boundary": "CDNs, WAFs and load balancers can hide vulnerable origins while scans only assess the edge."
        },
        "zh": {
          "scope": "分母是企业拥有或授权的所有公网域名、IP、服务、云端点、应用网关、API 和服务商托管租户，包括影子与短命暴露。",
          "build": "持续对账 DNS、证书、云台账、路由和外部攻击面发现，再按服务执行安全的有/无凭据测试；确认扫描源授权、速率和禁止破坏项，发现路由到真实服务责任人。",
          "proof": "发布无害测试服务和漏洞 Fixture，确认发现与扫描，移除后只有台账结案才算消失；测试 IPv6、替代端口、直连 Origin、遗忘子域和服务商前门，指标看完成的合格端点与未知暴露。",
          "boundary": "CDN/WAF/负载均衡会遮住脆弱 Origin，扫描可能只看边缘。"
        }
      },
      "category_counts": {
        "outcome": 7,
        "scope": 7,
        "ownership": 7,
        "data": 7,
        "integration": 7,
        "control": 7,
        "timing": 7,
        "exception": 7,
        "evidence": 7,
        "security": 7,
        "testing": 7,
        "operations": 7
      },
      "requirement_count": 84,
      "requirements": [
        {
          "code": "CIS-7.6-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "7.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Perform Automated Vulnerability Scans of Externally-Exposed Enterprise Assets; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“外网资产自动漏洞扫描”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-7.6-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "7.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 7.6, official Asset Class Software, Security Function Identify, and IG2 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 7.6、官方资产类别“软件”、安全功能“识别”和首次出现的 IG2，并保存来源抓取日期。"
        },
        {
          "code": "CIS-7.6-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "7.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “The denominator is every Internet-reachable domain, IP, service, cloud endpoint, application gateway, API and provider-hosted tenant the enterprise owns or authorizes, including shadow and transient exposure.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“分母是企业拥有或授权的所有公网域名、IP、服务、云端点、应用网关、API 和服务商托管租户，包括影子与短命暴露。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-7.6-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "7.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-7.6-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "7.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Perform Automated Vulnerability Scans of Externally-Exposed Enterprise Assets to its operating object—vulnerabilities, affected artifacts and deployments, exploitability context, remediation decisions, patches, mitigations, and residual exposure—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“外网资产自动漏洞扫描”连接到其运营对象——漏洞、受影响制品与部署、可利用性上下文、修复决策、补丁、缓解措施和残余暴露——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-7.6-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "7.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "For Perform Automated Vulnerability Scans of Externally-Exposed Enterprise Assets, express success as an observable decision over affected artifact identity, exploitability, business consequence, remediation choice, deployed fix, compensating control, and residual exposure; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“外网资产自动漏洞扫描”，以 受影响制品身份、可利用性、业务后果、修复选择、已部署修复、补偿控制和残余暴露 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-7.6-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "7.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "For Perform Automated Vulnerability Scans of Externally-Exposed Enterprise Assets, express success as an observable decision over coverage of every intended discovery vantage point, source, job, parser, and reconciliation path; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“外网资产自动漏洞扫描”，以 所有预期发现视角、来源、任务、解析器和对账路径的覆盖 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-7.6-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "7.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-7.6-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "7.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-7.6-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "7.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-7.6-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "7.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-7.6-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "7.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across unscannable assets, stale inventories, false positives, vendor backlog, compensating controls, superseded findings, ephemeral workloads, and failed patches; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 不可扫描资产、陈旧清单、误报、厂商积压、补偿控制、被取代发现、短生工作负载和失败补丁 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-7.6-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "7.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Include unknown versions, false positives, unavailable fixes, vendor lag, ephemeral workloads, unscannable platforms, inherited dependencies, mitigation-only states, and recurrence in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 未知版本、误报、无可用修复、厂商滞后、短生工作负载、不可扫描平台、继承依赖、仅缓解状态和复发 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-7.6-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "7.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Include unreachable zones, short-lived objects, blind spots, rate limits, credential failure, encrypted or proprietary protocols, and silent sensors in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 不可达区域、短生对象、盲区、限流、凭据失败、加密或专有协议和静默传感器 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-7.6-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "7.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-7.6-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "7.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-7.6-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "7.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-7.6-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "7.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-7.6-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "7.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind asset and application owners, vulnerability management, engineering, change management, threat intelligence, and risk owners to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 资产与应用责任人、漏洞管理、工程、变更管理、威胁情报和风险责任人 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-7.6-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "7.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Name who may transition discovered → validated → prioritized → assigned → fixed/mitigated/excepted → deployed → retested → closed/reopened, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 发现 → 验证 → 定级 → 分派 → 修复/缓解/例外 → 部署 → 复测 → 关闭/重开，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-7.6-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "7.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Name who may transition scheduled → started → observed → normalized → reconciled → dispositioned, with explicit partial and failed states, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 计划 → 启动 → 观测 → 归一化 → 对账 → 处置，并显式保留部分与失败状态，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-7.6-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "7.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-7.6-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "7.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-7.6-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "7.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV1, GV3, GV25, M1, M2, M3, M4, M5, M6) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV1, GV3, GV25, M1, M2, M3, M4, M5, M6）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-7.6-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "7.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-7.6-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "7.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the vulnerability finding and remediation authority linked to asset and software identity as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把与资产和软件身份关联的漏洞发现与修复权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-7.6-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "7.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle discovered → validated → prioritized → assigned → fixed/mitigated/excepted → deployed → retested → closed/reopened.",
          "zh": "对生命周期“发现 → 验证 → 定级 → 分派 → 修复/缓解/例外 → 部署 → 复测 → 关闭/重开”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-7.6-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "7.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle scheduled → started → observed → normalized → reconciled → dispositioned, with explicit partial and failed states.",
          "zh": "对生命周期“计划 → 启动 → 观测 → 归一化 → 对账 → 处置，并显式保留部分与失败状态”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-7.6-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "7.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 1.1, Safeguard 2.1, Safeguard 4.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 1.1、Safeguard 2.1、Safeguard 4.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-7.6-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "7.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-7.6-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "7.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-7.6-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "7.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-7.6-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "7.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile authenticated and unauthenticated scanners, package and image analysis, advisories, SBOMs, cloud findings, penetration tests, tickets, and deployment evidence and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 认证与非认证扫描、包与镜像分析、公告、SBOM、云发现、渗透测试、工单和部署证据，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-7.6-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "7.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Require every connector carrying affected artifact identity, exploitability, business consequence, remediation choice, deployed fix, compensating control, and residual exposure to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 受影响制品身份、可利用性、业务后果、修复选择、已部署修复、补偿控制和残余暴露 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-7.6-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "7.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Require every connector carrying coverage of every intended discovery vantage point, source, job, parser, and reconciliation path to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 所有预期发现视角、来源、任务、解析器和对账路径的覆盖 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-7.6-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "7.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Continuously reconcile DNS, certificates, cloud inventory, routing and external attack-surface discovery, then run safe authenticated or unauthenticated tests appropriate to each service.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“持续对账 DNS、证书、云台账、路由和外部攻击面发现，再按服务执行安全的有/无凭据测试；确认扫描源授权、速率和禁止破坏项，发现路由到真实服务责任人。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-7.6-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "7.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-7.6-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "7.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-7.6-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "7.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-7.6-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "7.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the vulnerability finding and remediation authority linked to asset and software identity and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在与资产和软件身份关联的漏洞发现与修复权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-7.6-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "7.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Implement the explicit state machine discovered → validated → prioritized → assigned → fixed/mitigated/excepted → deployed → retested → closed/reopened; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“发现 → 验证 → 定级 → 分派 → 修复/缓解/例外 → 部署 → 复测 → 关闭/重开”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-7.6-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "7.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Implement the explicit state machine scheduled → started → observed → normalized → reconciled → dispositioned, with explicit partial and failed states; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“计划 → 启动 → 观测 → 归一化 → 对账 → 处置，并显式保留部分与失败状态”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-7.6-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "7.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (monthly); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（monthly）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-7.6-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "7.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-7.6-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "7.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-7.6-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "7.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-7.6-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "7.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in vulnerabilities, affected artifacts and deployments, exploitability context, remediation decisions, patches, mitigations, and residual exposure; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 漏洞、受影响制品与部署、可利用性上下文、修复决策、补丁、缓解措施和残余暴露 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-7.6-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "7.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for discovered → validated → prioritized → assigned → fixed/mitigated/excepted → deployed → retested → closed/reopened; alert before each deadline becomes overdue.",
          "zh": "为“发现 → 验证 → 定级 → 分派 → 修复/缓解/例外 → 部署 → 复测 → 关闭/重开”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-7.6-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "7.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for scheduled → started → observed → normalized → reconciled → dispositioned, with explicit partial and failed states; alert before each deadline becomes overdue.",
          "zh": "为“计划 → 启动 → 观测 → 归一化 → 对账 → 处置，并显式保留部分与失败状态”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-7.6-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "7.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “CDNs, WAFs and load balancers can hide vulnerable origins while scans only assess the edge.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“CDN/WAF/负载均衡会遮住脆弱 Origin，扫描可能只看边缘。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-7.6-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "7.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-7.6-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "7.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-7.6-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "7.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-7.6-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "7.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat unscannable assets, stale inventories, false positives, vendor backlog, compensating controls, superseded findings, ephemeral workloads, and failed patches as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 不可扫描资产、陈旧清单、误报、厂商积压、补偿控制、被取代发现、短生工作负载和失败补丁 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-7.6-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "7.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Treat unknown versions, false positives, unavailable fixes, vendor lag, ephemeral workloads, unscannable platforms, inherited dependencies, mitigation-only states, and recurrence as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 未知版本、误报、无可用修复、厂商滞后、短生工作负载、不可扫描平台、继承依赖、仅缓解状态和复发 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-7.6-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "7.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Treat unreachable zones, short-lived objects, blind spots, rate limits, credential failure, encrypted or proprietary protocols, and silent sensors as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 不可达区域、短生对象、盲区、限流、凭据失败、加密或专有协议和静默传感器 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-7.6-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "7.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Publish a benign exposed test service and vulnerable fixture, confirm discovery and scan, then remove them and verify disappearance only after inventory closure.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“发布无害测试服务和漏洞 Fixture，确认发现与扫描，移除后只有台账结案才算消失；测试 IPv6、替代端口、直连 Origin、遗忘子域和服务商前门，指标看完成的合格端点与未知暴露。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-7.6-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "7.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-7.6-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "7.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 2 pinned CAS metric branch(es), 9 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 2 个指标分支、9 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-7.6-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "7.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-7.6-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "7.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the vulnerability finding and remediation authority linked to asset and software identity plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以与资产和软件身份关联的漏洞发现与修复权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-7.6-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "7.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Publish open, validated, false-positive, overdue, mitigated, excepted, deployed-unverified, retest-failed, reopened, and exposure-weighted findings with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 开放、已验证、误报、逾期、已缓解、例外、已部署未验证、复测失败、重开和暴露加权发现，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-7.6-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "7.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Publish scheduled, successful, partial, failed, stale, blind, newly discovered, unmatched, and reconciled observations with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 计划、成功、部分、失败、陈旧、盲区、新发现、未匹配和已对账观测，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-7.6-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "7.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-7.6-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "7.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-7.6-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "7.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-7.6-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "7.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-7.6-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "7.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the vulnerability finding and remediation authority linked to asset and software identity; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护与资产和软件身份关联的漏洞发现与修复权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-7.6-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "7.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Restrict authority to change discovered → validated → prioritized → assigned → fixed/mitigated/excepted → deployed → retested → closed/reopened; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“发现 → 验证 → 定级 → 分派 → 修复/缓解/例外 → 部署 → 复测 → 关闭/重开”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-7.6-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "7.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Restrict authority to change scheduled → started → observed → normalized → reconciled → dispositioned, with explicit partial and failed states; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“计划 → 启动 → 观测 → 归一化 → 对账 → 处置，并显式保留部分与失败状态”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-7.6-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "7.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-7.6-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "7.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-7.6-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "7.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-7.6-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "7.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-7.6-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "7.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise known vulnerable and fixed artifacts, credential failure, false-positive review, patch rollback, recurrence, external exposure, and mitigation bypass through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 已知漏洞与已修复制品、凭据失败、误报复核、补丁回滚、复发、外部暴露和缓解绕过，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-7.6-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "7.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Run the positive control a known vulnerable artifact repaired and independently retested; exercise negative, stale, duplicate, bypass, and outage controls including credential failure, wrong version match, unavailable fix, mitigation bypass, failed deployment, rollback, recurring finding, and exposed unowned asset.",
          "zh": "运行正向控制“一项已知漏洞制品完成修复并独立复测”，并执行包含“凭据失败、版本误配、无可用修复、缓解绕过、部署失败、回滚、问题复发和外露无主资产”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-7.6-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "7.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Run the positive control a known object visible from each representative vantage point; exercise negative, stale, duplicate, bypass, and outage controls including an unknown and short-lived object, failed credential, blocked scan, silent sensor, parser drift, and uncovered segment.",
          "zh": "运行正向控制“从每个代表性视角可见的一项已知对象”，并执行包含“未知与短生对象、凭据失败、扫描受阻、传感器静默、解析漂移和未覆盖网段”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-7.6-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "7.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-7.6-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "7.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-7.6-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "7.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-7.6-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "7.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-7.6-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "7.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever authenticated and unauthenticated scanners, package and image analysis, advisories, SBOMs, cloud findings, penetration tests, tickets, and deployment evidence change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 认证与非认证扫描、包与镜像分析、公告、SBOM、云发现、渗透测试、工单和部署证据 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-7.6-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "7.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Use open, validated, false-positive, overdue, mitigated, excepted, deployed-unverified, retest-failed, reopened, and exposure-weighted findings to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 开放、已验证、误报、逾期、已缓解、例外、已部署未验证、复测失败、重开和暴露加权发现 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-7.6-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "7.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Use scheduled, successful, partial, failed, stale, blind, newly discovered, unmatched, and reconciled observations to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 计划、成功、部分、失败、陈旧、盲区、新发现、未匹配和已对账观测 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "7.7",
      "control": 7,
      "title_en": "Remediate Detected Vulnerabilities",
      "title_zh": "漏洞修复与闭环",
      "first_ig": 2,
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Software",
      "security_function": "Respond",
      "patterns": [
        "vulnerability"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "1.1"
        ],
        "variables": [
          "GV1",
          "M1",
          "M2",
          "M3",
          "M4"
        ],
        "metric_branches": 1,
        "has_assumptions": true,
        "has_procedural_review": false
      },
      "official_cadence_terms": [
        "monthly"
      ],
      "implementation_contract": {
        "en": {
          "scope": "The population is every accepted finding-instance tied to an asset, component, configuration and evidence source, including duplicates consolidated without losing affected scope.",
          "build": "Route by the risk-based process, apply patch/upgrade/configuration/isolation/removal, preserve change and exception records, and require independent verification at least monthly or faster.",
          "proof": "Reproduce or rescan the exact affected path after treatment and pair it with a positive control proving the scanner/test still works.",
          "boundary": "The CAS assumes a finding absent from the next scan was remediated; asset disappearance, credential loss, scope change or scanner failure can create the same result."
        },
        "zh": {
          "scope": "总体是关联到资产、组件、配置和证据源的每个发现实例；去重不能丢失受影响范围。",
          "build": "按风险流程路由，补丁/升级/改配置/隔离/移除，保留变更和例外，并至少每月或更快独立验证；资产、易受害版本或暴露再现时重开，系统性根因回馈配置与开发控制。",
          "proof": "处理后重现或重扫准确路径，同时用正控证明扫描/测试仍工作；核对运行版本、利用条件和补偿控制，分别报告验证关闭、修复失败、重开和按风险逾期。",
          "boundary": "CAS 假设下次扫描没出现就是已修，但资产消失、凭据丢失、范围变化和扫描失败都能造成同样结果。"
        }
      },
      "category_counts": {
        "outcome": 6,
        "scope": 6,
        "ownership": 6,
        "data": 6,
        "integration": 6,
        "control": 6,
        "timing": 6,
        "exception": 6,
        "evidence": 6,
        "security": 6,
        "testing": 6,
        "operations": 6
      },
      "requirement_count": 72,
      "requirements": [
        {
          "code": "CIS-7.7-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "7.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Remediate Detected Vulnerabilities; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“漏洞修复与闭环”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-7.7-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "7.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 7.7, official Asset Class Software, Security Function Respond, and IG2 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 7.7、官方资产类别“软件”、安全功能“响应”和首次出现的 IG2，并保存来源抓取日期。"
        },
        {
          "code": "CIS-7.7-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "7.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “The population is every accepted finding-instance tied to an asset, component, configuration and evidence source, including duplicates consolidated without losing affected scope.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“总体是关联到资产、组件、配置和证据源的每个发现实例；去重不能丢失受影响范围。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-7.7-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "7.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-7.7-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "7.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Remediate Detected Vulnerabilities to its operating object—vulnerabilities, affected artifacts and deployments, exploitability context, remediation decisions, patches, mitigations, and residual exposure—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“漏洞修复与闭环”连接到其运营对象——漏洞、受影响制品与部署、可利用性上下文、修复决策、补丁、缓解措施和残余暴露——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-7.7-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "7.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "For Remediate Detected Vulnerabilities, express success as an observable decision over affected artifact identity, exploitability, business consequence, remediation choice, deployed fix, compensating control, and residual exposure; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“漏洞修复与闭环”，以 受影响制品身份、可利用性、业务后果、修复选择、已部署修复、补偿控制和残余暴露 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-7.7-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "7.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-7.7-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "7.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-7.7-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "7.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-7.7-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "7.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-7.7-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "7.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across unscannable assets, stale inventories, false positives, vendor backlog, compensating controls, superseded findings, ephemeral workloads, and failed patches; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 不可扫描资产、陈旧清单、误报、厂商积压、补偿控制、被取代发现、短生工作负载和失败补丁 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-7.7-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "7.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Include unknown versions, false positives, unavailable fixes, vendor lag, ephemeral workloads, unscannable platforms, inherited dependencies, mitigation-only states, and recurrence in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 未知版本、误报、无可用修复、厂商滞后、短生工作负载、不可扫描平台、继承依赖、仅缓解状态和复发 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-7.7-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "7.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-7.7-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "7.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-7.7-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "7.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-7.7-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "7.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-7.7-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "7.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind asset and application owners, vulnerability management, engineering, change management, threat intelligence, and risk owners to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 资产与应用责任人、漏洞管理、工程、变更管理、威胁情报和风险责任人 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-7.7-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "7.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Name who may transition discovered → validated → prioritized → assigned → fixed/mitigated/excepted → deployed → retested → closed/reopened, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 发现 → 验证 → 定级 → 分派 → 修复/缓解/例外 → 部署 → 复测 → 关闭/重开，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-7.7-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "7.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-7.7-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "7.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-7.7-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "7.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV1, M1, M2, M3, M4) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV1, M1, M2, M3, M4）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-7.7-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "7.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-7.7-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "7.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the vulnerability finding and remediation authority linked to asset and software identity as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把与资产和软件身份关联的漏洞发现与修复权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-7.7-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "7.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle discovered → validated → prioritized → assigned → fixed/mitigated/excepted → deployed → retested → closed/reopened.",
          "zh": "对生命周期“发现 → 验证 → 定级 → 分派 → 修复/缓解/例外 → 部署 → 复测 → 关闭/重开”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-7.7-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "7.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 1.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 1.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-7.7-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "7.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-7.7-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "7.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-7.7-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "7.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-7.7-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "7.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile authenticated and unauthenticated scanners, package and image analysis, advisories, SBOMs, cloud findings, penetration tests, tickets, and deployment evidence and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 认证与非认证扫描、包与镜像分析、公告、SBOM、云发现、渗透测试、工单和部署证据，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-7.7-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "7.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Require every connector carrying affected artifact identity, exploitability, business consequence, remediation choice, deployed fix, compensating control, and residual exposure to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 受影响制品身份、可利用性、业务后果、修复选择、已部署修复、补偿控制和残余暴露 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-7.7-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "7.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Route by the risk-based process, apply patch/upgrade/configuration/isolation/removal, preserve change and exception records, and require independent verification at least monthly or faster.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“按风险流程路由，补丁/升级/改配置/隔离/移除，保留变更和例外，并至少每月或更快独立验证；资产、易受害版本或暴露再现时重开，系统性根因回馈配置与开发控制。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-7.7-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "7.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-7.7-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "7.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-7.7-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "7.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-7.7-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "7.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the vulnerability finding and remediation authority linked to asset and software identity and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在与资产和软件身份关联的漏洞发现与修复权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-7.7-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "7.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Implement the explicit state machine discovered → validated → prioritized → assigned → fixed/mitigated/excepted → deployed → retested → closed/reopened; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“发现 → 验证 → 定级 → 分派 → 修复/缓解/例外 → 部署 → 复测 → 关闭/重开”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-7.7-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "7.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (monthly); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（monthly）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-7.7-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "7.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-7.7-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "7.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-7.7-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "7.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-7.7-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "7.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in vulnerabilities, affected artifacts and deployments, exploitability context, remediation decisions, patches, mitigations, and residual exposure; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 漏洞、受影响制品与部署、可利用性上下文、修复决策、补丁、缓解措施和残余暴露 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-7.7-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "7.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for discovered → validated → prioritized → assigned → fixed/mitigated/excepted → deployed → retested → closed/reopened; alert before each deadline becomes overdue.",
          "zh": "为“发现 → 验证 → 定级 → 分派 → 修复/缓解/例外 → 部署 → 复测 → 关闭/重开”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-7.7-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "7.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “The CAS assumes a finding absent from the next scan was remediated; asset disappearance, credential loss, scope change or scanner failure can create the same result.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“CAS 假设下次扫描没出现就是已修，但资产消失、凭据丢失、范围变化和扫描失败都能造成同样结果。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-7.7-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "7.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-7.7-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "7.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-7.7-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "7.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-7.7-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "7.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat unscannable assets, stale inventories, false positives, vendor backlog, compensating controls, superseded findings, ephemeral workloads, and failed patches as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 不可扫描资产、陈旧清单、误报、厂商积压、补偿控制、被取代发现、短生工作负载和失败补丁 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-7.7-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "7.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Treat unknown versions, false positives, unavailable fixes, vendor lag, ephemeral workloads, unscannable platforms, inherited dependencies, mitigation-only states, and recurrence as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 未知版本、误报、无可用修复、厂商滞后、短生工作负载、不可扫描平台、继承依赖、仅缓解状态和复发 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-7.7-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "7.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Reproduce or rescan the exact affected path after treatment and pair it with a positive control proving the scanner/test still works.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“处理后重现或重扫准确路径，同时用正控证明扫描/测试仍工作；核对运行版本、利用条件和补偿控制，分别报告验证关闭、修复失败、重开和按风险逾期。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-7.7-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "7.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-7.7-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "7.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 5 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、5 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-7.7-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "7.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-7.7-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "7.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the vulnerability finding and remediation authority linked to asset and software identity plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以与资产和软件身份关联的漏洞发现与修复权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-7.7-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "7.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Publish open, validated, false-positive, overdue, mitigated, excepted, deployed-unverified, retest-failed, reopened, and exposure-weighted findings with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 开放、已验证、误报、逾期、已缓解、例外、已部署未验证、复测失败、重开和暴露加权发现，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-7.7-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "7.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-7.7-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "7.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-7.7-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "7.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-7.7-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "7.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-7.7-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "7.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the vulnerability finding and remediation authority linked to asset and software identity; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护与资产和软件身份关联的漏洞发现与修复权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-7.7-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "7.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Restrict authority to change discovered → validated → prioritized → assigned → fixed/mitigated/excepted → deployed → retested → closed/reopened; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“发现 → 验证 → 定级 → 分派 → 修复/缓解/例外 → 部署 → 复测 → 关闭/重开”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-7.7-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "7.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-7.7-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "7.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-7.7-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "7.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-7.7-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "7.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-7.7-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "7.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise known vulnerable and fixed artifacts, credential failure, false-positive review, patch rollback, recurrence, external exposure, and mitigation bypass through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 已知漏洞与已修复制品、凭据失败、误报复核、补丁回滚、复发、外部暴露和缓解绕过，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-7.7-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "7.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Run the positive control a known vulnerable artifact repaired and independently retested; exercise negative, stale, duplicate, bypass, and outage controls including credential failure, wrong version match, unavailable fix, mitigation bypass, failed deployment, rollback, recurring finding, and exposed unowned asset.",
          "zh": "运行正向控制“一项已知漏洞制品完成修复并独立复测”，并执行包含“凭据失败、版本误配、无可用修复、缓解绕过、部署失败、回滚、问题复发和外露无主资产”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-7.7-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "7.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-7.7-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "7.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-7.7-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "7.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-7.7-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "7.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-7.7-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "7.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever authenticated and unauthenticated scanners, package and image analysis, advisories, SBOMs, cloud findings, penetration tests, tickets, and deployment evidence change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 认证与非认证扫描、包与镜像分析、公告、SBOM、云发现、渗透测试、工单和部署证据 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-7.7-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "7.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Use open, validated, false-positive, overdue, mitigated, excepted, deployed-unverified, retest-failed, reopened, and exposure-weighted findings to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 开放、已验证、误报、逾期、已缓解、例外、已部署未验证、复测失败、重开和暴露加权发现 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "8.1",
      "control": 8,
      "title_en": "Establish and Maintain an Audit Log Management Process",
      "title_zh": "审计日志管理流程",
      "first_ig": 1,
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Documentation",
      "security_function": "Govern",
      "patterns": [
        "telemetry",
        "governance"
      ],
      "expanded_complexity": true,
      "cas_context": {
        "dependencies": [],
        "variables": [
          "GV26",
          "M1",
          "M2",
          "M3"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [
        "annually"
      ],
      "implementation_contract": {
        "en": {
          "scope": "The process covers security-relevant logs from assets, identity, applications, data, cloud/SaaS, network, development and providers through generation, transport, normalization, protection, use, retention and disposal.",
          "build": "Define mandatory events/fields by source, owner, collection path, time, access, integrity, capacity, retention, privacy, review/detection use and failure response.",
          "proof": "Select representative incident questions and prove the required events can answer actor, action, object, time, source and result within retention.",
          "boundary": "Document completeness is the CAS focus; useful log arrival requires a separate observation."
        },
        "zh": {
          "scope": "覆盖资产、身份、应用、数据、云/SaaS、网络、开发和服务商日志从产生、传输、归一、保护、使用、保留到销毁的全链路；区分取证、检测、运维和法律用途，不主张“全部都记”。",
          "build": "按来源定义必需事件/字段、责任人、采集路径、时间、访问、完整性、容量、保留、隐私、复核/检测用途和故障处理；关联资产/数据台账和消费者，每年及架构、威胁、法规、服务商变化时更新。",
          "proof": "选代表事件问题，证明日志能在保留期内回答谁、何时、从哪里对什么做了什么、结果如何。",
          "boundary": "文档完整度（CAS 重点）不能证明日志有用或到达。"
        }
      },
      "category_counts": {
        "outcome": 8,
        "scope": 8,
        "ownership": 8,
        "data": 8,
        "integration": 8,
        "control": 8,
        "timing": 8,
        "exception": 8,
        "evidence": 8,
        "security": 8,
        "testing": 8,
        "operations": 8
      },
      "requirement_count": 96,
      "requirements": [
        {
          "code": "CIS-8.1-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "8.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Establish and Maintain an Audit Log Management Process; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“审计日志管理流程”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-8.1-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "8.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 8.1, official Asset Class Documentation, Security Function Govern, and IG1 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 8.1、官方资产类别“文档与治理”、安全功能“治理”和首次出现的 IG1，并保存来源抓取日期。"
        },
        {
          "code": "CIS-8.1-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "8.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “The process covers security-relevant logs from assets, identity, applications, data, cloud/SaaS, network, development and providers through generation, transport, normalization, protection, use, retention and disposal.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“覆盖资产、身份、应用、数据、云/SaaS、网络、开发和服务商日志从产生、传输、归一、保护、使用、保留到销毁的全链路；区分取证、检测、运维和法律用途，不主张“全部都记”。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-8.1-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "8.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-8.1-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "8.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Establish and Maintain an Audit Log Management Process to its operating object—security-relevant events, actor and target identity, timestamps, decisions, outcomes, source health, retention, search, and custody—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“审计日志管理流程”连接到其运营对象——安全相关事件、行为者与目标身份、时间、决策、结果、来源健康、保留、检索和证据保管——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-8.1-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "8.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "For Establish and Maintain an Audit Log Management Process, express success as an observable decision over complete, attributable, timely, protected, searchable, and actionable security telemetry plus source health; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“审计日志管理流程”，以 完整、可归因、及时、受保护、可检索、可行动的安全遥测及来源健康 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-8.1-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "8.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "For Establish and Maintain an Audit Log Management Process, express success as an observable decision over a documented decision system with policy, process, procedure, accountable owner, approval, and review; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“审计日志管理流程”，以 包含策略、流程、程序、责任人、审批和复核的文档化决策系统 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-8.1-OUT-08",
          "local_code": "OUT-08",
          "display_code": "O08",
          "safeguard_id": "8.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "For the expanded Establish and Maintain an Audit Log Management Process scope, resolve conflicts among security, safety, privacy, legal, availability, customer, and operational objectives through an explicit risk decision.",
          "zh": "对“审计日志管理流程”的扩展范围，通过显式风险决策解决安全、安全生产、隐私、法律、可用性、客户和运营目标冲突。"
        },
        {
          "code": "CIS-8.1-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "8.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-8.1-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "8.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-8.1-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "8.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-8.1-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "8.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-8.1-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "8.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across missing fields, clock drift, parser failure, dropped events, duplicate delivery, pooled identities, privacy redaction, provider gaps, quota, and archive unreadability; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 字段缺失、时钟漂移、解析失败、事件丢失、重复投递、汇聚身份、隐私脱敏、提供商缺口、配额和归档不可读 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-8.1-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "8.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Include clock skew, actor loss, field truncation, parser drift, dropped or duplicate events, privacy redaction, provider gaps, encrypted paths, quota, and archive failure in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 时钟偏移、行为者丢失、字段截断、解析漂移、事件丢失或重复、隐私脱敏、提供商缺口、加密路径、配额和归档故障 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-8.1-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "8.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Include missing policy clauses, conflicting authorities, local deviations, obsolete documentation, and decisions made outside the governed workflow in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 策略条款缺失、权限冲突、本地偏离、文档过期及绕过治理流程的决策 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-8.1-SCP-08",
          "local_code": "SCP-08",
          "display_code": "P08",
          "safeguard_id": "8.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Define nested scope at enterprise, business service, tenant, environment, platform, object, identity, data set, and transaction levels; prohibit a parent result from hiding a failing child.",
          "zh": "按企业、业务服务、租户、环境、平台、对象、身份、数据集和交易定义嵌套范围，禁止父级结果遮蔽失败子级。"
        },
        {
          "code": "CIS-8.1-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "8.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-8.1-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "8.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-8.1-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "8.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-8.1-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "8.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-8.1-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "8.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind source owners, platform and security engineering, detection teams, incident responders, privacy, records management, and auditors to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 来源责任人、平台与安全工程、检测团队、事件响应、隐私、档案管理和审计方 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-8.1-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "8.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Name who may transition event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-8.1-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "8.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Name who may transition draft → reviewed → approved → effective → exception/withdrawn → superseded, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-8.1-OWN-08",
          "local_code": "OWN-08",
          "display_code": "W08",
          "safeguard_id": "8.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Model delegated authority, quorum or dual approval where warranted, escalation deadlines, provider handoffs, conflict resolution, and executive risk acceptance.",
          "zh": "建模委派权限、必要时的双人或法定人数审批、升级期限、提供商交接、冲突解决和管理层风险接受。"
        },
        {
          "code": "CIS-8.1-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "8.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-8.1-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "8.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-8.1-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "8.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV26, M1, M2, M3) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV26, M1, M2, M3）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-8.1-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "8.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-8.1-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "8.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the governed log-source inventory and evidence platform as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把受治理的日志源清单与证据平台作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-8.1-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "8.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired.",
          "zh": "对生命周期“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-8.1-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "8.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle draft → reviewed → approved → effective → exception/withdrawn → superseded.",
          "zh": "对生命周期“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-8.1-DAT-08",
          "local_code": "DAT-08",
          "display_code": "D08",
          "safeguard_id": "8.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Version schemas and state transitions with migration, backfill, deduplication, lineage, historical denominator, deletion, and rollback semantics.",
          "zh": "对模式和状态转换做版本管理，定义迁移、回填、去重、血缘、历史分母、删除和回滚语义。"
        },
        {
          "code": "CIS-8.1-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "8.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for no explicit predecessor in the pinned CAS page; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 固定 CAS 页面没有列出显式前置项 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-8.1-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "8.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-8.1-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "8.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-8.1-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "8.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-8.1-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "8.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile endpoints, identity, applications, databases, network, cloud/SaaS, providers, collectors, archives, detections, and review records and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 终端、身份、应用、数据库、网络、云/SaaS、提供商、采集器、归档、检测和审阅记录，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-8.1-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "8.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Require every connector carrying complete, attributable, timely, protected, searchable, and actionable security telemetry plus source health to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 完整、可归因、及时、受保护、可检索、可行动的安全遥测及来源健康 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-8.1-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "8.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Require every connector carrying a documented decision system with policy, process, procedure, accountable owner, approval, and review to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 包含策略、流程、程序、责任人、审批和复核的文档化决策系统 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-8.1-INT-08",
          "local_code": "INT-08",
          "display_code": "I08",
          "safeguard_id": "8.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Define consistency rules across disagreeing sources, source precedence, confidence, reconciliation queues, dead-letter handling, reprocessing, and end-to-end trace identity.",
          "zh": "定义冲突来源的一致性、优先级、置信度、对账队列、死信、重处理和端到端追踪身份。"
        },
        {
          "code": "CIS-8.1-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "8.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Define mandatory events/fields by source, owner, collection path, time, access, integrity, capacity, retention, privacy, review/detection use and failure response.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“按来源定义必需事件/字段、责任人、采集路径、时间、访问、完整性、容量、保留、隐私、复核/检测用途和故障处理；关联资产/数据台账和消费者，每年及架构、威胁、法规、服务商变化时更新。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-8.1-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "8.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-8.1-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "8.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-8.1-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "8.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-8.1-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "8.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the governed log-source inventory and evidence platform and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在受治理的日志源清单与证据平台中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-8.1-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "8.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Implement the explicit state machine event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-8.1-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "8.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Implement the explicit state machine draft → reviewed → approved → effective → exception/withdrawn → superseded; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-8.1-CTL-08",
          "local_code": "CTL-08",
          "display_code": "C08",
          "safeguard_id": "8.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Specify concurrent decisions, partial success, compensating transactions, repeated requests, stale policy, dependency outage, and recovery from an interrupted state transition.",
          "zh": "定义并发决策、部分成功、补偿事务、重复请求、陈旧策略、依赖中断和中途状态转换恢复。"
        },
        {
          "code": "CIS-8.1-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "8.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (annually); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（annually）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-8.1-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "8.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-8.1-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "8.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-8.1-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "8.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-8.1-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "8.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in security-relevant events, actor and target identity, timestamps, decisions, outcomes, source health, retention, search, and custody; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 安全相关事件、行为者与目标身份、时间、决策、结果、来源健康、保留、检索和证据保管 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-8.1-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "8.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired; alert before each deadline becomes overdue.",
          "zh": "为“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-8.1-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "8.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for draft → reviewed → approved → effective → exception/withdrawn → superseded; alert before each deadline becomes overdue.",
          "zh": "为“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-8.1-TIM-08",
          "local_code": "TIM-08",
          "display_code": "T08",
          "safeguard_id": "8.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Allocate an end-to-end SLO budget across discovery, collection, processing, approval, enforcement, verification, and closure; prioritize overdue work by consequence and exposure.",
          "zh": "把端到端 SLO 预算分配到发现、采集、处理、审批、执行、验证和关闭，并按后果与暴露排列逾期工作。"
        },
        {
          "code": "CIS-8.1-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "8.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “Document completeness is the CAS focus; useful log arrival requires a separate observation.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“文档完整度（CAS 重点）不能证明日志有用或到达。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-8.1-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "8.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-8.1-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "8.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-8.1-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "8.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-8.1-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "8.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat missing fields, clock drift, parser failure, dropped events, duplicate delivery, pooled identities, privacy redaction, provider gaps, quota, and archive unreadability as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 字段缺失、时钟漂移、解析失败、事件丢失、重复投递、汇聚身份、隐私脱敏、提供商缺口、配额和归档不可读 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-8.1-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "8.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Treat clock skew, actor loss, field truncation, parser drift, dropped or duplicate events, privacy redaction, provider gaps, encrypted paths, quota, and archive failure as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 时钟偏移、行为者丢失、字段截断、解析漂移、事件丢失或重复、隐私脱敏、提供商缺口、加密路径、配额和归档故障 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-8.1-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "8.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Treat missing policy clauses, conflicting authorities, local deviations, obsolete documentation, and decisions made outside the governed workflow as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 策略条款缺失、权限冲突、本地偏离、文档过期及绕过治理流程的决策 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-8.1-EXC-08",
          "local_code": "EXC-08",
          "display_code": "X08",
          "safeguard_id": "8.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Exercise compound failures where an exception, stale source, provider outage, unavailable owner, and degraded control overlap; define one safe command and one accountable decision.",
          "zh": "演练例外、陈旧来源、提供商中断、责任人不可用和控制降级同时出现的复合故障，明确一条安全指令和一个责任决策。"
        },
        {
          "code": "CIS-8.1-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "8.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Select representative incident questions and prove the required events can answer actor, action, object, time, source and result within retention.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“选代表事件问题，证明日志能在保留期内回答谁、何时、从哪里对什么做了什么、结果如何。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-8.1-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "8.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-8.1-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "8.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 4 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、4 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-8.1-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "8.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-8.1-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "8.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the governed log-source inventory and evidence platform plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以受治理的日志源清单与证据平台和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-8.1-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "8.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Publish healthy, silent, partial, late, malformed, duplicate, unowned, unreviewed, alerted, investigated, and archived sources or events with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 健康、静默、部分、迟到、畸形、重复、无责任人、未审阅、已告警、已调查和已归档来源或事件，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-8.1-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "8.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Publish clause coverage, owner and reviewer completeness, approval age, triggered reviews, deviations, overdue actions, and superseded versions still in use with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 条款覆盖、责任人与复核人完整性、批准年龄、触发式复核、偏离、逾期行动及仍在使用的旧版本，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-8.1-EVD-08",
          "local_code": "EVD-08",
          "display_code": "E08",
          "safeguard_id": "8.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Require an independent party to reconstruct the decision from source receipts and reproduce the population, state transition, calculation, test result, exception, and final closure.",
          "zh": "要求独立人员使用来源回执重建决策，并复现总体、状态转换、计算、测试结果、例外和最终关闭。"
        },
        {
          "code": "CIS-8.1-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "8.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-8.1-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "8.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-8.1-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "8.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-8.1-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "8.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-8.1-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "8.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the governed log-source inventory and evidence platform; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护受治理的日志源清单与证据平台的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-8.1-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "8.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Restrict authority to change event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-8.1-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "8.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Restrict authority to change draft → reviewed → approved → effective → exception/withdrawn → superseded; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-8.1-SEC-08",
          "local_code": "SEC-08",
          "display_code": "S08",
          "safeguard_id": "8.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Threat-model the implementation system itself: forged evidence, poisoned inventory, privilege abuse, cross-tenant confusion, policy rollback, audit deletion, denial of service, and recovery compromise.",
          "zh": "威胁建模实施系统自身：伪造证据、污染清单、权限滥用、跨租户混淆、策略回滚、审计删除、拒绝服务和恢复失陷。"
        },
        {
          "code": "CIS-8.1-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "8.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-8.1-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "8.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-8.1-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "8.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-8.1-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "8.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-8.1-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "8.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise allowed and denied canary events, collector and parser failure, clock skew, retention boundary, archive restore, provider export loss, and analyst review through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 允许与拒绝的金丝雀事件、采集器与解析器故障、时钟偏移、保留边界、归档恢复、提供商导出丢失和分析员审阅，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-8.1-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "8.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Run the positive control an allowed and denied canary event traced from source through review; exercise negative, stale, duplicate, bypass, and outage controls including source loss, parser/schema change, time skew, queue overflow, duplicate delivery, provider export outage, missed alert, and unreadable archive.",
          "zh": "运行正向控制“一项允许与拒绝金丝雀事件从来源贯穿到审阅”，并执行包含“来源丢失、解析器/模式变化、时钟偏移、队列溢出、重复投递、提供商导出中断、漏报和归档不可读”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-8.1-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "8.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Run the positive control an approved current process used for a representative decision; exercise negative, stale, duplicate, bypass, and outage controls including an obsolete version, missing approver, undocumented deviation, overdue review, and bypassed workflow.",
          "zh": "运行正向控制“使用当前获批流程完成一项代表性决策”，并执行包含“旧版本、审批人缺失、未记录偏离、逾期复核和绕过流程”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-8.1-TST-08",
          "local_code": "TST-08",
          "display_code": "V08",
          "safeguard_id": "8.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Build a pairwise platform-and-failure matrix, then add high-consequence multi-factor cases, historical regression, source substitution, red-team challenge, and assessor replay.",
          "zh": "建立平台—故障两两组合矩阵，再加入高后果多因素案例、历史回归、来源替换、红队挑战和评估方重放。"
        },
        {
          "code": "CIS-8.1-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "8.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-8.1-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "8.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-8.1-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "8.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-8.1-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "8.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-8.1-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "8.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever endpoints, identity, applications, databases, network, cloud/SaaS, providers, collectors, archives, detections, and review records change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 终端、身份、应用、数据库、网络、云/SaaS、提供商、采集器、归档、检测和审阅记录 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-8.1-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "8.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Use healthy, silent, partial, late, malformed, duplicate, unowned, unreviewed, alerted, investigated, and archived sources or events to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 健康、静默、部分、迟到、畸形、重复、无责任人、未审阅、已告警、已调查和已归档来源或事件 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-8.1-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "8.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Use clause coverage, owner and reviewer completeness, approval age, triggered reviews, deviations, overdue actions, and superseded versions still in use to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 条款覆盖、责任人与复核人完整性、批准年龄、触发式复核、偏离、逾期行动及仍在使用的旧版本 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-8.1-OPS-08",
          "local_code": "OPS-08",
          "display_code": "R08",
          "safeguard_id": "8.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Use canary deployment, kill criteria, rollback, backlog burn-down, exception reduction, source-quality targets, quarterly design review, and a measurable retirement plan.",
          "zh": "采用金丝雀、停止标准、回滚、积压燃尽、例外缩减、来源质量目标、季度设计复核和可量化退役计划。"
        }
      ]
    },
    {
      "id": "8.2",
      "control": 8,
      "title_en": "Collect Audit Logs",
      "title_zh": "日志采集",
      "first_ig": 1,
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Data",
      "security_function": "Detect",
      "patterns": [
        "telemetry",
        "discovery"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "1.1",
          "4.1",
          "8.1"
        ],
        "variables": [
          "GV1",
          "GV3",
          "GV26",
          "GV27",
          "M1",
          "M2",
          "M3"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "Include every in-scope asset and control plane capable of security-relevant logging, with event sets defined by 8.1.",
          "build": "Configure source generation and reliable forwarding, buffer outages, authenticate transport, protect credentials and monitor heartbeat, lag, parse and drop.",
          "proof": "Generate an allowed and denied canary event on each source class and trace raw and normalized forms to the destination with correct identity/time.",
          "boundary": "Devices may be online but legitimately quiet, so use synthetic heartbeats or configuration plus expected-event tests."
        },
        "zh": {
          "scope": "包括所有能产生安全相关事件的在管资产和控制面，事件集由 8.1 规定。",
          "build": "配置源端产生与可靠转发，故障时缓冲，认证传输，保护凭据并监测心跳、延迟、解析和丢弃；短命工作负载用镜像/策略即代码，托管服务用服务商 API，并分别指定源和管道责任人。",
          "proof": "在每类源生成允许与拒绝金丝雀事件，追踪原始/归一形式和正确身份/时间；覆盖率以独立合格台账为分母，要求近期送达必需事件，另列静默、部分、延迟与解析失败。",
          "boundary": "设备在线却业务安静时，用合成心跳或配置加预期事件验证。"
        }
      },
      "category_counts": {
        "outcome": 7,
        "scope": 7,
        "ownership": 7,
        "data": 7,
        "integration": 7,
        "control": 7,
        "timing": 7,
        "exception": 7,
        "evidence": 7,
        "security": 7,
        "testing": 7,
        "operations": 7
      },
      "requirement_count": 84,
      "requirements": [
        {
          "code": "CIS-8.2-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "8.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Collect Audit Logs; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“日志采集”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-8.2-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "8.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 8.2, official Asset Class Data, Security Function Detect, and IG1 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 8.2、官方资产类别“数据”、安全功能“检测”和首次出现的 IG1，并保存来源抓取日期。"
        },
        {
          "code": "CIS-8.2-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "8.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Include every in-scope asset and control plane capable of security-relevant logging, with event sets defined by 8.1.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“包括所有能产生安全相关事件的在管资产和控制面，事件集由 8.1 规定。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-8.2-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "8.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-8.2-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "8.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Collect Audit Logs to its operating object—security-relevant events, actor and target identity, timestamps, decisions, outcomes, source health, retention, search, and custody—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“日志采集”连接到其运营对象——安全相关事件、行为者与目标身份、时间、决策、结果、来源健康、保留、检索和证据保管——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-8.2-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "8.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "For Collect Audit Logs, express success as an observable decision over complete, attributable, timely, protected, searchable, and actionable security telemetry plus source health; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“日志采集”，以 完整、可归因、及时、受保护、可检索、可行动的安全遥测及来源健康 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-8.2-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "8.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "For Collect Audit Logs, express success as an observable decision over coverage of every intended discovery vantage point, source, job, parser, and reconciliation path; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“日志采集”，以 所有预期发现视角、来源、任务、解析器和对账路径的覆盖 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-8.2-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "8.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-8.2-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "8.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-8.2-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "8.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-8.2-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "8.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-8.2-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "8.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across missing fields, clock drift, parser failure, dropped events, duplicate delivery, pooled identities, privacy redaction, provider gaps, quota, and archive unreadability; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 字段缺失、时钟漂移、解析失败、事件丢失、重复投递、汇聚身份、隐私脱敏、提供商缺口、配额和归档不可读 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-8.2-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "8.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Include clock skew, actor loss, field truncation, parser drift, dropped or duplicate events, privacy redaction, provider gaps, encrypted paths, quota, and archive failure in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 时钟偏移、行为者丢失、字段截断、解析漂移、事件丢失或重复、隐私脱敏、提供商缺口、加密路径、配额和归档故障 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-8.2-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "8.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Include unreachable zones, short-lived objects, blind spots, rate limits, credential failure, encrypted or proprietary protocols, and silent sensors in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 不可达区域、短生对象、盲区、限流、凭据失败、加密或专有协议和静默传感器 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-8.2-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "8.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-8.2-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "8.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-8.2-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "8.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-8.2-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "8.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-8.2-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "8.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind source owners, platform and security engineering, detection teams, incident responders, privacy, records management, and auditors to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 来源责任人、平台与安全工程、检测团队、事件响应、隐私、档案管理和审计方 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-8.2-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "8.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Name who may transition event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-8.2-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "8.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Name who may transition scheduled → started → observed → normalized → reconciled → dispositioned, with explicit partial and failed states, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 计划 → 启动 → 观测 → 归一化 → 对账 → 处置，并显式保留部分与失败状态，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-8.2-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "8.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-8.2-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "8.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-8.2-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "8.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV1, GV3, GV26, GV27, M1, M2, M3) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV1, GV3, GV26, GV27, M1, M2, M3）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-8.2-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "8.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-8.2-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "8.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the governed log-source inventory and evidence platform as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把受治理的日志源清单与证据平台作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-8.2-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "8.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired.",
          "zh": "对生命周期“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-8.2-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "8.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle scheduled → started → observed → normalized → reconciled → dispositioned, with explicit partial and failed states.",
          "zh": "对生命周期“计划 → 启动 → 观测 → 归一化 → 对账 → 处置，并显式保留部分与失败状态”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-8.2-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "8.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 1.1, Safeguard 4.1, Safeguard 8.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 1.1、Safeguard 4.1、Safeguard 8.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-8.2-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "8.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-8.2-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "8.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-8.2-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "8.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-8.2-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "8.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile endpoints, identity, applications, databases, network, cloud/SaaS, providers, collectors, archives, detections, and review records and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 终端、身份、应用、数据库、网络、云/SaaS、提供商、采集器、归档、检测和审阅记录，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-8.2-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "8.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Require every connector carrying complete, attributable, timely, protected, searchable, and actionable security telemetry plus source health to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 完整、可归因、及时、受保护、可检索、可行动的安全遥测及来源健康 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-8.2-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "8.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Require every connector carrying coverage of every intended discovery vantage point, source, job, parser, and reconciliation path to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 所有预期发现视角、来源、任务、解析器和对账路径的覆盖 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-8.2-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "8.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Configure source generation and reliable forwarding, buffer outages, authenticate transport, protect credentials and monitor heartbeat, lag, parse and drop.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“配置源端产生与可靠转发，故障时缓冲，认证传输，保护凭据并监测心跳、延迟、解析和丢弃；短命工作负载用镜像/策略即代码，托管服务用服务商 API，并分别指定源和管道责任人。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-8.2-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "8.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-8.2-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "8.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-8.2-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "8.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-8.2-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "8.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the governed log-source inventory and evidence platform and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在受治理的日志源清单与证据平台中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-8.2-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "8.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Implement the explicit state machine event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-8.2-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "8.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Implement the explicit state machine scheduled → started → observed → normalized → reconciled → dispositioned, with explicit partial and failed states; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“计划 → 启动 → 观测 → 归一化 → 对账 → 处置，并显式保留部分与失败状态”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-8.2-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "8.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-8.2-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "8.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-8.2-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "8.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-8.2-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "8.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-8.2-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "8.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in security-relevant events, actor and target identity, timestamps, decisions, outcomes, source health, retention, search, and custody; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 安全相关事件、行为者与目标身份、时间、决策、结果、来源健康、保留、检索和证据保管 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-8.2-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "8.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired; alert before each deadline becomes overdue.",
          "zh": "为“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-8.2-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "8.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for scheduled → started → observed → normalized → reconciled → dispositioned, with explicit partial and failed states; alert before each deadline becomes overdue.",
          "zh": "为“计划 → 启动 → 观测 → 归一化 → 对账 → 处置，并显式保留部分与失败状态”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-8.2-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "8.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “Devices may be online but legitimately quiet, so use synthetic heartbeats or configuration plus expected-event tests.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“设备在线却业务安静时，用合成心跳或配置加预期事件验证。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-8.2-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "8.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-8.2-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "8.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-8.2-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "8.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-8.2-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "8.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat missing fields, clock drift, parser failure, dropped events, duplicate delivery, pooled identities, privacy redaction, provider gaps, quota, and archive unreadability as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 字段缺失、时钟漂移、解析失败、事件丢失、重复投递、汇聚身份、隐私脱敏、提供商缺口、配额和归档不可读 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-8.2-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "8.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Treat clock skew, actor loss, field truncation, parser drift, dropped or duplicate events, privacy redaction, provider gaps, encrypted paths, quota, and archive failure as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 时钟偏移、行为者丢失、字段截断、解析漂移、事件丢失或重复、隐私脱敏、提供商缺口、加密路径、配额和归档故障 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-8.2-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "8.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Treat unreachable zones, short-lived objects, blind spots, rate limits, credential failure, encrypted or proprietary protocols, and silent sensors as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 不可达区域、短生对象、盲区、限流、凭据失败、加密或专有协议和静默传感器 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-8.2-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "8.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Generate an allowed and denied canary event on each source class and trace raw and normalized forms to the destination with correct identity/time.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“在每类源生成允许与拒绝金丝雀事件，追踪原始/归一形式和正确身份/时间；覆盖率以独立合格台账为分母，要求近期送达必需事件，另列静默、部分、延迟与解析失败。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-8.2-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "8.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-8.2-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "8.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 7 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、7 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-8.2-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "8.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-8.2-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "8.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the governed log-source inventory and evidence platform plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以受治理的日志源清单与证据平台和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-8.2-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "8.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Publish healthy, silent, partial, late, malformed, duplicate, unowned, unreviewed, alerted, investigated, and archived sources or events with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 健康、静默、部分、迟到、畸形、重复、无责任人、未审阅、已告警、已调查和已归档来源或事件，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-8.2-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "8.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Publish scheduled, successful, partial, failed, stale, blind, newly discovered, unmatched, and reconciled observations with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 计划、成功、部分、失败、陈旧、盲区、新发现、未匹配和已对账观测，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-8.2-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "8.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-8.2-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "8.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-8.2-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "8.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-8.2-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "8.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-8.2-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "8.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the governed log-source inventory and evidence platform; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护受治理的日志源清单与证据平台的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-8.2-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "8.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Restrict authority to change event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-8.2-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "8.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Restrict authority to change scheduled → started → observed → normalized → reconciled → dispositioned, with explicit partial and failed states; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“计划 → 启动 → 观测 → 归一化 → 对账 → 处置，并显式保留部分与失败状态”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-8.2-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "8.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-8.2-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "8.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-8.2-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "8.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-8.2-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "8.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-8.2-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "8.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise allowed and denied canary events, collector and parser failure, clock skew, retention boundary, archive restore, provider export loss, and analyst review through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 允许与拒绝的金丝雀事件、采集器与解析器故障、时钟偏移、保留边界、归档恢复、提供商导出丢失和分析员审阅，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-8.2-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "8.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Run the positive control an allowed and denied canary event traced from source through review; exercise negative, stale, duplicate, bypass, and outage controls including source loss, parser/schema change, time skew, queue overflow, duplicate delivery, provider export outage, missed alert, and unreadable archive.",
          "zh": "运行正向控制“一项允许与拒绝金丝雀事件从来源贯穿到审阅”，并执行包含“来源丢失、解析器/模式变化、时钟偏移、队列溢出、重复投递、提供商导出中断、漏报和归档不可读”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-8.2-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "8.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Run the positive control a known object visible from each representative vantage point; exercise negative, stale, duplicate, bypass, and outage controls including an unknown and short-lived object, failed credential, blocked scan, silent sensor, parser drift, and uncovered segment.",
          "zh": "运行正向控制“从每个代表性视角可见的一项已知对象”，并执行包含“未知与短生对象、凭据失败、扫描受阻、传感器静默、解析漂移和未覆盖网段”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-8.2-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "8.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-8.2-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "8.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-8.2-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "8.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-8.2-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "8.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-8.2-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "8.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever endpoints, identity, applications, databases, network, cloud/SaaS, providers, collectors, archives, detections, and review records change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 终端、身份、应用、数据库、网络、云/SaaS、提供商、采集器、归档、检测和审阅记录 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-8.2-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "8.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Use healthy, silent, partial, late, malformed, duplicate, unowned, unreviewed, alerted, investigated, and archived sources or events to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 健康、静默、部分、迟到、畸形、重复、无责任人、未审阅、已告警、已调查和已归档来源或事件 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-8.2-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "8.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Use scheduled, successful, partial, failed, stale, blind, newly discovered, unmatched, and reconciled observations to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 计划、成功、部分、失败、陈旧、盲区、新发现、未匹配和已对账观测 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "8.3",
      "control": 8,
      "title_en": "Ensure Adequate Audit Log Storage",
      "title_zh": "日志存储容量",
      "first_ig": 1,
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Data",
      "security_function": "Protect",
      "patterns": [
        "telemetry"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "1.1"
        ],
        "variables": [
          "GV26",
          "GV27",
          "M1",
          "M2",
          "M3"
        ],
        "metric_branches": 1,
        "has_assumptions": true,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "Capacity covers local buffers, collectors, queues, hot search, archive and restore paths needed to meet the log process under normal peaks and incident bursts.",
          "build": "Model volume by source and peak, reserve headroom, set priority and backpressure, alert on saturation/lag/drop, and budget immutable or protected tiers.",
          "proof": "Replay a controlled burst and collector outage, then verify buffering, no critical-event loss, recovery order and actual oldest searchable/restorable timestamp.",
          "boundary": "Compression and sampling affect evidentiary detail; define which events may be sampled."
        },
        "zh": {
          "scope": "容量覆盖为满足流程所需的本地缓冲、收集器、队列、热查询、归档和恢复路径，既考虑正常峰值也考虑事件爆发。",
          "build": "按来源/峰值建模，留余量，设优先级和背压，对饱和、积压、丢弃告警，并为不可变/受保护层预算。",
          "proof": "回放受控流量突发并中断收集器，验证缓冲、关键事件不丢、恢复顺序和实际最老可查/可恢复时间。",
          "boundary": "压缩与采样会改变证据细节，必须说明哪些可采样。"
        }
      },
      "category_counts": {
        "outcome": 6,
        "scope": 6,
        "ownership": 6,
        "data": 6,
        "integration": 6,
        "control": 6,
        "timing": 6,
        "exception": 6,
        "evidence": 6,
        "security": 6,
        "testing": 6,
        "operations": 6
      },
      "requirement_count": 72,
      "requirements": [
        {
          "code": "CIS-8.3-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "8.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Ensure Adequate Audit Log Storage; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“日志存储容量”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-8.3-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "8.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 8.3, official Asset Class Data, Security Function Protect, and IG1 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 8.3、官方资产类别“数据”、安全功能“保护”和首次出现的 IG1，并保存来源抓取日期。"
        },
        {
          "code": "CIS-8.3-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "8.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Capacity covers local buffers, collectors, queues, hot search, archive and restore paths needed to meet the log process under normal peaks and incident bursts.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“容量覆盖为满足流程所需的本地缓冲、收集器、队列、热查询、归档和恢复路径，既考虑正常峰值也考虑事件爆发。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-8.3-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "8.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-8.3-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "8.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Ensure Adequate Audit Log Storage to its operating object—security-relevant events, actor and target identity, timestamps, decisions, outcomes, source health, retention, search, and custody—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“日志存储容量”连接到其运营对象——安全相关事件、行为者与目标身份、时间、决策、结果、来源健康、保留、检索和证据保管——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-8.3-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "8.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "For Ensure Adequate Audit Log Storage, express success as an observable decision over complete, attributable, timely, protected, searchable, and actionable security telemetry plus source health; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“日志存储容量”，以 完整、可归因、及时、受保护、可检索、可行动的安全遥测及来源健康 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-8.3-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "8.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-8.3-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "8.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-8.3-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "8.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-8.3-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "8.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-8.3-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "8.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across missing fields, clock drift, parser failure, dropped events, duplicate delivery, pooled identities, privacy redaction, provider gaps, quota, and archive unreadability; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 字段缺失、时钟漂移、解析失败、事件丢失、重复投递、汇聚身份、隐私脱敏、提供商缺口、配额和归档不可读 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-8.3-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "8.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Include clock skew, actor loss, field truncation, parser drift, dropped or duplicate events, privacy redaction, provider gaps, encrypted paths, quota, and archive failure in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 时钟偏移、行为者丢失、字段截断、解析漂移、事件丢失或重复、隐私脱敏、提供商缺口、加密路径、配额和归档故障 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-8.3-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "8.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-8.3-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "8.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-8.3-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "8.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-8.3-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "8.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-8.3-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "8.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind source owners, platform and security engineering, detection teams, incident responders, privacy, records management, and auditors to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 来源责任人、平台与安全工程、检测团队、事件响应、隐私、档案管理和审计方 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-8.3-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "8.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Name who may transition event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-8.3-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "8.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-8.3-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "8.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-8.3-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "8.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV26, GV27, M1, M2, M3) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV26, GV27, M1, M2, M3）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-8.3-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "8.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-8.3-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "8.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the governed log-source inventory and evidence platform as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把受治理的日志源清单与证据平台作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-8.3-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "8.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired.",
          "zh": "对生命周期“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-8.3-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "8.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 1.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 1.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-8.3-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "8.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-8.3-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "8.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-8.3-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "8.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-8.3-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "8.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile endpoints, identity, applications, databases, network, cloud/SaaS, providers, collectors, archives, detections, and review records and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 终端、身份、应用、数据库、网络、云/SaaS、提供商、采集器、归档、检测和审阅记录，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-8.3-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "8.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Require every connector carrying complete, attributable, timely, protected, searchable, and actionable security telemetry plus source health to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 完整、可归因、及时、受保护、可检索、可行动的安全遥测及来源健康 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-8.3-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "8.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Model volume by source and peak, reserve headroom, set priority and backpressure, alert on saturation/lag/drop, and budget immutable or protected tiers.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“按来源/峰值建模，留余量，设优先级和背压，对饱和、积压、丢弃告警，并为不可变/受保护层预算。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-8.3-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "8.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-8.3-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "8.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-8.3-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "8.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-8.3-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "8.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the governed log-source inventory and evidence platform and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在受治理的日志源清单与证据平台中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-8.3-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "8.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Implement the explicit state machine event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-8.3-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "8.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-8.3-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "8.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-8.3-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "8.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-8.3-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "8.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-8.3-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "8.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in security-relevant events, actor and target identity, timestamps, decisions, outcomes, source health, retention, search, and custody; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 安全相关事件、行为者与目标身份、时间、决策、结果、来源健康、保留、检索和证据保管 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-8.3-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "8.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired; alert before each deadline becomes overdue.",
          "zh": "为“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-8.3-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "8.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “Compression and sampling affect evidentiary detail; define which events may be sampled.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“压缩与采样会改变证据细节，必须说明哪些可采样。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-8.3-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "8.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-8.3-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "8.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-8.3-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "8.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-8.3-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "8.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat missing fields, clock drift, parser failure, dropped events, duplicate delivery, pooled identities, privacy redaction, provider gaps, quota, and archive unreadability as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 字段缺失、时钟漂移、解析失败、事件丢失、重复投递、汇聚身份、隐私脱敏、提供商缺口、配额和归档不可读 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-8.3-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "8.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Treat clock skew, actor loss, field truncation, parser drift, dropped or duplicate events, privacy redaction, provider gaps, encrypted paths, quota, and archive failure as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 时钟偏移、行为者丢失、字段截断、解析漂移、事件丢失或重复、隐私脱敏、提供商缺口、加密路径、配额和归档故障 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-8.3-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "8.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Replay a controlled burst and collector outage, then verify buffering, no critical-event loss, recovery order and actual oldest searchable/restorable timestamp.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“回放受控流量突发并中断收集器，验证缓冲、关键事件不丢、恢复顺序和实际最老可查/可恢复时间。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-8.3-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "8.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-8.3-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "8.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 5 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、5 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-8.3-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "8.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-8.3-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "8.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the governed log-source inventory and evidence platform plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以受治理的日志源清单与证据平台和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-8.3-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "8.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Publish healthy, silent, partial, late, malformed, duplicate, unowned, unreviewed, alerted, investigated, and archived sources or events with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 健康、静默、部分、迟到、畸形、重复、无责任人、未审阅、已告警、已调查和已归档来源或事件，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-8.3-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "8.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-8.3-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "8.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-8.3-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "8.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-8.3-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "8.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-8.3-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "8.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the governed log-source inventory and evidence platform; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护受治理的日志源清单与证据平台的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-8.3-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "8.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Restrict authority to change event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-8.3-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "8.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-8.3-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "8.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-8.3-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "8.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-8.3-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "8.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-8.3-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "8.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise allowed and denied canary events, collector and parser failure, clock skew, retention boundary, archive restore, provider export loss, and analyst review through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 允许与拒绝的金丝雀事件、采集器与解析器故障、时钟偏移、保留边界、归档恢复、提供商导出丢失和分析员审阅，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-8.3-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "8.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Run the positive control an allowed and denied canary event traced from source through review; exercise negative, stale, duplicate, bypass, and outage controls including source loss, parser/schema change, time skew, queue overflow, duplicate delivery, provider export outage, missed alert, and unreadable archive.",
          "zh": "运行正向控制“一项允许与拒绝金丝雀事件从来源贯穿到审阅”，并执行包含“来源丢失、解析器/模式变化、时钟偏移、队列溢出、重复投递、提供商导出中断、漏报和归档不可读”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-8.3-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "8.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-8.3-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "8.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-8.3-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "8.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-8.3-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "8.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-8.3-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "8.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever endpoints, identity, applications, databases, network, cloud/SaaS, providers, collectors, archives, detections, and review records change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 终端、身份、应用、数据库、网络、云/SaaS、提供商、采集器、归档、检测和审阅记录 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-8.3-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "8.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Use healthy, silent, partial, late, malformed, duplicate, unowned, unreviewed, alerted, investigated, and archived sources or events to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 健康、静默、部分、迟到、畸形、重复、无责任人、未审阅、已告警、已调查和已归档来源或事件 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "8.4",
      "control": 8,
      "title_en": "Standardize Time Synchronization",
      "title_zh": "时间同步",
      "first_ig": 2,
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Data",
      "security_function": "Protect",
      "patterns": [
        "telemetry"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "1.1"
        ],
        "variables": [
          "GV27",
          "M1",
          "M2",
          "M3",
          "M4"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "Eligible logging and security assets should use at least two approved synchronized sources where supported, with a trusted hierarchy, authenticated time where risk warrants it and a defined tolerance.",
          "build": "Configure redundant sources centrally, prevent ordinary changes, monitor offset, source health and stratum, preserve time zone/UTC semantics, and define behavior during loss or malicious shifts.",
          "proof": "Measure actual offset and selected source, not only configuration.",
          "boundary": "Two configured sources are not independent if they share an upstream."
        },
        "zh": {
          "scope": "支持时，产生日志和安全事件的资产至少使用两个批准且同步的时间源，建立可信层级；高风险处需认证时间与误差阈值。",
          "build": "集中配置冗余来源，阻止普通人改时，监控偏移、源健康和层级，统一 UTC/时区语义，并定义时间源丢失或恶意跳变时的行为。",
          "proof": "测量实际偏移和当前选源，不只看配置。",
          "boundary": "两个配置源若共用同一上游就不独立。"
        }
      },
      "category_counts": {
        "outcome": 6,
        "scope": 6,
        "ownership": 6,
        "data": 6,
        "integration": 6,
        "control": 6,
        "timing": 6,
        "exception": 6,
        "evidence": 6,
        "security": 6,
        "testing": 6,
        "operations": 6
      },
      "requirement_count": 72,
      "requirements": [
        {
          "code": "CIS-8.4-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "8.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Standardize Time Synchronization; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“时间同步”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-8.4-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "8.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 8.4, official Asset Class Data, Security Function Protect, and IG2 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 8.4、官方资产类别“数据”、安全功能“保护”和首次出现的 IG2，并保存来源抓取日期。"
        },
        {
          "code": "CIS-8.4-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "8.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Eligible logging and security assets should use at least two approved synchronized sources where supported, with a trusted hierarchy, authenticated time where risk warrants it and a defined tolerance.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“支持时，产生日志和安全事件的资产至少使用两个批准且同步的时间源，建立可信层级；高风险处需认证时间与误差阈值。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-8.4-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "8.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-8.4-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "8.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Standardize Time Synchronization to its operating object—security-relevant events, actor and target identity, timestamps, decisions, outcomes, source health, retention, search, and custody—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“时间同步”连接到其运营对象——安全相关事件、行为者与目标身份、时间、决策、结果、来源健康、保留、检索和证据保管——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-8.4-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "8.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "For Standardize Time Synchronization, express success as an observable decision over complete, attributable, timely, protected, searchable, and actionable security telemetry plus source health; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“时间同步”，以 完整、可归因、及时、受保护、可检索、可行动的安全遥测及来源健康 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-8.4-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "8.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-8.4-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "8.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-8.4-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "8.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-8.4-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "8.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-8.4-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "8.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across missing fields, clock drift, parser failure, dropped events, duplicate delivery, pooled identities, privacy redaction, provider gaps, quota, and archive unreadability; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 字段缺失、时钟漂移、解析失败、事件丢失、重复投递、汇聚身份、隐私脱敏、提供商缺口、配额和归档不可读 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-8.4-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "8.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Include clock skew, actor loss, field truncation, parser drift, dropped or duplicate events, privacy redaction, provider gaps, encrypted paths, quota, and archive failure in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 时钟偏移、行为者丢失、字段截断、解析漂移、事件丢失或重复、隐私脱敏、提供商缺口、加密路径、配额和归档故障 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-8.4-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "8.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-8.4-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "8.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-8.4-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "8.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-8.4-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "8.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-8.4-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "8.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind source owners, platform and security engineering, detection teams, incident responders, privacy, records management, and auditors to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 来源责任人、平台与安全工程、检测团队、事件响应、隐私、档案管理和审计方 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-8.4-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "8.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Name who may transition event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-8.4-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "8.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-8.4-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "8.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-8.4-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "8.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV27, M1, M2, M3, M4) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV27, M1, M2, M3, M4）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-8.4-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "8.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-8.4-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "8.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the governed log-source inventory and evidence platform as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把受治理的日志源清单与证据平台作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-8.4-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "8.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired.",
          "zh": "对生命周期“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-8.4-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "8.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 1.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 1.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-8.4-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "8.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-8.4-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "8.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-8.4-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "8.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-8.4-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "8.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile endpoints, identity, applications, databases, network, cloud/SaaS, providers, collectors, archives, detections, and review records and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 终端、身份、应用、数据库、网络、云/SaaS、提供商、采集器、归档、检测和审阅记录，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-8.4-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "8.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Require every connector carrying complete, attributable, timely, protected, searchable, and actionable security telemetry plus source health to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 完整、可归因、及时、受保护、可检索、可行动的安全遥测及来源健康 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-8.4-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "8.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Configure redundant sources centrally, prevent ordinary changes, monitor offset, source health and stratum, preserve time zone/UTC semantics, and define behavior during loss or malicious shifts.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“集中配置冗余来源，阻止普通人改时，监控偏移、源健康和层级，统一 UTC/时区语义，并定义时间源丢失或恶意跳变时的行为。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-8.4-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "8.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-8.4-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "8.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-8.4-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "8.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-8.4-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "8.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the governed log-source inventory and evidence platform and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在受治理的日志源清单与证据平台中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-8.4-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "8.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Implement the explicit state machine event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-8.4-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "8.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-8.4-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "8.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-8.4-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "8.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-8.4-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "8.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-8.4-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "8.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in security-relevant events, actor and target identity, timestamps, decisions, outcomes, source health, retention, search, and custody; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 安全相关事件、行为者与目标身份、时间、决策、结果、来源健康、保留、检索和证据保管 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-8.4-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "8.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired; alert before each deadline becomes overdue.",
          "zh": "为“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-8.4-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "8.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “Two configured sources are not independent if they share an upstream.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“两个配置源若共用同一上游就不独立。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-8.4-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "8.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-8.4-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "8.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-8.4-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "8.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-8.4-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "8.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat missing fields, clock drift, parser failure, dropped events, duplicate delivery, pooled identities, privacy redaction, provider gaps, quota, and archive unreadability as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 字段缺失、时钟漂移、解析失败、事件丢失、重复投递、汇聚身份、隐私脱敏、提供商缺口、配额和归档不可读 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-8.4-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "8.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Treat clock skew, actor loss, field truncation, parser drift, dropped or duplicate events, privacy redaction, provider gaps, encrypted paths, quota, and archive failure as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 时钟偏移、行为者丢失、字段截断、解析漂移、事件丢失或重复、隐私脱敏、提供商缺口、加密路径、配额和归档故障 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-8.4-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "8.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Measure actual offset and selected source, not only configuration.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“测量实际偏移和当前选源，不只看配置。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-8.4-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "8.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-8.4-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "8.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 5 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、5 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-8.4-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "8.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-8.4-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "8.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the governed log-source inventory and evidence platform plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以受治理的日志源清单与证据平台和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-8.4-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "8.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Publish healthy, silent, partial, late, malformed, duplicate, unowned, unreviewed, alerted, investigated, and archived sources or events with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 健康、静默、部分、迟到、畸形、重复、无责任人、未审阅、已告警、已调查和已归档来源或事件，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-8.4-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "8.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-8.4-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "8.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-8.4-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "8.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-8.4-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "8.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-8.4-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "8.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the governed log-source inventory and evidence platform; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护受治理的日志源清单与证据平台的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-8.4-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "8.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Restrict authority to change event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-8.4-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "8.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-8.4-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "8.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-8.4-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "8.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-8.4-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "8.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-8.4-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "8.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise allowed and denied canary events, collector and parser failure, clock skew, retention boundary, archive restore, provider export loss, and analyst review through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 允许与拒绝的金丝雀事件、采集器与解析器故障、时钟偏移、保留边界、归档恢复、提供商导出丢失和分析员审阅，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-8.4-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "8.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Run the positive control an allowed and denied canary event traced from source through review; exercise negative, stale, duplicate, bypass, and outage controls including source loss, parser/schema change, time skew, queue overflow, duplicate delivery, provider export outage, missed alert, and unreadable archive.",
          "zh": "运行正向控制“一项允许与拒绝金丝雀事件从来源贯穿到审阅”，并执行包含“来源丢失、解析器/模式变化、时钟偏移、队列溢出、重复投递、提供商导出中断、漏报和归档不可读”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-8.4-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "8.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-8.4-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "8.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-8.4-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "8.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-8.4-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "8.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-8.4-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "8.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever endpoints, identity, applications, databases, network, cloud/SaaS, providers, collectors, archives, detections, and review records change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 终端、身份、应用、数据库、网络、云/SaaS、提供商、采集器、归档、检测和审阅记录 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-8.4-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "8.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Use healthy, silent, partial, late, malformed, duplicate, unowned, unreviewed, alerted, investigated, and archived sources or events to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 健康、静默、部分、迟到、畸形、重复、无责任人、未审阅、已告警、已调查和已归档来源或事件 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "8.5",
      "control": 8,
      "title_en": "Collect Detailed Audit Logs",
      "title_zh": "详细审计字段",
      "first_ig": 2,
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Data",
      "security_function": "Detect",
      "patterns": [
        "telemetry",
        "discovery"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "1.1"
        ],
        "variables": [
          "GV3",
          "GV18",
          "GV26",
          "GV27",
          "M1",
          "M2",
          "M3",
          "M4"
        ],
        "metric_branches": 2,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "Detailed logging applies to assets holding sensitive data and high-consequence control planes.",
          "build": "Define source-specific schemas and enable the most useful native/application events; preserve stable asset/account/data identities through normalization.",
          "proof": "Execute representative read, write, delete, permission and administrative actions plus denials, then verify every required field and correlation across layers.",
          "boundary": "Proxies, pooled connections and service accounts can replace the real actor; application context must restore it."
        },
        "zh": {
          "scope": "详细日志面向承载敏感数据的资产和高后果控制面；字段包括事件源、日期/时间、有效用户/工作负载、源/目的上下文、动作、对象和结果，必要时加交易/关联 ID。",
          "build": "按来源定义 Schema，启用最有用的原生/应用事件，归一时保留稳定资产、账户与数据身份；少记秘密/载荷，记录字段转换，对高敏/详细审计流做更严格访问控制。",
          "proof": "执行代表性的读写删、权限和管理动作及拒绝，核验每个字段与跨层关联。",
          "boundary": "代理、连接池和服务账户会替换真实行为人，需应用上下文恢复。"
        }
      },
      "category_counts": {
        "outcome": 7,
        "scope": 7,
        "ownership": 7,
        "data": 7,
        "integration": 7,
        "control": 7,
        "timing": 7,
        "exception": 7,
        "evidence": 7,
        "security": 7,
        "testing": 7,
        "operations": 7
      },
      "requirement_count": 84,
      "requirements": [
        {
          "code": "CIS-8.5-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "8.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Collect Detailed Audit Logs; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“详细审计字段”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-8.5-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "8.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 8.5, official Asset Class Data, Security Function Detect, and IG2 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 8.5、官方资产类别“数据”、安全功能“检测”和首次出现的 IG2，并保存来源抓取日期。"
        },
        {
          "code": "CIS-8.5-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "8.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Detailed logging applies to assets holding sensitive data and high-consequence control planes.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“详细日志面向承载敏感数据的资产和高后果控制面；字段包括事件源、日期/时间、有效用户/工作负载、源/目的上下文、动作、对象和结果，必要时加交易/关联 ID。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-8.5-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "8.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-8.5-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "8.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Collect Detailed Audit Logs to its operating object—security-relevant events, actor and target identity, timestamps, decisions, outcomes, source health, retention, search, and custody—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“详细审计字段”连接到其运营对象——安全相关事件、行为者与目标身份、时间、决策、结果、来源健康、保留、检索和证据保管——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-8.5-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "8.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "For Collect Detailed Audit Logs, express success as an observable decision over complete, attributable, timely, protected, searchable, and actionable security telemetry plus source health; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“详细审计字段”，以 完整、可归因、及时、受保护、可检索、可行动的安全遥测及来源健康 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-8.5-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "8.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "For Collect Detailed Audit Logs, express success as an observable decision over coverage of every intended discovery vantage point, source, job, parser, and reconciliation path; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“详细审计字段”，以 所有预期发现视角、来源、任务、解析器和对账路径的覆盖 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-8.5-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "8.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-8.5-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "8.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-8.5-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "8.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-8.5-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "8.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-8.5-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "8.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across missing fields, clock drift, parser failure, dropped events, duplicate delivery, pooled identities, privacy redaction, provider gaps, quota, and archive unreadability; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 字段缺失、时钟漂移、解析失败、事件丢失、重复投递、汇聚身份、隐私脱敏、提供商缺口、配额和归档不可读 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-8.5-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "8.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Include clock skew, actor loss, field truncation, parser drift, dropped or duplicate events, privacy redaction, provider gaps, encrypted paths, quota, and archive failure in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 时钟偏移、行为者丢失、字段截断、解析漂移、事件丢失或重复、隐私脱敏、提供商缺口、加密路径、配额和归档故障 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-8.5-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "8.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Include unreachable zones, short-lived objects, blind spots, rate limits, credential failure, encrypted or proprietary protocols, and silent sensors in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 不可达区域、短生对象、盲区、限流、凭据失败、加密或专有协议和静默传感器 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-8.5-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "8.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-8.5-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "8.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-8.5-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "8.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-8.5-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "8.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-8.5-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "8.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind source owners, platform and security engineering, detection teams, incident responders, privacy, records management, and auditors to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 来源责任人、平台与安全工程、检测团队、事件响应、隐私、档案管理和审计方 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-8.5-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "8.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Name who may transition event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-8.5-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "8.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Name who may transition scheduled → started → observed → normalized → reconciled → dispositioned, with explicit partial and failed states, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 计划 → 启动 → 观测 → 归一化 → 对账 → 处置，并显式保留部分与失败状态，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-8.5-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "8.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-8.5-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "8.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-8.5-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "8.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV3, GV18, GV26, GV27, M1, M2, M3, M4) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV3, GV18, GV26, GV27, M1, M2, M3, M4）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-8.5-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "8.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-8.5-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "8.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the governed log-source inventory and evidence platform as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把受治理的日志源清单与证据平台作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-8.5-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "8.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired.",
          "zh": "对生命周期“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-8.5-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "8.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle scheduled → started → observed → normalized → reconciled → dispositioned, with explicit partial and failed states.",
          "zh": "对生命周期“计划 → 启动 → 观测 → 归一化 → 对账 → 处置，并显式保留部分与失败状态”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-8.5-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "8.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 1.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 1.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-8.5-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "8.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-8.5-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "8.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-8.5-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "8.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-8.5-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "8.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile endpoints, identity, applications, databases, network, cloud/SaaS, providers, collectors, archives, detections, and review records and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 终端、身份、应用、数据库、网络、云/SaaS、提供商、采集器、归档、检测和审阅记录，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-8.5-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "8.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Require every connector carrying complete, attributable, timely, protected, searchable, and actionable security telemetry plus source health to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 完整、可归因、及时、受保护、可检索、可行动的安全遥测及来源健康 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-8.5-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "8.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Require every connector carrying coverage of every intended discovery vantage point, source, job, parser, and reconciliation path to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 所有预期发现视角、来源、任务、解析器和对账路径的覆盖 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-8.5-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "8.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Define source-specific schemas and enable the most useful native/application events; preserve stable asset/account/data identities through normalization.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“按来源定义 Schema，启用最有用的原生/应用事件，归一时保留稳定资产、账户与数据身份；少记秘密/载荷，记录字段转换，对高敏/详细审计流做更严格访问控制。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-8.5-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "8.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-8.5-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "8.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-8.5-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "8.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-8.5-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "8.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the governed log-source inventory and evidence platform and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在受治理的日志源清单与证据平台中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-8.5-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "8.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Implement the explicit state machine event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-8.5-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "8.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Implement the explicit state machine scheduled → started → observed → normalized → reconciled → dispositioned, with explicit partial and failed states; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“计划 → 启动 → 观测 → 归一化 → 对账 → 处置，并显式保留部分与失败状态”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-8.5-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "8.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-8.5-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "8.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-8.5-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "8.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-8.5-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "8.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-8.5-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "8.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in security-relevant events, actor and target identity, timestamps, decisions, outcomes, source health, retention, search, and custody; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 安全相关事件、行为者与目标身份、时间、决策、结果、来源健康、保留、检索和证据保管 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-8.5-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "8.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired; alert before each deadline becomes overdue.",
          "zh": "为“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-8.5-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "8.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for scheduled → started → observed → normalized → reconciled → dispositioned, with explicit partial and failed states; alert before each deadline becomes overdue.",
          "zh": "为“计划 → 启动 → 观测 → 归一化 → 对账 → 处置，并显式保留部分与失败状态”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-8.5-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "8.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “Proxies, pooled connections and service accounts can replace the real actor; application context must restore it.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“代理、连接池和服务账户会替换真实行为人，需应用上下文恢复。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-8.5-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "8.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-8.5-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "8.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-8.5-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "8.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-8.5-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "8.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat missing fields, clock drift, parser failure, dropped events, duplicate delivery, pooled identities, privacy redaction, provider gaps, quota, and archive unreadability as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 字段缺失、时钟漂移、解析失败、事件丢失、重复投递、汇聚身份、隐私脱敏、提供商缺口、配额和归档不可读 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-8.5-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "8.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Treat clock skew, actor loss, field truncation, parser drift, dropped or duplicate events, privacy redaction, provider gaps, encrypted paths, quota, and archive failure as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 时钟偏移、行为者丢失、字段截断、解析漂移、事件丢失或重复、隐私脱敏、提供商缺口、加密路径、配额和归档故障 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-8.5-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "8.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Treat unreachable zones, short-lived objects, blind spots, rate limits, credential failure, encrypted or proprietary protocols, and silent sensors as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 不可达区域、短生对象、盲区、限流、凭据失败、加密或专有协议和静默传感器 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-8.5-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "8.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Execute representative read, write, delete, permission and administrative actions plus denials, then verify every required field and correlation across layers.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“执行代表性的读写删、权限和管理动作及拒绝，核验每个字段与跨层关联。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-8.5-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "8.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-8.5-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "8.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 2 pinned CAS metric branch(es), 8 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 2 个指标分支、8 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-8.5-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "8.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-8.5-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "8.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the governed log-source inventory and evidence platform plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以受治理的日志源清单与证据平台和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-8.5-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "8.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Publish healthy, silent, partial, late, malformed, duplicate, unowned, unreviewed, alerted, investigated, and archived sources or events with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 健康、静默、部分、迟到、畸形、重复、无责任人、未审阅、已告警、已调查和已归档来源或事件，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-8.5-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "8.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Publish scheduled, successful, partial, failed, stale, blind, newly discovered, unmatched, and reconciled observations with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 计划、成功、部分、失败、陈旧、盲区、新发现、未匹配和已对账观测，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-8.5-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "8.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-8.5-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "8.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-8.5-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "8.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-8.5-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "8.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-8.5-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "8.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the governed log-source inventory and evidence platform; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护受治理的日志源清单与证据平台的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-8.5-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "8.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Restrict authority to change event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-8.5-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "8.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Restrict authority to change scheduled → started → observed → normalized → reconciled → dispositioned, with explicit partial and failed states; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“计划 → 启动 → 观测 → 归一化 → 对账 → 处置，并显式保留部分与失败状态”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-8.5-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "8.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-8.5-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "8.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-8.5-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "8.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-8.5-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "8.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-8.5-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "8.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise allowed and denied canary events, collector and parser failure, clock skew, retention boundary, archive restore, provider export loss, and analyst review through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 允许与拒绝的金丝雀事件、采集器与解析器故障、时钟偏移、保留边界、归档恢复、提供商导出丢失和分析员审阅，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-8.5-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "8.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Run the positive control an allowed and denied canary event traced from source through review; exercise negative, stale, duplicate, bypass, and outage controls including source loss, parser/schema change, time skew, queue overflow, duplicate delivery, provider export outage, missed alert, and unreadable archive.",
          "zh": "运行正向控制“一项允许与拒绝金丝雀事件从来源贯穿到审阅”，并执行包含“来源丢失、解析器/模式变化、时钟偏移、队列溢出、重复投递、提供商导出中断、漏报和归档不可读”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-8.5-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "8.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Run the positive control a known object visible from each representative vantage point; exercise negative, stale, duplicate, bypass, and outage controls including an unknown and short-lived object, failed credential, blocked scan, silent sensor, parser drift, and uncovered segment.",
          "zh": "运行正向控制“从每个代表性视角可见的一项已知对象”，并执行包含“未知与短生对象、凭据失败、扫描受阻、传感器静默、解析漂移和未覆盖网段”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-8.5-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "8.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-8.5-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "8.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-8.5-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "8.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-8.5-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "8.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-8.5-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "8.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever endpoints, identity, applications, databases, network, cloud/SaaS, providers, collectors, archives, detections, and review records change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 终端、身份、应用、数据库、网络、云/SaaS、提供商、采集器、归档、检测和审阅记录 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-8.5-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "8.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Use healthy, silent, partial, late, malformed, duplicate, unowned, unreviewed, alerted, investigated, and archived sources or events to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 健康、静默、部分、迟到、畸形、重复、无责任人、未审阅、已告警、已调查和已归档来源或事件 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-8.5-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "8.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Use scheduled, successful, partial, failed, stale, blind, newly discovered, unmatched, and reconciled observations to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 计划、成功、部分、失败、陈旧、盲区、新发现、未匹配和已对账观测 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "8.6",
      "control": 8,
      "title_en": "Collect DNS Query Audit Logs",
      "title_zh": "DNS 查询日志",
      "first_ig": 2,
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Data",
      "security_function": "Detect",
      "patterns": [
        "telemetry",
        "discovery",
        "network"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "1.1",
          "4.1"
        ],
        "variables": [
          "GV1",
          "GV3",
          "M1",
          "M2",
          "M3"
        ],
        "metric_branches": 1,
        "has_assumptions": true,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "Capture enterprise DNS decisions at internal, endpoint, cloud, mobile and approved external resolvers where appropriate, including query, type, response, client or identity context, policy action, resolver and time.",
          "build": "Enable logs at controlled resolvers and endpoint agents where source identity is otherwise lost, centralize them, govern retention/privacy and monitor encrypted-DNS bypass.",
          "proof": "Resolve benign, blocked, nonexistent and direct/encrypted test domains from representative networks and devices; trace client, query, answer/action and time end to end.",
          "boundary": "The CAS assumes the enterprise runs internal DNS, excluding outsourced and endpoint models."
        },
        "zh": {
          "scope": "采集企业内网、终端、云、移动和批准外部递归解析器的 DNS 决定，视情况包含查询、类型、回答、客户端/身份、策略动作、解析器和时间；权威 DNS 与递归客户端日志回答不同问题。",
          "build": "在受控解析器启用日志，若 NAT 遮住来源则补终端 Agent，集中化并治理保留/隐私，监测加密 DNS 绕过；外包 DNS 要配置租户导出/API，并对账漫游设备和 Split DNS。",
          "proof": "从代表网络/设备解析正常、被拦、NXDOMAIN 和直连/加密测试域，追踪客户端、查询、回答/动作和时间；把端点观测与解析器日志对比，找缓存、NAT 和旁路。",
          "boundary": "CAS 假设企业自建内网 DNS，漏掉外包和端点模型。"
        }
      },
      "category_counts": {
        "outcome": 8,
        "scope": 8,
        "ownership": 8,
        "data": 8,
        "integration": 8,
        "control": 8,
        "timing": 8,
        "exception": 8,
        "evidence": 8,
        "security": 8,
        "testing": 8,
        "operations": 8
      },
      "requirement_count": 96,
      "requirements": [
        {
          "code": "CIS-8.6-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "8.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Collect DNS Query Audit Logs; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“DNS 查询日志”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-8.6-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "8.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 8.6, official Asset Class Data, Security Function Detect, and IG2 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 8.6、官方资产类别“数据”、安全功能“检测”和首次出现的 IG2，并保存来源抓取日期。"
        },
        {
          "code": "CIS-8.6-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "8.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Capture enterprise DNS decisions at internal, endpoint, cloud, mobile and approved external resolvers where appropriate, including query, type, response, client or identity context, policy action, resolver and time.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“采集企业内网、终端、云、移动和批准外部递归解析器的 DNS 决定，视情况包含查询、类型、回答、客户端/身份、策略动作、解析器和时间；权威 DNS 与递归客户端日志回答不同问题。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-8.6-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "8.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-8.6-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "8.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Collect DNS Query Audit Logs to its operating object—security-relevant events, actor and target identity, timestamps, decisions, outcomes, source health, retention, search, and custody—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“DNS 查询日志”连接到其运营对象——安全相关事件、行为者与目标身份、时间、决策、结果、来源健康、保留、检索和证据保管——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-8.6-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "8.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "For Collect DNS Query Audit Logs, express success as an observable decision over complete, attributable, timely, protected, searchable, and actionable security telemetry plus source health; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“DNS 查询日志”，以 完整、可归因、及时、受保护、可检索、可行动的安全遥测及来源健康 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-8.6-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "8.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "For Collect DNS Query Audit Logs, express success as an observable decision over coverage of every intended discovery vantage point, source, job, parser, and reconciliation path; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“DNS 查询日志”，以 所有预期发现视角、来源、任务、解析器和对账路径的覆盖 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-8.6-OUT-08",
          "local_code": "OUT-08",
          "display_code": "O08",
          "safeguard_id": "8.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "For Collect DNS Query Audit Logs, express success as an observable decision over intended connectivity, trust zone, route, protocol, identity, management path, traffic decision, and observed outcome; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“DNS 查询日志”，以 预期连接、信任区、路由、协议、身份、管理路径、流量决策和观察结果 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-8.6-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "8.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-8.6-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "8.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-8.6-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "8.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-8.6-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "8.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-8.6-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "8.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across missing fields, clock drift, parser failure, dropped events, duplicate delivery, pooled identities, privacy redaction, provider gaps, quota, and archive unreadability; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 字段缺失、时钟漂移、解析失败、事件丢失、重复投递、汇聚身份、隐私脱敏、提供商缺口、配额和归档不可读 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-8.6-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "8.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Include clock skew, actor loss, field truncation, parser drift, dropped or duplicate events, privacy redaction, provider gaps, encrypted paths, quota, and archive failure in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 时钟偏移、行为者丢失、字段截断、解析漂移、事件丢失或重复、隐私脱敏、提供商缺口、加密路径、配额和归档故障 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-8.6-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "8.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Include unreachable zones, short-lived objects, blind spots, rate limits, credential failure, encrypted or proprietary protocols, and silent sensors in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 不可达区域、短生对象、盲区、限流、凭据失败、加密或专有协议和静默传感器 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-8.6-SCP-08",
          "local_code": "SCP-08",
          "display_code": "P08",
          "safeguard_id": "8.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Include IPv6, overlays, east-west paths, remote and roaming devices, direct egress, alternate resolvers, QUIC, asymmetric routes, provider abstraction, and emergency consoles in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 IPv6、覆盖网络、东西向路径、远程与漫游设备、直接出口、替代解析器、QUIC、非对称路由、提供商抽象和紧急控制台 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-8.6-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "8.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-8.6-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "8.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-8.6-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "8.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-8.6-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "8.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-8.6-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "8.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind source owners, platform and security engineering, detection teams, incident responders, privacy, records management, and auditors to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 来源责任人、平台与安全工程、检测团队、事件响应、隐私、档案管理和审计方 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-8.6-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "8.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Name who may transition event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-8.6-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "8.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Name who may transition scheduled → started → observed → normalized → reconciled → dispositioned, with explicit partial and failed states, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 计划 → 启动 → 观测 → 归一化 → 对账 → 处置，并显式保留部分与失败状态，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-8.6-OWN-08",
          "local_code": "OWN-08",
          "display_code": "W08",
          "safeguard_id": "8.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Name who may transition requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-8.6-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "8.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-8.6-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "8.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-8.6-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "8.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV1, GV3, M1, M2, M3) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV1, GV3, M1, M2, M3）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-8.6-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "8.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-8.6-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "8.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the governed log-source inventory and evidence platform as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把受治理的日志源清单与证据平台作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-8.6-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "8.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired.",
          "zh": "对生命周期“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-8.6-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "8.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle scheduled → started → observed → normalized → reconciled → dispositioned, with explicit partial and failed states.",
          "zh": "对生命周期“计划 → 启动 → 观测 → 归一化 → 对账 → 处置，并显式保留部分与失败状态”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-8.6-DAT-08",
          "local_code": "DAT-08",
          "display_code": "D08",
          "safeguard_id": "8.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired.",
          "zh": "对生命周期“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-8.6-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "8.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 1.1, Safeguard 4.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 1.1、Safeguard 4.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-8.6-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "8.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-8.6-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "8.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-8.6-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "8.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-8.6-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "8.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile endpoints, identity, applications, databases, network, cloud/SaaS, providers, collectors, archives, detections, and review records and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 终端、身份、应用、数据库、网络、云/SaaS、提供商、采集器、归档、检测和审阅记录，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-8.6-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "8.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Require every connector carrying complete, attributable, timely, protected, searchable, and actionable security telemetry plus source health to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 完整、可归因、及时、受保护、可检索、可行动的安全遥测及来源健康 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-8.6-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "8.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Require every connector carrying coverage of every intended discovery vantage point, source, job, parser, and reconciliation path to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 所有预期发现视角、来源、任务、解析器和对账路径的覆盖 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-8.6-INT-08",
          "local_code": "INT-08",
          "display_code": "I08",
          "safeguard_id": "8.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Require every connector carrying intended connectivity, trust zone, route, protocol, identity, management path, traffic decision, and observed outcome to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 预期连接、信任区、路由、协议、身份、管理路径、流量决策和观察结果 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-8.6-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "8.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Enable logs at controlled resolvers and endpoint agents where source identity is otherwise lost, centralize them, govern retention/privacy and monitor encrypted-DNS bypass.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“在受控解析器启用日志，若 NAT 遮住来源则补终端 Agent，集中化并治理保留/隐私，监测加密 DNS 绕过；外包 DNS 要配置租户导出/API，并对账漫游设备和 Split DNS。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-8.6-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "8.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-8.6-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "8.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-8.6-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "8.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-8.6-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "8.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the governed log-source inventory and evidence platform and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在受治理的日志源清单与证据平台中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-8.6-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "8.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Implement the explicit state machine event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-8.6-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "8.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Implement the explicit state machine scheduled → started → observed → normalized → reconciled → dispositioned, with explicit partial and failed states; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“计划 → 启动 → 观测 → 归一化 → 对账 → 处置，并显式保留部分与失败状态”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-8.6-CTL-08",
          "local_code": "CTL-08",
          "display_code": "C08",
          "safeguard_id": "8.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Implement the explicit state machine requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-8.6-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "8.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-8.6-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "8.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-8.6-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "8.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-8.6-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "8.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-8.6-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "8.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in security-relevant events, actor and target identity, timestamps, decisions, outcomes, source health, retention, search, and custody; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 安全相关事件、行为者与目标身份、时间、决策、结果、来源健康、保留、检索和证据保管 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-8.6-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "8.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired; alert before each deadline becomes overdue.",
          "zh": "为“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-8.6-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "8.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for scheduled → started → observed → normalized → reconciled → dispositioned, with explicit partial and failed states; alert before each deadline becomes overdue.",
          "zh": "为“计划 → 启动 → 观测 → 归一化 → 对账 → 处置，并显式保留部分与失败状态”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-8.6-TIM-08",
          "local_code": "TIM-08",
          "display_code": "T08",
          "safeguard_id": "8.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; alert before each deadline becomes overdue.",
          "zh": "为“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-8.6-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "8.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “The CAS assumes the enterprise runs internal DNS, excluding outsourced and endpoint models.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“CAS 假设企业自建内网 DNS，漏掉外包和端点模型。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-8.6-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "8.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-8.6-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "8.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-8.6-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "8.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-8.6-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "8.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat missing fields, clock drift, parser failure, dropped events, duplicate delivery, pooled identities, privacy redaction, provider gaps, quota, and archive unreadability as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 字段缺失、时钟漂移、解析失败、事件丢失、重复投递、汇聚身份、隐私脱敏、提供商缺口、配额和归档不可读 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-8.6-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "8.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Treat clock skew, actor loss, field truncation, parser drift, dropped or duplicate events, privacy redaction, provider gaps, encrypted paths, quota, and archive failure as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 时钟偏移、行为者丢失、字段截断、解析漂移、事件丢失或重复、隐私脱敏、提供商缺口、加密路径、配额和归档故障 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-8.6-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "8.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Treat unreachable zones, short-lived objects, blind spots, rate limits, credential failure, encrypted or proprietary protocols, and silent sensors as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 不可达区域、短生对象、盲区、限流、凭据失败、加密或专有协议和静默传感器 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-8.6-EXC-08",
          "local_code": "EXC-08",
          "display_code": "X08",
          "safeguard_id": "8.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Treat IPv6, overlays, east-west paths, remote and roaming devices, direct egress, alternate resolvers, QUIC, asymmetric routes, provider abstraction, and emergency consoles as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 IPv6、覆盖网络、东西向路径、远程与漫游设备、直接出口、替代解析器、QUIC、非对称路由、提供商抽象和紧急控制台 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-8.6-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "8.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Resolve benign, blocked, nonexistent and direct/encrypted test domains from representative networks and devices; trace client, query, answer/action and time end to end.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“从代表网络/设备解析正常、被拦、NXDOMAIN 和直连/加密测试域，追踪客户端、查询、回答/动作和时间；把端点观测与解析器日志对比，找缓存、NAT 和旁路。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-8.6-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "8.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-8.6-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "8.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 5 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、5 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-8.6-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "8.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-8.6-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "8.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the governed log-source inventory and evidence platform plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以受治理的日志源清单与证据平台和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-8.6-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "8.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Publish healthy, silent, partial, late, malformed, duplicate, unowned, unreviewed, alerted, investigated, and archived sources or events with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 健康、静默、部分、迟到、畸形、重复、无责任人、未审阅、已告警、已调查和已归档来源或事件，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-8.6-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "8.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Publish scheduled, successful, partial, failed, stale, blind, newly discovered, unmatched, and reconciled observations with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 计划、成功、部分、失败、陈旧、盲区、新发现、未匹配和已对账观测，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-8.6-EVD-08",
          "local_code": "EVD-08",
          "display_code": "E08",
          "safeguard_id": "8.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Publish known, unknown, allowed, denied, shadow, bypassed, asymmetric, stale-rule, exception, and unobserved paths with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已知、未知、允许、拒绝、影子、绕过、非对称、陈旧规则、例外和未观测路径，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-8.6-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "8.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-8.6-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "8.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-8.6-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "8.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-8.6-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "8.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-8.6-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "8.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the governed log-source inventory and evidence platform; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护受治理的日志源清单与证据平台的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-8.6-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "8.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Restrict authority to change event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-8.6-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "8.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Restrict authority to change scheduled → started → observed → normalized → reconciled → dispositioned, with explicit partial and failed states; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“计划 → 启动 → 观测 → 归一化 → 对账 → 处置，并显式保留部分与失败状态”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-8.6-SEC-08",
          "local_code": "SEC-08",
          "display_code": "S08",
          "safeguard_id": "8.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Restrict authority to change requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-8.6-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "8.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-8.6-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "8.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-8.6-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "8.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-8.6-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "8.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-8.6-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "8.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise allowed and denied canary events, collector and parser failure, clock skew, retention boundary, archive restore, provider export loss, and analyst review through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 允许与拒绝的金丝雀事件、采集器与解析器故障、时钟偏移、保留边界、归档恢复、提供商导出丢失和分析员审阅，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-8.6-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "8.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Run the positive control an allowed and denied canary event traced from source through review; exercise negative, stale, duplicate, bypass, and outage controls including source loss, parser/schema change, time skew, queue overflow, duplicate delivery, provider export outage, missed alert, and unreadable archive.",
          "zh": "运行正向控制“一项允许与拒绝金丝雀事件从来源贯穿到审阅”，并执行包含“来源丢失、解析器/模式变化、时钟偏移、队列溢出、重复投递、提供商导出中断、漏报和归档不可读”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-8.6-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "8.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Run the positive control a known object visible from each representative vantage point; exercise negative, stale, duplicate, bypass, and outage controls including an unknown and short-lived object, failed credential, blocked scan, silent sensor, parser drift, and uncovered segment.",
          "zh": "运行正向控制“从每个代表性视角可见的一项已知对象”，并执行包含“未知与短生对象、凭据失败、扫描受阻、传感器静默、解析漂移和未覆盖网段”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-8.6-TST-08",
          "local_code": "TST-08",
          "display_code": "V08",
          "safeguard_id": "8.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Run the positive control an approved flow over the required secure management or business path; exercise negative, stale, duplicate, bypass, and outage controls including an unapproved route, protocol downgrade, direct egress, alternate DNS/QUIC path, segmentation bypass, AAA loss, stale rule, and rollback failure.",
          "zh": "运行正向控制“通过规定安全管理或业务路径的一项获批流量”，并执行包含“未批准路由、协议降级、直接出口、替代 DNS/QUIC 路径、分段绕过、AAA 丢失、陈旧规则和回滚失败”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-8.6-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "8.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-8.6-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "8.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-8.6-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "8.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-8.6-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "8.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-8.6-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "8.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever endpoints, identity, applications, databases, network, cloud/SaaS, providers, collectors, archives, detections, and review records change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 终端、身份、应用、数据库、网络、云/SaaS、提供商、采集器、归档、检测和审阅记录 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-8.6-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "8.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Use healthy, silent, partial, late, malformed, duplicate, unowned, unreviewed, alerted, investigated, and archived sources or events to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 健康、静默、部分、迟到、畸形、重复、无责任人、未审阅、已告警、已调查和已归档来源或事件 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-8.6-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "8.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Use scheduled, successful, partial, failed, stale, blind, newly discovered, unmatched, and reconciled observations to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 计划、成功、部分、失败、陈旧、盲区、新发现、未匹配和已对账观测 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-8.6-OPS-08",
          "local_code": "OPS-08",
          "display_code": "R08",
          "safeguard_id": "8.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Use known, unknown, allowed, denied, shadow, bypassed, asymmetric, stale-rule, exception, and unobserved paths to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已知、未知、允许、拒绝、影子、绕过、非对称、陈旧规则、例外和未观测路径 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "8.7",
      "control": 8,
      "title_en": "Collect URL Request Audit Logs",
      "title_zh": "URL 请求日志",
      "first_ig": 2,
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Data",
      "security_function": "Detect",
      "patterns": [
        "telemetry",
        "discovery",
        "network"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "1.1",
          "4.1"
        ],
        "variables": [
          "GV1",
          "GV3",
          "M1",
          "M2",
          "M3"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "Scope web and API requests visible at secure web gateways, proxies, endpoints, browsers, DNS/security services and applications, including remote and cloud paths.",
          "build": "Collect at the control point that can lawfully see the needed fields, bind user/device/session, centralize and redact secrets, tokens, health data and other unnecessary query content.",
          "proof": "Request benign, blocked, redirected and encoded test URLs from managed and remote devices and verify identity, destination, action, time and correlation.",
          "boundary": "TLS, certificate pinning, privacy relays and end-to-end applications limit path visibility."
        },
        "zh": {
          "scope": "覆盖代理、安全 Web 网关、终端、浏览器、DNS/安全服务和应用可见的 Web/API 请求，包括远程与云路径。",
          "build": "在合法且能看到所需字段的控制点采集，绑定用户/设备/会话，集中化并脱敏秘密、Token、健康信息等查询内容；监测客户端旁路和服务商导出，在不经代理时用终端遥测补足。",
          "proof": "从受管/远程设备请求正常、被拦、重定向和编码 URL，核验身份、目的、动作、时间和关联；再测 QUIC、直连 IP、替代浏览器与 VPN。",
          "boundary": "TLS、证书 Pin、隐私 Relay 和端到端应用限制路径可见性。"
        }
      },
      "category_counts": {
        "outcome": 8,
        "scope": 8,
        "ownership": 8,
        "data": 8,
        "integration": 8,
        "control": 8,
        "timing": 8,
        "exception": 8,
        "evidence": 8,
        "security": 8,
        "testing": 8,
        "operations": 8
      },
      "requirement_count": 96,
      "requirements": [
        {
          "code": "CIS-8.7-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "8.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Collect URL Request Audit Logs; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“URL 请求日志”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-8.7-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "8.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 8.7, official Asset Class Data, Security Function Detect, and IG2 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 8.7、官方资产类别“数据”、安全功能“检测”和首次出现的 IG2，并保存来源抓取日期。"
        },
        {
          "code": "CIS-8.7-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "8.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Scope web and API requests visible at secure web gateways, proxies, endpoints, browsers, DNS/security services and applications, including remote and cloud paths.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“覆盖代理、安全 Web 网关、终端、浏览器、DNS/安全服务和应用可见的 Web/API 请求，包括远程与云路径。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-8.7-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "8.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-8.7-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "8.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Collect URL Request Audit Logs to its operating object—security-relevant events, actor and target identity, timestamps, decisions, outcomes, source health, retention, search, and custody—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“URL 请求日志”连接到其运营对象——安全相关事件、行为者与目标身份、时间、决策、结果、来源健康、保留、检索和证据保管——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-8.7-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "8.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "For Collect URL Request Audit Logs, express success as an observable decision over complete, attributable, timely, protected, searchable, and actionable security telemetry plus source health; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“URL 请求日志”，以 完整、可归因、及时、受保护、可检索、可行动的安全遥测及来源健康 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-8.7-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "8.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "For Collect URL Request Audit Logs, express success as an observable decision over coverage of every intended discovery vantage point, source, job, parser, and reconciliation path; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“URL 请求日志”，以 所有预期发现视角、来源、任务、解析器和对账路径的覆盖 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-8.7-OUT-08",
          "local_code": "OUT-08",
          "display_code": "O08",
          "safeguard_id": "8.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "For Collect URL Request Audit Logs, express success as an observable decision over intended connectivity, trust zone, route, protocol, identity, management path, traffic decision, and observed outcome; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“URL 请求日志”，以 预期连接、信任区、路由、协议、身份、管理路径、流量决策和观察结果 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-8.7-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "8.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-8.7-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "8.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-8.7-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "8.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-8.7-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "8.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-8.7-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "8.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across missing fields, clock drift, parser failure, dropped events, duplicate delivery, pooled identities, privacy redaction, provider gaps, quota, and archive unreadability; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 字段缺失、时钟漂移、解析失败、事件丢失、重复投递、汇聚身份、隐私脱敏、提供商缺口、配额和归档不可读 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-8.7-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "8.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Include clock skew, actor loss, field truncation, parser drift, dropped or duplicate events, privacy redaction, provider gaps, encrypted paths, quota, and archive failure in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 时钟偏移、行为者丢失、字段截断、解析漂移、事件丢失或重复、隐私脱敏、提供商缺口、加密路径、配额和归档故障 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-8.7-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "8.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Include unreachable zones, short-lived objects, blind spots, rate limits, credential failure, encrypted or proprietary protocols, and silent sensors in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 不可达区域、短生对象、盲区、限流、凭据失败、加密或专有协议和静默传感器 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-8.7-SCP-08",
          "local_code": "SCP-08",
          "display_code": "P08",
          "safeguard_id": "8.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Include IPv6, overlays, east-west paths, remote and roaming devices, direct egress, alternate resolvers, QUIC, asymmetric routes, provider abstraction, and emergency consoles in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 IPv6、覆盖网络、东西向路径、远程与漫游设备、直接出口、替代解析器、QUIC、非对称路由、提供商抽象和紧急控制台 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-8.7-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "8.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-8.7-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "8.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-8.7-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "8.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-8.7-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "8.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-8.7-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "8.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind source owners, platform and security engineering, detection teams, incident responders, privacy, records management, and auditors to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 来源责任人、平台与安全工程、检测团队、事件响应、隐私、档案管理和审计方 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-8.7-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "8.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Name who may transition event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-8.7-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "8.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Name who may transition scheduled → started → observed → normalized → reconciled → dispositioned, with explicit partial and failed states, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 计划 → 启动 → 观测 → 归一化 → 对账 → 处置，并显式保留部分与失败状态，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-8.7-OWN-08",
          "local_code": "OWN-08",
          "display_code": "W08",
          "safeguard_id": "8.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Name who may transition requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-8.7-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "8.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-8.7-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "8.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-8.7-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "8.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV1, GV3, M1, M2, M3) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV1, GV3, M1, M2, M3）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-8.7-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "8.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-8.7-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "8.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the governed log-source inventory and evidence platform as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把受治理的日志源清单与证据平台作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-8.7-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "8.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired.",
          "zh": "对生命周期“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-8.7-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "8.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle scheduled → started → observed → normalized → reconciled → dispositioned, with explicit partial and failed states.",
          "zh": "对生命周期“计划 → 启动 → 观测 → 归一化 → 对账 → 处置，并显式保留部分与失败状态”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-8.7-DAT-08",
          "local_code": "DAT-08",
          "display_code": "D08",
          "safeguard_id": "8.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired.",
          "zh": "对生命周期“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-8.7-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "8.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 1.1, Safeguard 4.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 1.1、Safeguard 4.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-8.7-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "8.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-8.7-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "8.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-8.7-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "8.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-8.7-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "8.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile endpoints, identity, applications, databases, network, cloud/SaaS, providers, collectors, archives, detections, and review records and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 终端、身份、应用、数据库、网络、云/SaaS、提供商、采集器、归档、检测和审阅记录，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-8.7-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "8.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Require every connector carrying complete, attributable, timely, protected, searchable, and actionable security telemetry plus source health to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 完整、可归因、及时、受保护、可检索、可行动的安全遥测及来源健康 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-8.7-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "8.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Require every connector carrying coverage of every intended discovery vantage point, source, job, parser, and reconciliation path to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 所有预期发现视角、来源、任务、解析器和对账路径的覆盖 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-8.7-INT-08",
          "local_code": "INT-08",
          "display_code": "I08",
          "safeguard_id": "8.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Require every connector carrying intended connectivity, trust zone, route, protocol, identity, management path, traffic decision, and observed outcome to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 预期连接、信任区、路由、协议、身份、管理路径、流量决策和观察结果 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-8.7-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "8.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Collect at the control point that can lawfully see the needed fields, bind user/device/session, centralize and redact secrets, tokens, health data and other unnecessary query content.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“在合法且能看到所需字段的控制点采集，绑定用户/设备/会话，集中化并脱敏秘密、Token、健康信息等查询内容；监测客户端旁路和服务商导出，在不经代理时用终端遥测补足。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-8.7-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "8.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-8.7-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "8.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-8.7-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "8.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-8.7-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "8.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the governed log-source inventory and evidence platform and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在受治理的日志源清单与证据平台中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-8.7-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "8.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Implement the explicit state machine event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-8.7-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "8.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Implement the explicit state machine scheduled → started → observed → normalized → reconciled → dispositioned, with explicit partial and failed states; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“计划 → 启动 → 观测 → 归一化 → 对账 → 处置，并显式保留部分与失败状态”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-8.7-CTL-08",
          "local_code": "CTL-08",
          "display_code": "C08",
          "safeguard_id": "8.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Implement the explicit state machine requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-8.7-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "8.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-8.7-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "8.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-8.7-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "8.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-8.7-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "8.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-8.7-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "8.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in security-relevant events, actor and target identity, timestamps, decisions, outcomes, source health, retention, search, and custody; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 安全相关事件、行为者与目标身份、时间、决策、结果、来源健康、保留、检索和证据保管 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-8.7-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "8.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired; alert before each deadline becomes overdue.",
          "zh": "为“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-8.7-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "8.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for scheduled → started → observed → normalized → reconciled → dispositioned, with explicit partial and failed states; alert before each deadline becomes overdue.",
          "zh": "为“计划 → 启动 → 观测 → 归一化 → 对账 → 处置，并显式保留部分与失败状态”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-8.7-TIM-08",
          "local_code": "TIM-08",
          "display_code": "T08",
          "safeguard_id": "8.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; alert before each deadline becomes overdue.",
          "zh": "为“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-8.7-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "8.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “TLS, certificate pinning, privacy relays and end-to-end applications limit path visibility.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“TLS、证书 Pin、隐私 Relay 和端到端应用限制路径可见性。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-8.7-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "8.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-8.7-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "8.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-8.7-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "8.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-8.7-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "8.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat missing fields, clock drift, parser failure, dropped events, duplicate delivery, pooled identities, privacy redaction, provider gaps, quota, and archive unreadability as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 字段缺失、时钟漂移、解析失败、事件丢失、重复投递、汇聚身份、隐私脱敏、提供商缺口、配额和归档不可读 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-8.7-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "8.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Treat clock skew, actor loss, field truncation, parser drift, dropped or duplicate events, privacy redaction, provider gaps, encrypted paths, quota, and archive failure as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 时钟偏移、行为者丢失、字段截断、解析漂移、事件丢失或重复、隐私脱敏、提供商缺口、加密路径、配额和归档故障 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-8.7-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "8.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Treat unreachable zones, short-lived objects, blind spots, rate limits, credential failure, encrypted or proprietary protocols, and silent sensors as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 不可达区域、短生对象、盲区、限流、凭据失败、加密或专有协议和静默传感器 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-8.7-EXC-08",
          "local_code": "EXC-08",
          "display_code": "X08",
          "safeguard_id": "8.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Treat IPv6, overlays, east-west paths, remote and roaming devices, direct egress, alternate resolvers, QUIC, asymmetric routes, provider abstraction, and emergency consoles as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 IPv6、覆盖网络、东西向路径、远程与漫游设备、直接出口、替代解析器、QUIC、非对称路由、提供商抽象和紧急控制台 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-8.7-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "8.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Request benign, blocked, redirected and encoded test URLs from managed and remote devices and verify identity, destination, action, time and correlation.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“从受管/远程设备请求正常、被拦、重定向和编码 URL，核验身份、目的、动作、时间和关联；再测 QUIC、直连 IP、替代浏览器与 VPN。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-8.7-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "8.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-8.7-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "8.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 5 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、5 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-8.7-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "8.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-8.7-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "8.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the governed log-source inventory and evidence platform plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以受治理的日志源清单与证据平台和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-8.7-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "8.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Publish healthy, silent, partial, late, malformed, duplicate, unowned, unreviewed, alerted, investigated, and archived sources or events with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 健康、静默、部分、迟到、畸形、重复、无责任人、未审阅、已告警、已调查和已归档来源或事件，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-8.7-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "8.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Publish scheduled, successful, partial, failed, stale, blind, newly discovered, unmatched, and reconciled observations with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 计划、成功、部分、失败、陈旧、盲区、新发现、未匹配和已对账观测，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-8.7-EVD-08",
          "local_code": "EVD-08",
          "display_code": "E08",
          "safeguard_id": "8.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Publish known, unknown, allowed, denied, shadow, bypassed, asymmetric, stale-rule, exception, and unobserved paths with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已知、未知、允许、拒绝、影子、绕过、非对称、陈旧规则、例外和未观测路径，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-8.7-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "8.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-8.7-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "8.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-8.7-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "8.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-8.7-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "8.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-8.7-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "8.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the governed log-source inventory and evidence platform; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护受治理的日志源清单与证据平台的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-8.7-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "8.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Restrict authority to change event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-8.7-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "8.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Restrict authority to change scheduled → started → observed → normalized → reconciled → dispositioned, with explicit partial and failed states; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“计划 → 启动 → 观测 → 归一化 → 对账 → 处置，并显式保留部分与失败状态”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-8.7-SEC-08",
          "local_code": "SEC-08",
          "display_code": "S08",
          "safeguard_id": "8.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Restrict authority to change requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-8.7-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "8.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-8.7-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "8.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-8.7-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "8.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-8.7-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "8.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-8.7-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "8.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise allowed and denied canary events, collector and parser failure, clock skew, retention boundary, archive restore, provider export loss, and analyst review through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 允许与拒绝的金丝雀事件、采集器与解析器故障、时钟偏移、保留边界、归档恢复、提供商导出丢失和分析员审阅，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-8.7-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "8.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Run the positive control an allowed and denied canary event traced from source through review; exercise negative, stale, duplicate, bypass, and outage controls including source loss, parser/schema change, time skew, queue overflow, duplicate delivery, provider export outage, missed alert, and unreadable archive.",
          "zh": "运行正向控制“一项允许与拒绝金丝雀事件从来源贯穿到审阅”，并执行包含“来源丢失、解析器/模式变化、时钟偏移、队列溢出、重复投递、提供商导出中断、漏报和归档不可读”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-8.7-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "8.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Run the positive control a known object visible from each representative vantage point; exercise negative, stale, duplicate, bypass, and outage controls including an unknown and short-lived object, failed credential, blocked scan, silent sensor, parser drift, and uncovered segment.",
          "zh": "运行正向控制“从每个代表性视角可见的一项已知对象”，并执行包含“未知与短生对象、凭据失败、扫描受阻、传感器静默、解析漂移和未覆盖网段”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-8.7-TST-08",
          "local_code": "TST-08",
          "display_code": "V08",
          "safeguard_id": "8.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Run the positive control an approved flow over the required secure management or business path; exercise negative, stale, duplicate, bypass, and outage controls including an unapproved route, protocol downgrade, direct egress, alternate DNS/QUIC path, segmentation bypass, AAA loss, stale rule, and rollback failure.",
          "zh": "运行正向控制“通过规定安全管理或业务路径的一项获批流量”，并执行包含“未批准路由、协议降级、直接出口、替代 DNS/QUIC 路径、分段绕过、AAA 丢失、陈旧规则和回滚失败”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-8.7-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "8.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-8.7-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "8.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-8.7-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "8.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-8.7-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "8.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-8.7-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "8.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever endpoints, identity, applications, databases, network, cloud/SaaS, providers, collectors, archives, detections, and review records change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 终端、身份、应用、数据库、网络、云/SaaS、提供商、采集器、归档、检测和审阅记录 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-8.7-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "8.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Use healthy, silent, partial, late, malformed, duplicate, unowned, unreviewed, alerted, investigated, and archived sources or events to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 健康、静默、部分、迟到、畸形、重复、无责任人、未审阅、已告警、已调查和已归档来源或事件 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-8.7-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "8.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Use scheduled, successful, partial, failed, stale, blind, newly discovered, unmatched, and reconciled observations to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 计划、成功、部分、失败、陈旧、盲区、新发现、未匹配和已对账观测 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-8.7-OPS-08",
          "local_code": "OPS-08",
          "display_code": "R08",
          "safeguard_id": "8.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Use known, unknown, allowed, denied, shadow, bypassed, asymmetric, stale-rule, exception, and unobserved paths to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已知、未知、允许、拒绝、影子、绕过、非对称、陈旧规则、例外和未观测路径 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "8.8",
      "control": 8,
      "title_en": "Collect Command-Line Audit Logs",
      "title_zh": "命令行日志",
      "first_ig": 2,
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Data",
      "security_function": "Detect",
      "patterns": [
        "telemetry",
        "discovery"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "1.1",
          "4.1"
        ],
        "variables": [
          "GV1",
          "GV3",
          "M1",
          "M2",
          "M3"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "Include interactive and non-interactive PowerShell, shell, command prompt, remote terminals, scripts, container exec, CI/CD runners and cloud command interfaces that can change enterprise state.",
          "build": "Enable platform-native command/process/script-block and terminal-session auditing according to risk, preserve user, effective privilege, parent, host/workload, command or content identity, result and time, and centralize quickly.",
          "proof": "Run benign commands through direct, encoded, script, remote, sudo/elevation and container paths; verify capture and correlation without truncation.",
          "boundary": "Attackers and admins can use APIs, GUI, in-memory calls or allowed interpreters without a conventional command line."
        },
        "zh": {
          "scope": "包括交互和非交互的 PowerShell、Shell、命令提示、远程终端、脚本、容器 Exec、CI/CD Runner 与云命令接口。",
          "build": "按风险启用命令/进程/脚本块/终端会话审计，保留用户、有效权限、父进程、主机/工作负载、命令或内容身份、结果与时间，并快速集中；阻止秘密上命令行或做脱敏，保护高权录屏。",
          "proof": "通过直连、编码、脚本、远程、sudo/提权与容器路径运行无害命令，验证采集、关联和不截断；执行秘密金丝雀确认阻止/遮罩，再停 Sensor 测健康告警。",
          "boundary": "攻击者/管理员可走 API、GUI、内存调用或允许解释器而无传统命令行。"
        }
      },
      "category_counts": {
        "outcome": 7,
        "scope": 7,
        "ownership": 7,
        "data": 7,
        "integration": 7,
        "control": 7,
        "timing": 7,
        "exception": 7,
        "evidence": 7,
        "security": 7,
        "testing": 7,
        "operations": 7
      },
      "requirement_count": 84,
      "requirements": [
        {
          "code": "CIS-8.8-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "8.8",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Collect Command-Line Audit Logs; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“命令行日志”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-8.8-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "8.8",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 8.8, official Asset Class Data, Security Function Detect, and IG2 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 8.8、官方资产类别“数据”、安全功能“检测”和首次出现的 IG2，并保存来源抓取日期。"
        },
        {
          "code": "CIS-8.8-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "8.8",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Include interactive and non-interactive PowerShell, shell, command prompt, remote terminals, scripts, container exec, CI/CD runners and cloud command interfaces that can change enterprise state.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“包括交互和非交互的 PowerShell、Shell、命令提示、远程终端、脚本、容器 Exec、CI/CD Runner 与云命令接口。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-8.8-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "8.8",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-8.8-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "8.8",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Collect Command-Line Audit Logs to its operating object—security-relevant events, actor and target identity, timestamps, decisions, outcomes, source health, retention, search, and custody—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“命令行日志”连接到其运营对象——安全相关事件、行为者与目标身份、时间、决策、结果、来源健康、保留、检索和证据保管——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-8.8-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "8.8",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "For Collect Command-Line Audit Logs, express success as an observable decision over complete, attributable, timely, protected, searchable, and actionable security telemetry plus source health; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“命令行日志”，以 完整、可归因、及时、受保护、可检索、可行动的安全遥测及来源健康 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-8.8-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "8.8",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "For Collect Command-Line Audit Logs, express success as an observable decision over coverage of every intended discovery vantage point, source, job, parser, and reconciliation path; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“命令行日志”，以 所有预期发现视角、来源、任务、解析器和对账路径的覆盖 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-8.8-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "8.8",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-8.8-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "8.8",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-8.8-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "8.8",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-8.8-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "8.8",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-8.8-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "8.8",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across missing fields, clock drift, parser failure, dropped events, duplicate delivery, pooled identities, privacy redaction, provider gaps, quota, and archive unreadability; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 字段缺失、时钟漂移、解析失败、事件丢失、重复投递、汇聚身份、隐私脱敏、提供商缺口、配额和归档不可读 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-8.8-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "8.8",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Include clock skew, actor loss, field truncation, parser drift, dropped or duplicate events, privacy redaction, provider gaps, encrypted paths, quota, and archive failure in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 时钟偏移、行为者丢失、字段截断、解析漂移、事件丢失或重复、隐私脱敏、提供商缺口、加密路径、配额和归档故障 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-8.8-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "8.8",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Include unreachable zones, short-lived objects, blind spots, rate limits, credential failure, encrypted or proprietary protocols, and silent sensors in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 不可达区域、短生对象、盲区、限流、凭据失败、加密或专有协议和静默传感器 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-8.8-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "8.8",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-8.8-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "8.8",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-8.8-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "8.8",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-8.8-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "8.8",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-8.8-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "8.8",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind source owners, platform and security engineering, detection teams, incident responders, privacy, records management, and auditors to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 来源责任人、平台与安全工程、检测团队、事件响应、隐私、档案管理和审计方 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-8.8-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "8.8",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Name who may transition event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-8.8-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "8.8",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Name who may transition scheduled → started → observed → normalized → reconciled → dispositioned, with explicit partial and failed states, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 计划 → 启动 → 观测 → 归一化 → 对账 → 处置，并显式保留部分与失败状态，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-8.8-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "8.8",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-8.8-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "8.8",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-8.8-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "8.8",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV1, GV3, M1, M2, M3) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV1, GV3, M1, M2, M3）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-8.8-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "8.8",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-8.8-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "8.8",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the governed log-source inventory and evidence platform as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把受治理的日志源清单与证据平台作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-8.8-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "8.8",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired.",
          "zh": "对生命周期“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-8.8-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "8.8",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle scheduled → started → observed → normalized → reconciled → dispositioned, with explicit partial and failed states.",
          "zh": "对生命周期“计划 → 启动 → 观测 → 归一化 → 对账 → 处置，并显式保留部分与失败状态”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-8.8-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "8.8",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 1.1, Safeguard 4.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 1.1、Safeguard 4.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-8.8-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "8.8",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-8.8-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "8.8",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-8.8-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "8.8",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-8.8-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "8.8",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile endpoints, identity, applications, databases, network, cloud/SaaS, providers, collectors, archives, detections, and review records and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 终端、身份、应用、数据库、网络、云/SaaS、提供商、采集器、归档、检测和审阅记录，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-8.8-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "8.8",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Require every connector carrying complete, attributable, timely, protected, searchable, and actionable security telemetry plus source health to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 完整、可归因、及时、受保护、可检索、可行动的安全遥测及来源健康 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-8.8-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "8.8",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Require every connector carrying coverage of every intended discovery vantage point, source, job, parser, and reconciliation path to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 所有预期发现视角、来源、任务、解析器和对账路径的覆盖 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-8.8-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "8.8",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Enable platform-native command/process/script-block and terminal-session auditing according to risk, preserve user, effective privilege, parent, host/workload, command or content identity, result and time, and centralize quickly.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“按风险启用命令/进程/脚本块/终端会话审计，保留用户、有效权限、父进程、主机/工作负载、命令或内容身份、结果与时间，并快速集中；阻止秘密上命令行或做脱敏，保护高权录屏。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-8.8-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "8.8",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-8.8-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "8.8",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-8.8-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "8.8",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-8.8-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "8.8",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the governed log-source inventory and evidence platform and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在受治理的日志源清单与证据平台中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-8.8-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "8.8",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Implement the explicit state machine event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-8.8-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "8.8",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Implement the explicit state machine scheduled → started → observed → normalized → reconciled → dispositioned, with explicit partial and failed states; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“计划 → 启动 → 观测 → 归一化 → 对账 → 处置，并显式保留部分与失败状态”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-8.8-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "8.8",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-8.8-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "8.8",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-8.8-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "8.8",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-8.8-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "8.8",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-8.8-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "8.8",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in security-relevant events, actor and target identity, timestamps, decisions, outcomes, source health, retention, search, and custody; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 安全相关事件、行为者与目标身份、时间、决策、结果、来源健康、保留、检索和证据保管 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-8.8-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "8.8",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired; alert before each deadline becomes overdue.",
          "zh": "为“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-8.8-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "8.8",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for scheduled → started → observed → normalized → reconciled → dispositioned, with explicit partial and failed states; alert before each deadline becomes overdue.",
          "zh": "为“计划 → 启动 → 观测 → 归一化 → 对账 → 处置，并显式保留部分与失败状态”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-8.8-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "8.8",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “Attackers and admins can use APIs, GUI, in-memory calls or allowed interpreters without a conventional command line.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“攻击者/管理员可走 API、GUI、内存调用或允许解释器而无传统命令行。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-8.8-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "8.8",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-8.8-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "8.8",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-8.8-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "8.8",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-8.8-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "8.8",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat missing fields, clock drift, parser failure, dropped events, duplicate delivery, pooled identities, privacy redaction, provider gaps, quota, and archive unreadability as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 字段缺失、时钟漂移、解析失败、事件丢失、重复投递、汇聚身份、隐私脱敏、提供商缺口、配额和归档不可读 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-8.8-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "8.8",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Treat clock skew, actor loss, field truncation, parser drift, dropped or duplicate events, privacy redaction, provider gaps, encrypted paths, quota, and archive failure as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 时钟偏移、行为者丢失、字段截断、解析漂移、事件丢失或重复、隐私脱敏、提供商缺口、加密路径、配额和归档故障 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-8.8-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "8.8",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Treat unreachable zones, short-lived objects, blind spots, rate limits, credential failure, encrypted or proprietary protocols, and silent sensors as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 不可达区域、短生对象、盲区、限流、凭据失败、加密或专有协议和静默传感器 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-8.8-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "8.8",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Run benign commands through direct, encoded, script, remote, sudo/elevation and container paths; verify capture and correlation without truncation.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“通过直连、编码、脚本、远程、sudo/提权与容器路径运行无害命令，验证采集、关联和不截断；执行秘密金丝雀确认阻止/遮罩，再停 Sensor 测健康告警。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-8.8-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "8.8",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-8.8-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "8.8",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 5 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、5 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-8.8-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "8.8",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-8.8-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "8.8",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the governed log-source inventory and evidence platform plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以受治理的日志源清单与证据平台和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-8.8-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "8.8",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Publish healthy, silent, partial, late, malformed, duplicate, unowned, unreviewed, alerted, investigated, and archived sources or events with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 健康、静默、部分、迟到、畸形、重复、无责任人、未审阅、已告警、已调查和已归档来源或事件，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-8.8-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "8.8",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Publish scheduled, successful, partial, failed, stale, blind, newly discovered, unmatched, and reconciled observations with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 计划、成功、部分、失败、陈旧、盲区、新发现、未匹配和已对账观测，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-8.8-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "8.8",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-8.8-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "8.8",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-8.8-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "8.8",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-8.8-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "8.8",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-8.8-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "8.8",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the governed log-source inventory and evidence platform; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护受治理的日志源清单与证据平台的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-8.8-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "8.8",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Restrict authority to change event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-8.8-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "8.8",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Restrict authority to change scheduled → started → observed → normalized → reconciled → dispositioned, with explicit partial and failed states; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“计划 → 启动 → 观测 → 归一化 → 对账 → 处置，并显式保留部分与失败状态”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-8.8-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "8.8",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-8.8-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "8.8",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-8.8-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "8.8",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-8.8-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "8.8",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-8.8-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "8.8",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise allowed and denied canary events, collector and parser failure, clock skew, retention boundary, archive restore, provider export loss, and analyst review through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 允许与拒绝的金丝雀事件、采集器与解析器故障、时钟偏移、保留边界、归档恢复、提供商导出丢失和分析员审阅，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-8.8-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "8.8",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Run the positive control an allowed and denied canary event traced from source through review; exercise negative, stale, duplicate, bypass, and outage controls including source loss, parser/schema change, time skew, queue overflow, duplicate delivery, provider export outage, missed alert, and unreadable archive.",
          "zh": "运行正向控制“一项允许与拒绝金丝雀事件从来源贯穿到审阅”，并执行包含“来源丢失、解析器/模式变化、时钟偏移、队列溢出、重复投递、提供商导出中断、漏报和归档不可读”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-8.8-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "8.8",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Run the positive control a known object visible from each representative vantage point; exercise negative, stale, duplicate, bypass, and outage controls including an unknown and short-lived object, failed credential, blocked scan, silent sensor, parser drift, and uncovered segment.",
          "zh": "运行正向控制“从每个代表性视角可见的一项已知对象”，并执行包含“未知与短生对象、凭据失败、扫描受阻、传感器静默、解析漂移和未覆盖网段”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-8.8-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "8.8",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-8.8-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "8.8",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-8.8-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "8.8",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-8.8-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "8.8",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-8.8-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "8.8",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever endpoints, identity, applications, databases, network, cloud/SaaS, providers, collectors, archives, detections, and review records change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 终端、身份、应用、数据库、网络、云/SaaS、提供商、采集器、归档、检测和审阅记录 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-8.8-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "8.8",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Use healthy, silent, partial, late, malformed, duplicate, unowned, unreviewed, alerted, investigated, and archived sources or events to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 健康、静默、部分、迟到、畸形、重复、无责任人、未审阅、已告警、已调查和已归档来源或事件 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-8.8-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "8.8",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Use scheduled, successful, partial, failed, stale, blind, newly discovered, unmatched, and reconciled observations to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 计划、成功、部分、失败、陈旧、盲区、新发现、未匹配和已对账观测 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "8.9",
      "control": 8,
      "title_en": "Centralize Audit Logs",
      "title_zh": "集中日志",
      "first_ig": 2,
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Data",
      "security_function": "Detect",
      "patterns": [
        "telemetry"
      ],
      "expanded_complexity": true,
      "cas_context": {
        "dependencies": [
          "1.1",
          "2.1"
        ],
        "variables": [
          "GV5",
          "GV27",
          "GV28",
          "M1",
          "M2",
          "M3"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "Centralization covers required events from every source that can export them, into governed stores where correlation, access control, retention and incident use are possible.",
          "build": "Use authenticated, buffered pipelines and normalized stable identifiers; isolate ingestion from search, restrict tenant and analyst access, maintain source health and immutable/independent copies for critical evidence.",
          "proof": "Trace canary events from each source class, fail collector/network/parser components, and verify buffering, duplicate handling, order, integrity and alerting.",
          "boundary": "An agent configured to forward does not count when events never arrive."
        },
        "zh": {
          "scope": "把所有可导出的必需事件放入受治理、可关联、可控访问/保留并可供事件使用的存储体系。",
          "build": "用认证、有缓冲的管道和稳定归一身份，分离接入与查询，限制租户/分析员访问，维护源健康；关键证据保留不可变或独立副本。",
          "proof": "从每类源追金丝雀，分别故障收集器、网络和 Parser，验证缓冲、去重、顺序、完整性和告警；把近期到达的源身份与日志源台账对账，部分事件集和陈旧源单列。",
          "boundary": "Agent 配了转发但事件没到不能算。"
        }
      },
      "category_counts": {
        "outcome": 7,
        "scope": 7,
        "ownership": 7,
        "data": 7,
        "integration": 7,
        "control": 7,
        "timing": 7,
        "exception": 7,
        "evidence": 7,
        "security": 7,
        "testing": 7,
        "operations": 7
      },
      "requirement_count": 84,
      "requirements": [
        {
          "code": "CIS-8.9-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "8.9",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Centralize Audit Logs; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“集中日志”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-8.9-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "8.9",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 8.9, official Asset Class Data, Security Function Detect, and IG2 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 8.9、官方资产类别“数据”、安全功能“检测”和首次出现的 IG2，并保存来源抓取日期。"
        },
        {
          "code": "CIS-8.9-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "8.9",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Centralization covers required events from every source that can export them, into governed stores where correlation, access control, retention and incident use are possible.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“把所有可导出的必需事件放入受治理、可关联、可控访问/保留并可供事件使用的存储体系。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-8.9-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "8.9",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-8.9-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "8.9",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Centralize Audit Logs to its operating object—security-relevant events, actor and target identity, timestamps, decisions, outcomes, source health, retention, search, and custody—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“集中日志”连接到其运营对象——安全相关事件、行为者与目标身份、时间、决策、结果、来源健康、保留、检索和证据保管——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-8.9-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "8.9",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "For Centralize Audit Logs, express success as an observable decision over complete, attributable, timely, protected, searchable, and actionable security telemetry plus source health; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“集中日志”，以 完整、可归因、及时、受保护、可检索、可行动的安全遥测及来源健康 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-8.9-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "8.9",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "For the expanded Centralize Audit Logs scope, resolve conflicts among security, safety, privacy, legal, availability, customer, and operational objectives through an explicit risk decision.",
          "zh": "对“集中日志”的扩展范围，通过显式风险决策解决安全、安全生产、隐私、法律、可用性、客户和运营目标冲突。"
        },
        {
          "code": "CIS-8.9-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "8.9",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-8.9-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "8.9",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-8.9-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "8.9",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-8.9-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "8.9",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-8.9-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "8.9",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across missing fields, clock drift, parser failure, dropped events, duplicate delivery, pooled identities, privacy redaction, provider gaps, quota, and archive unreadability; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 字段缺失、时钟漂移、解析失败、事件丢失、重复投递、汇聚身份、隐私脱敏、提供商缺口、配额和归档不可读 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-8.9-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "8.9",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Include clock skew, actor loss, field truncation, parser drift, dropped or duplicate events, privacy redaction, provider gaps, encrypted paths, quota, and archive failure in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 时钟偏移、行为者丢失、字段截断、解析漂移、事件丢失或重复、隐私脱敏、提供商缺口、加密路径、配额和归档故障 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-8.9-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "8.9",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Define nested scope at enterprise, business service, tenant, environment, platform, object, identity, data set, and transaction levels; prohibit a parent result from hiding a failing child.",
          "zh": "按企业、业务服务、租户、环境、平台、对象、身份、数据集和交易定义嵌套范围，禁止父级结果遮蔽失败子级。"
        },
        {
          "code": "CIS-8.9-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "8.9",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-8.9-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "8.9",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-8.9-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "8.9",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-8.9-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "8.9",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-8.9-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "8.9",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind source owners, platform and security engineering, detection teams, incident responders, privacy, records management, and auditors to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 来源责任人、平台与安全工程、检测团队、事件响应、隐私、档案管理和审计方 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-8.9-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "8.9",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Name who may transition event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-8.9-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "8.9",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Model delegated authority, quorum or dual approval where warranted, escalation deadlines, provider handoffs, conflict resolution, and executive risk acceptance.",
          "zh": "建模委派权限、必要时的双人或法定人数审批、升级期限、提供商交接、冲突解决和管理层风险接受。"
        },
        {
          "code": "CIS-8.9-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "8.9",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-8.9-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "8.9",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-8.9-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "8.9",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV5, GV27, GV28, M1, M2, M3) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV5, GV27, GV28, M1, M2, M3）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-8.9-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "8.9",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-8.9-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "8.9",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the governed log-source inventory and evidence platform as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把受治理的日志源清单与证据平台作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-8.9-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "8.9",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired.",
          "zh": "对生命周期“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-8.9-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "8.9",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Version schemas and state transitions with migration, backfill, deduplication, lineage, historical denominator, deletion, and rollback semantics.",
          "zh": "对模式和状态转换做版本管理，定义迁移、回填、去重、血缘、历史分母、删除和回滚语义。"
        },
        {
          "code": "CIS-8.9-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "8.9",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 1.1, Safeguard 2.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 1.1、Safeguard 2.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-8.9-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "8.9",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-8.9-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "8.9",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-8.9-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "8.9",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-8.9-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "8.9",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile endpoints, identity, applications, databases, network, cloud/SaaS, providers, collectors, archives, detections, and review records and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 终端、身份、应用、数据库、网络、云/SaaS、提供商、采集器、归档、检测和审阅记录，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-8.9-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "8.9",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Require every connector carrying complete, attributable, timely, protected, searchable, and actionable security telemetry plus source health to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 完整、可归因、及时、受保护、可检索、可行动的安全遥测及来源健康 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-8.9-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "8.9",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Define consistency rules across disagreeing sources, source precedence, confidence, reconciliation queues, dead-letter handling, reprocessing, and end-to-end trace identity.",
          "zh": "定义冲突来源的一致性、优先级、置信度、对账队列、死信、重处理和端到端追踪身份。"
        },
        {
          "code": "CIS-8.9-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "8.9",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Use authenticated, buffered pipelines and normalized stable identifiers; isolate ingestion from search, restrict tenant and analyst access, maintain source health and immutable/independent copies for critical evidence.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“用认证、有缓冲的管道和稳定归一身份，分离接入与查询，限制租户/分析员访问，维护源健康；关键证据保留不可变或独立副本。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-8.9-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "8.9",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-8.9-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "8.9",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-8.9-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "8.9",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-8.9-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "8.9",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the governed log-source inventory and evidence platform and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在受治理的日志源清单与证据平台中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-8.9-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "8.9",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Implement the explicit state machine event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-8.9-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "8.9",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Specify concurrent decisions, partial success, compensating transactions, repeated requests, stale policy, dependency outage, and recovery from an interrupted state transition.",
          "zh": "定义并发决策、部分成功、补偿事务、重复请求、陈旧策略、依赖中断和中途状态转换恢复。"
        },
        {
          "code": "CIS-8.9-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "8.9",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-8.9-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "8.9",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-8.9-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "8.9",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-8.9-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "8.9",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-8.9-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "8.9",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in security-relevant events, actor and target identity, timestamps, decisions, outcomes, source health, retention, search, and custody; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 安全相关事件、行为者与目标身份、时间、决策、结果、来源健康、保留、检索和证据保管 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-8.9-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "8.9",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired; alert before each deadline becomes overdue.",
          "zh": "为“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-8.9-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "8.9",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Allocate an end-to-end SLO budget across discovery, collection, processing, approval, enforcement, verification, and closure; prioritize overdue work by consequence and exposure.",
          "zh": "把端到端 SLO 预算分配到发现、采集、处理、审批、执行、验证和关闭，并按后果与暴露排列逾期工作。"
        },
        {
          "code": "CIS-8.9-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "8.9",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “An agent configured to forward does not count when events never arrive.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“Agent 配了转发但事件没到不能算。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-8.9-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "8.9",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-8.9-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "8.9",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-8.9-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "8.9",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-8.9-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "8.9",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat missing fields, clock drift, parser failure, dropped events, duplicate delivery, pooled identities, privacy redaction, provider gaps, quota, and archive unreadability as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 字段缺失、时钟漂移、解析失败、事件丢失、重复投递、汇聚身份、隐私脱敏、提供商缺口、配额和归档不可读 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-8.9-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "8.9",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Treat clock skew, actor loss, field truncation, parser drift, dropped or duplicate events, privacy redaction, provider gaps, encrypted paths, quota, and archive failure as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 时钟偏移、行为者丢失、字段截断、解析漂移、事件丢失或重复、隐私脱敏、提供商缺口、加密路径、配额和归档故障 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-8.9-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "8.9",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Exercise compound failures where an exception, stale source, provider outage, unavailable owner, and degraded control overlap; define one safe command and one accountable decision.",
          "zh": "演练例外、陈旧来源、提供商中断、责任人不可用和控制降级同时出现的复合故障，明确一条安全指令和一个责任决策。"
        },
        {
          "code": "CIS-8.9-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "8.9",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Trace canary events from each source class, fail collector/network/parser components, and verify buffering, duplicate handling, order, integrity and alerting.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“从每类源追金丝雀，分别故障收集器、网络和 Parser，验证缓冲、去重、顺序、完整性和告警；把近期到达的源身份与日志源台账对账，部分事件集和陈旧源单列。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-8.9-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "8.9",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-8.9-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "8.9",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 6 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、6 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-8.9-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "8.9",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-8.9-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "8.9",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the governed log-source inventory and evidence platform plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以受治理的日志源清单与证据平台和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-8.9-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "8.9",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Publish healthy, silent, partial, late, malformed, duplicate, unowned, unreviewed, alerted, investigated, and archived sources or events with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 健康、静默、部分、迟到、畸形、重复、无责任人、未审阅、已告警、已调查和已归档来源或事件，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-8.9-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "8.9",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Require an independent party to reconstruct the decision from source receipts and reproduce the population, state transition, calculation, test result, exception, and final closure.",
          "zh": "要求独立人员使用来源回执重建决策，并复现总体、状态转换、计算、测试结果、例外和最终关闭。"
        },
        {
          "code": "CIS-8.9-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "8.9",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-8.9-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "8.9",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-8.9-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "8.9",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-8.9-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "8.9",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-8.9-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "8.9",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the governed log-source inventory and evidence platform; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护受治理的日志源清单与证据平台的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-8.9-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "8.9",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Restrict authority to change event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-8.9-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "8.9",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Threat-model the implementation system itself: forged evidence, poisoned inventory, privilege abuse, cross-tenant confusion, policy rollback, audit deletion, denial of service, and recovery compromise.",
          "zh": "威胁建模实施系统自身：伪造证据、污染清单、权限滥用、跨租户混淆、策略回滚、审计删除、拒绝服务和恢复失陷。"
        },
        {
          "code": "CIS-8.9-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "8.9",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-8.9-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "8.9",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-8.9-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "8.9",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-8.9-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "8.9",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-8.9-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "8.9",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise allowed and denied canary events, collector and parser failure, clock skew, retention boundary, archive restore, provider export loss, and analyst review through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 允许与拒绝的金丝雀事件、采集器与解析器故障、时钟偏移、保留边界、归档恢复、提供商导出丢失和分析员审阅，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-8.9-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "8.9",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Run the positive control an allowed and denied canary event traced from source through review; exercise negative, stale, duplicate, bypass, and outage controls including source loss, parser/schema change, time skew, queue overflow, duplicate delivery, provider export outage, missed alert, and unreadable archive.",
          "zh": "运行正向控制“一项允许与拒绝金丝雀事件从来源贯穿到审阅”，并执行包含“来源丢失、解析器/模式变化、时钟偏移、队列溢出、重复投递、提供商导出中断、漏报和归档不可读”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-8.9-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "8.9",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Build a pairwise platform-and-failure matrix, then add high-consequence multi-factor cases, historical regression, source substitution, red-team challenge, and assessor replay.",
          "zh": "建立平台—故障两两组合矩阵，再加入高后果多因素案例、历史回归、来源替换、红队挑战和评估方重放。"
        },
        {
          "code": "CIS-8.9-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "8.9",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-8.9-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "8.9",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-8.9-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "8.9",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-8.9-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "8.9",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-8.9-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "8.9",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever endpoints, identity, applications, databases, network, cloud/SaaS, providers, collectors, archives, detections, and review records change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 终端、身份、应用、数据库、网络、云/SaaS、提供商、采集器、归档、检测和审阅记录 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-8.9-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "8.9",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Use healthy, silent, partial, late, malformed, duplicate, unowned, unreviewed, alerted, investigated, and archived sources or events to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 健康、静默、部分、迟到、畸形、重复、无责任人、未审阅、已告警、已调查和已归档来源或事件 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-8.9-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "8.9",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Use canary deployment, kill criteria, rollback, backlog burn-down, exception reduction, source-quality targets, quarterly design review, and a measurable retirement plan.",
          "zh": "采用金丝雀、停止标准、回滚、积压燃尽、例外缩减、来源质量目标、季度设计复核和可量化退役计划。"
        }
      ]
    },
    {
      "id": "8.10",
      "control": 8,
      "title_en": "Retain Audit Logs",
      "title_zh": "日志保留",
      "first_ig": 2,
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Data",
      "security_function": "Protect",
      "patterns": [
        "telemetry"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "4.1",
          "8.9"
        ],
        "variables": [
          "GV3",
          "GV28",
          "M1",
          "M2",
          "M3"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [
        "90 days"
      ],
      "implementation_contract": {
        "en": {
          "scope": "Retain required audit logs at least 90 days across local, centralized, provider and archive tiers, while incident, legal and regulatory needs may require longer.",
          "build": "Apply lifecycle and immutability/access rules by log class, monitor actual oldest event and early deletion, preserve schemas/keys needed to read archives, and align local buffers with central success.",
          "proof": "Query events just inside and beyond 90 days in a time-shifted test or historical store, restore archived samples and verify integrity, identity and readable schema.",
          "boundary": "A 90-day setting can fail under quotas, ingest delay or timestamp parsing."
        },
        "zh": {
          "scope": "全部必需审计日志至少保留 90 天，覆盖本地、集中、服务商和归档层；事件、法律和法规可要求更久。",
          "build": "按日志类别执行生命周期与不可变/访问策略，监测真实最老事件和提前删除，保存读取归档所需 Schema/密钥；本地缓冲与中央接收一致。",
          "proof": "在时间推进或历史存储中查询 90 天内外事件，恢复归档样本并验证完整性、身份与可读 Schema。",
          "boundary": "90 天设置会因配额、接入延迟或时间解析而失败。"
        }
      },
      "category_counts": {
        "outcome": 6,
        "scope": 6,
        "ownership": 6,
        "data": 6,
        "integration": 6,
        "control": 6,
        "timing": 6,
        "exception": 6,
        "evidence": 6,
        "security": 6,
        "testing": 6,
        "operations": 6
      },
      "requirement_count": 72,
      "requirements": [
        {
          "code": "CIS-8.10-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "8.10",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Retain Audit Logs; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“日志保留”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-8.10-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "8.10",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 8.10, official Asset Class Data, Security Function Protect, and IG2 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 8.10、官方资产类别“数据”、安全功能“保护”和首次出现的 IG2，并保存来源抓取日期。"
        },
        {
          "code": "CIS-8.10-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "8.10",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Retain required audit logs at least 90 days across local, centralized, provider and archive tiers, while incident, legal and regulatory needs may require longer.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“全部必需审计日志至少保留 90 天，覆盖本地、集中、服务商和归档层；事件、法律和法规可要求更久。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-8.10-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "8.10",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-8.10-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "8.10",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Retain Audit Logs to its operating object—security-relevant events, actor and target identity, timestamps, decisions, outcomes, source health, retention, search, and custody—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“日志保留”连接到其运营对象——安全相关事件、行为者与目标身份、时间、决策、结果、来源健康、保留、检索和证据保管——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-8.10-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "8.10",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "For Retain Audit Logs, express success as an observable decision over complete, attributable, timely, protected, searchable, and actionable security telemetry plus source health; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“日志保留”，以 完整、可归因、及时、受保护、可检索、可行动的安全遥测及来源健康 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-8.10-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "8.10",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-8.10-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "8.10",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-8.10-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "8.10",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-8.10-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "8.10",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-8.10-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "8.10",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across missing fields, clock drift, parser failure, dropped events, duplicate delivery, pooled identities, privacy redaction, provider gaps, quota, and archive unreadability; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 字段缺失、时钟漂移、解析失败、事件丢失、重复投递、汇聚身份、隐私脱敏、提供商缺口、配额和归档不可读 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-8.10-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "8.10",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Include clock skew, actor loss, field truncation, parser drift, dropped or duplicate events, privacy redaction, provider gaps, encrypted paths, quota, and archive failure in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 时钟偏移、行为者丢失、字段截断、解析漂移、事件丢失或重复、隐私脱敏、提供商缺口、加密路径、配额和归档故障 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-8.10-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "8.10",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-8.10-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "8.10",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-8.10-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "8.10",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-8.10-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "8.10",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-8.10-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "8.10",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind source owners, platform and security engineering, detection teams, incident responders, privacy, records management, and auditors to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 来源责任人、平台与安全工程、检测团队、事件响应、隐私、档案管理和审计方 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-8.10-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "8.10",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Name who may transition event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-8.10-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "8.10",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-8.10-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "8.10",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-8.10-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "8.10",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV3, GV28, M1, M2, M3) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV3, GV28, M1, M2, M3）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-8.10-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "8.10",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-8.10-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "8.10",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the governed log-source inventory and evidence platform as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把受治理的日志源清单与证据平台作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-8.10-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "8.10",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired.",
          "zh": "对生命周期“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-8.10-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "8.10",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 4.1, Safeguard 8.9; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 4.1、Safeguard 8.9 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-8.10-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "8.10",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-8.10-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "8.10",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-8.10-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "8.10",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-8.10-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "8.10",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile endpoints, identity, applications, databases, network, cloud/SaaS, providers, collectors, archives, detections, and review records and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 终端、身份、应用、数据库、网络、云/SaaS、提供商、采集器、归档、检测和审阅记录，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-8.10-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "8.10",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Require every connector carrying complete, attributable, timely, protected, searchable, and actionable security telemetry plus source health to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 完整、可归因、及时、受保护、可检索、可行动的安全遥测及来源健康 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-8.10-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "8.10",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Apply lifecycle and immutability/access rules by log class, monitor actual oldest event and early deletion, preserve schemas/keys needed to read archives, and align local buffers with central success.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“按日志类别执行生命周期与不可变/访问策略，监测真实最老事件和提前删除，保存读取归档所需 Schema/密钥；本地缓冲与中央接收一致。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-8.10-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "8.10",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-8.10-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "8.10",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-8.10-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "8.10",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-8.10-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "8.10",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the governed log-source inventory and evidence platform and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在受治理的日志源清单与证据平台中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-8.10-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "8.10",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Implement the explicit state machine event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-8.10-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "8.10",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (90 days); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（90 days）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-8.10-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "8.10",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-8.10-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "8.10",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-8.10-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "8.10",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-8.10-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "8.10",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in security-relevant events, actor and target identity, timestamps, decisions, outcomes, source health, retention, search, and custody; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 安全相关事件、行为者与目标身份、时间、决策、结果、来源健康、保留、检索和证据保管 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-8.10-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "8.10",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired; alert before each deadline becomes overdue.",
          "zh": "为“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-8.10-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "8.10",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “A 90-day setting can fail under quotas, ingest delay or timestamp parsing.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“90 天设置会因配额、接入延迟或时间解析而失败。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-8.10-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "8.10",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-8.10-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "8.10",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-8.10-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "8.10",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-8.10-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "8.10",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat missing fields, clock drift, parser failure, dropped events, duplicate delivery, pooled identities, privacy redaction, provider gaps, quota, and archive unreadability as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 字段缺失、时钟漂移、解析失败、事件丢失、重复投递、汇聚身份、隐私脱敏、提供商缺口、配额和归档不可读 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-8.10-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "8.10",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Treat clock skew, actor loss, field truncation, parser drift, dropped or duplicate events, privacy redaction, provider gaps, encrypted paths, quota, and archive failure as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 时钟偏移、行为者丢失、字段截断、解析漂移、事件丢失或重复、隐私脱敏、提供商缺口、加密路径、配额和归档故障 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-8.10-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "8.10",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Query events just inside and beyond 90 days in a time-shifted test or historical store, restore archived samples and verify integrity, identity and readable schema.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“在时间推进或历史存储中查询 90 天内外事件，恢复归档样本并验证完整性、身份与可读 Schema。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-8.10-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "8.10",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-8.10-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "8.10",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 5 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、5 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-8.10-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "8.10",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-8.10-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "8.10",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the governed log-source inventory and evidence platform plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以受治理的日志源清单与证据平台和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-8.10-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "8.10",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Publish healthy, silent, partial, late, malformed, duplicate, unowned, unreviewed, alerted, investigated, and archived sources or events with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 健康、静默、部分、迟到、畸形、重复、无责任人、未审阅、已告警、已调查和已归档来源或事件，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-8.10-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "8.10",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-8.10-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "8.10",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-8.10-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "8.10",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-8.10-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "8.10",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-8.10-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "8.10",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the governed log-source inventory and evidence platform; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护受治理的日志源清单与证据平台的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-8.10-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "8.10",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Restrict authority to change event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-8.10-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "8.10",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-8.10-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "8.10",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-8.10-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "8.10",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-8.10-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "8.10",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-8.10-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "8.10",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise allowed and denied canary events, collector and parser failure, clock skew, retention boundary, archive restore, provider export loss, and analyst review through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 允许与拒绝的金丝雀事件、采集器与解析器故障、时钟偏移、保留边界、归档恢复、提供商导出丢失和分析员审阅，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-8.10-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "8.10",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Run the positive control an allowed and denied canary event traced from source through review; exercise negative, stale, duplicate, bypass, and outage controls including source loss, parser/schema change, time skew, queue overflow, duplicate delivery, provider export outage, missed alert, and unreadable archive.",
          "zh": "运行正向控制“一项允许与拒绝金丝雀事件从来源贯穿到审阅”，并执行包含“来源丢失、解析器/模式变化、时钟偏移、队列溢出、重复投递、提供商导出中断、漏报和归档不可读”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-8.10-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "8.10",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-8.10-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "8.10",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-8.10-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "8.10",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-8.10-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "8.10",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-8.10-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "8.10",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever endpoints, identity, applications, databases, network, cloud/SaaS, providers, collectors, archives, detections, and review records change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 终端、身份、应用、数据库、网络、云/SaaS、提供商、采集器、归档、检测和审阅记录 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-8.10-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "8.10",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Use healthy, silent, partial, late, malformed, duplicate, unowned, unreviewed, alerted, investigated, and archived sources or events to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 健康、静默、部分、迟到、畸形、重复、无责任人、未审阅、已告警、已调查和已归档来源或事件 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "8.11",
      "control": 8,
      "title_en": "Conduct Audit Log Reviews",
      "title_zh": "日志审阅",
      "first_ig": 2,
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Data",
      "security_function": "Detect",
      "patterns": [
        "telemetry"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [],
        "variables": [
          "M1"
        ],
        "metric_branches": 0,
        "has_assumptions": true,
        "has_procedural_review": false
      },
      "official_cadence_terms": [
        "weekly"
      ],
      "implementation_contract": {
        "en": {
          "scope": "Reviews cover risk-based detections, anomalies, source-health failures and human investigation of audit data at least weekly; the objective is a recorded decision and response, not opening a dashboard.",
          "build": "Create queries/rules and analyst procedures with owners, expected frequency, baselines, triage, escalation, tuning and closure.",
          "proof": "Inject benign canary anomalies and normal controls, then verify alert, analyst interpretation, evidence, disposition and response within SLO.",
          "boundary": "CAS only compares two review timestamps, so an empty or rubber-stamped review can pass."
        },
        "zh": {
          "scope": "至少每周审阅风险化检测、异常、源健康故障和人工调查，目标是有记录的判断与响应，不是打开 Dashboard。",
          "build": "为查询/规则和分析流程设责任人、频率、基线、分诊、升级、调优和关闭；适合的检测持续自动化，同时每周做有记录的覆盖审阅，包含失效源和未处理告警。",
          "proof": "注入无害异常金丝雀与正常对照，验证告警、分析解释、证据、处置和 SLO 内响应；抽查审阅质量与漏周期，跟踪精度、积压年龄、检测缺口和重复误报。",
          "boundary": "CAS 只比较两次审阅时间，空白或盖章审阅也能过。"
        }
      },
      "category_counts": {
        "outcome": 6,
        "scope": 6,
        "ownership": 6,
        "data": 6,
        "integration": 6,
        "control": 6,
        "timing": 6,
        "exception": 6,
        "evidence": 6,
        "security": 6,
        "testing": 6,
        "operations": 6
      },
      "requirement_count": 72,
      "requirements": [
        {
          "code": "CIS-8.11-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "8.11",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Conduct Audit Log Reviews; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“日志审阅”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-8.11-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "8.11",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 8.11, official Asset Class Data, Security Function Detect, and IG2 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 8.11、官方资产类别“数据”、安全功能“检测”和首次出现的 IG2，并保存来源抓取日期。"
        },
        {
          "code": "CIS-8.11-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "8.11",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Reviews cover risk-based detections, anomalies, source-health failures and human investigation of audit data at least weekly; the objective is a recorded decision and response, not opening a dashboard.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“至少每周审阅风险化检测、异常、源健康故障和人工调查，目标是有记录的判断与响应，不是打开 Dashboard。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-8.11-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "8.11",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-8.11-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "8.11",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Conduct Audit Log Reviews to its operating object—security-relevant events, actor and target identity, timestamps, decisions, outcomes, source health, retention, search, and custody—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“日志审阅”连接到其运营对象——安全相关事件、行为者与目标身份、时间、决策、结果、来源健康、保留、检索和证据保管——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-8.11-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "8.11",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "For Conduct Audit Log Reviews, express success as an observable decision over complete, attributable, timely, protected, searchable, and actionable security telemetry plus source health; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“日志审阅”，以 完整、可归因、及时、受保护、可检索、可行动的安全遥测及来源健康 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-8.11-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "8.11",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-8.11-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "8.11",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-8.11-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "8.11",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-8.11-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "8.11",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-8.11-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "8.11",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across missing fields, clock drift, parser failure, dropped events, duplicate delivery, pooled identities, privacy redaction, provider gaps, quota, and archive unreadability; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 字段缺失、时钟漂移、解析失败、事件丢失、重复投递、汇聚身份、隐私脱敏、提供商缺口、配额和归档不可读 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-8.11-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "8.11",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Include clock skew, actor loss, field truncation, parser drift, dropped or duplicate events, privacy redaction, provider gaps, encrypted paths, quota, and archive failure in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 时钟偏移、行为者丢失、字段截断、解析漂移、事件丢失或重复、隐私脱敏、提供商缺口、加密路径、配额和归档故障 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-8.11-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "8.11",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-8.11-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "8.11",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-8.11-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "8.11",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-8.11-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "8.11",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-8.11-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "8.11",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind source owners, platform and security engineering, detection teams, incident responders, privacy, records management, and auditors to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 来源责任人、平台与安全工程、检测团队、事件响应、隐私、档案管理和审计方 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-8.11-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "8.11",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Name who may transition event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-8.11-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "8.11",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-8.11-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "8.11",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-8.11-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "8.11",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (M1) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（M1）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-8.11-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "8.11",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-8.11-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "8.11",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the governed log-source inventory and evidence platform as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把受治理的日志源清单与证据平台作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-8.11-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "8.11",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired.",
          "zh": "对生命周期“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-8.11-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "8.11",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for no explicit predecessor in the pinned CAS page; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 固定 CAS 页面没有列出显式前置项 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-8.11-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "8.11",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-8.11-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "8.11",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-8.11-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "8.11",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-8.11-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "8.11",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile endpoints, identity, applications, databases, network, cloud/SaaS, providers, collectors, archives, detections, and review records and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 终端、身份、应用、数据库、网络、云/SaaS、提供商、采集器、归档、检测和审阅记录，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-8.11-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "8.11",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Require every connector carrying complete, attributable, timely, protected, searchable, and actionable security telemetry plus source health to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 完整、可归因、及时、受保护、可检索、可行动的安全遥测及来源健康 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-8.11-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "8.11",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Create queries/rules and analyst procedures with owners, expected frequency, baselines, triage, escalation, tuning and closure.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“为查询/规则和分析流程设责任人、频率、基线、分诊、升级、调优和关闭；适合的检测持续自动化，同时每周做有记录的覆盖审阅，包含失效源和未处理告警。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-8.11-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "8.11",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-8.11-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "8.11",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-8.11-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "8.11",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-8.11-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "8.11",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the governed log-source inventory and evidence platform and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在受治理的日志源清单与证据平台中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-8.11-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "8.11",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Implement the explicit state machine event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-8.11-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "8.11",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (weekly); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（weekly）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-8.11-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "8.11",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-8.11-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "8.11",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-8.11-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "8.11",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-8.11-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "8.11",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in security-relevant events, actor and target identity, timestamps, decisions, outcomes, source health, retention, search, and custody; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 安全相关事件、行为者与目标身份、时间、决策、结果、来源健康、保留、检索和证据保管 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-8.11-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "8.11",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired; alert before each deadline becomes overdue.",
          "zh": "为“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-8.11-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "8.11",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “CAS only compares two review timestamps, so an empty or rubber-stamped review can pass.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“CAS 只比较两次审阅时间，空白或盖章审阅也能过。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-8.11-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "8.11",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-8.11-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "8.11",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-8.11-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "8.11",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-8.11-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "8.11",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat missing fields, clock drift, parser failure, dropped events, duplicate delivery, pooled identities, privacy redaction, provider gaps, quota, and archive unreadability as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 字段缺失、时钟漂移、解析失败、事件丢失、重复投递、汇聚身份、隐私脱敏、提供商缺口、配额和归档不可读 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-8.11-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "8.11",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Treat clock skew, actor loss, field truncation, parser drift, dropped or duplicate events, privacy redaction, provider gaps, encrypted paths, quota, and archive failure as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 时钟偏移、行为者丢失、字段截断、解析漂移、事件丢失或重复、隐私脱敏、提供商缺口、加密路径、配额和归档故障 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-8.11-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "8.11",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Inject benign canary anomalies and normal controls, then verify alert, analyst interpretation, evidence, disposition and response within SLO.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“注入无害异常金丝雀与正常对照，验证告警、分析解释、证据、处置和 SLO 内响应；抽查审阅质量与漏周期，跟踪精度、积压年龄、检测缺口和重复误报。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-8.11-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "8.11",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-8.11-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "8.11",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 0 pinned CAS metric branch(es), 1 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 0 个指标分支、1 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-8.11-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "8.11",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-8.11-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "8.11",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the governed log-source inventory and evidence platform plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以受治理的日志源清单与证据平台和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-8.11-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "8.11",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Publish healthy, silent, partial, late, malformed, duplicate, unowned, unreviewed, alerted, investigated, and archived sources or events with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 健康、静默、部分、迟到、畸形、重复、无责任人、未审阅、已告警、已调查和已归档来源或事件，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-8.11-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "8.11",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-8.11-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "8.11",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-8.11-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "8.11",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-8.11-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "8.11",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-8.11-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "8.11",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the governed log-source inventory and evidence platform; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护受治理的日志源清单与证据平台的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-8.11-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "8.11",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Restrict authority to change event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-8.11-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "8.11",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-8.11-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "8.11",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-8.11-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "8.11",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-8.11-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "8.11",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-8.11-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "8.11",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise allowed and denied canary events, collector and parser failure, clock skew, retention boundary, archive restore, provider export loss, and analyst review through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 允许与拒绝的金丝雀事件、采集器与解析器故障、时钟偏移、保留边界、归档恢复、提供商导出丢失和分析员审阅，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-8.11-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "8.11",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Run the positive control an allowed and denied canary event traced from source through review; exercise negative, stale, duplicate, bypass, and outage controls including source loss, parser/schema change, time skew, queue overflow, duplicate delivery, provider export outage, missed alert, and unreadable archive.",
          "zh": "运行正向控制“一项允许与拒绝金丝雀事件从来源贯穿到审阅”，并执行包含“来源丢失、解析器/模式变化、时钟偏移、队列溢出、重复投递、提供商导出中断、漏报和归档不可读”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-8.11-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "8.11",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-8.11-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "8.11",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-8.11-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "8.11",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-8.11-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "8.11",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-8.11-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "8.11",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever endpoints, identity, applications, databases, network, cloud/SaaS, providers, collectors, archives, detections, and review records change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 终端、身份、应用、数据库、网络、云/SaaS、提供商、采集器、归档、检测和审阅记录 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-8.11-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "8.11",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Use healthy, silent, partial, late, malformed, duplicate, unowned, unreviewed, alerted, investigated, and archived sources or events to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 健康、静默、部分、迟到、畸形、重复、无责任人、未审阅、已告警、已调查和已归档来源或事件 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "8.12",
      "control": 8,
      "title_en": "Collect Service Provider Logs",
      "title_zh": "服务提供商日志",
      "first_ig": 3,
      "implementation_groups": [
        3
      ],
      "asset_class": "Data",
      "security_function": "Detect",
      "patterns": [
        "telemetry",
        "discovery",
        "supplier"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "4.1",
          "15.1"
        ],
        "variables": [
          "GV3",
          "GV29",
          "M1",
          "M2",
          "M3"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "Scope providers whose services can affect identity, data, infrastructure, software delivery or security, including cloud, SaaS, MSP/MSSP and critical suppliers.",
          "build": "Contract for log access, retention, clock, fields, incident availability and export; enable tenant audit, authentication/authorization, admin/support, data lifecycle and configuration events.",
          "proof": "Perform tenant actions and provider-supported admin/data events, trace them to the enterprise store and verify identity, time, completeness and latency.",
          "boundary": "Provider plans may charge for logs, omit support actions or retain them briefly."
        },
        "zh": {
          "scope": "包括能影响身份、数据、基础设施、软件交付或安全的云、SaaS、MSP/MSSP 与关键供应商。",
          "build": "合同约定日志访问、保留、时钟、字段、事件可用性和导出；启用租户认证/授权、管理/支持、数据生命周期和配置事件，经 API 或受保护存储拉取，监控缺口，并把关键证据保存在可能被攻陷的服务商之外。",
          "proof": "执行租户动作和可支持的管理/数据事件，追到企业存储，核验身份、时间、完整度与时延；停导出或耗尽 API 限额测试健康发现，并抽样比对服务商 Console 历史。",
          "boundary": "服务商套餐可能额外收费、缺少支持行为或保留很短，需要升级套餐，否则降低依赖或补偿。"
        }
      },
      "category_counts": {
        "outcome": 8,
        "scope": 8,
        "ownership": 8,
        "data": 8,
        "integration": 8,
        "control": 8,
        "timing": 8,
        "exception": 8,
        "evidence": 8,
        "security": 8,
        "testing": 8,
        "operations": 8
      },
      "requirement_count": 96,
      "requirements": [
        {
          "code": "CIS-8.12-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "8.12",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Collect Service Provider Logs; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“服务提供商日志”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-8.12-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "8.12",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 8.12, official Asset Class Data, Security Function Detect, and IG3 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 8.12、官方资产类别“数据”、安全功能“检测”和首次出现的 IG3，并保存来源抓取日期。"
        },
        {
          "code": "CIS-8.12-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "8.12",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Scope providers whose services can affect identity, data, infrastructure, software delivery or security, including cloud, SaaS, MSP/MSSP and critical suppliers.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“包括能影响身份、数据、基础设施、软件交付或安全的云、SaaS、MSP/MSSP 与关键供应商。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-8.12-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "8.12",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-8.12-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "8.12",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Collect Service Provider Logs to its operating object—security-relevant events, actor and target identity, timestamps, decisions, outcomes, source health, retention, search, and custody—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“服务提供商日志”连接到其运营对象——安全相关事件、行为者与目标身份、时间、决策、结果、来源健康、保留、检索和证据保管——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-8.12-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "8.12",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "For Collect Service Provider Logs, express success as an observable decision over complete, attributable, timely, protected, searchable, and actionable security telemetry plus source health; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“服务提供商日志”，以 完整、可归因、及时、受保护、可检索、可行动的安全遥测及来源健康 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-8.12-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "8.12",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "For Collect Service Provider Logs, express success as an observable decision over coverage of every intended discovery vantage point, source, job, parser, and reconciliation path; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“服务提供商日志”，以 所有预期发现视角、来源、任务、解析器和对账路径的覆盖 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-8.12-OUT-08",
          "local_code": "OUT-08",
          "display_code": "O08",
          "safeguard_id": "8.12",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "For Collect Service Provider Logs, express success as an observable decision over provider identity, supplied capability, data and privilege path, criticality, contract, assurance, tenant control, incident duty, dependency, and exit; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“服务提供商日志”，以 提供商身份、供应能力、数据与权限路径、关键度、合同、保证、租户控制、事件义务、依赖和退出 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-8.12-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "8.12",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-8.12-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "8.12",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-8.12-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "8.12",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-8.12-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "8.12",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-8.12-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "8.12",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across missing fields, clock drift, parser failure, dropped events, duplicate delivery, pooled identities, privacy redaction, provider gaps, quota, and archive unreadability; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 字段缺失、时钟漂移、解析失败、事件丢失、重复投递、汇聚身份、隐私脱敏、提供商缺口、配额和归档不可读 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-8.12-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "8.12",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Include clock skew, actor loss, field truncation, parser drift, dropped or duplicate events, privacy redaction, provider gaps, encrypted paths, quota, and archive failure in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 时钟偏移、行为者丢失、字段截断、解析漂移、事件丢失或重复、隐私脱敏、提供商缺口、加密路径、配额和归档故障 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-8.12-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "8.12",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Include unreachable zones, short-lived objects, blind spots, rate limits, credential failure, encrypted or proprietary protocols, and silent sensors in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 不可达区域、短生对象、盲区、限流、凭据失败、加密或专有协议和静默传感器 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-8.12-SCP-08",
          "local_code": "SCP-08",
          "display_code": "P08",
          "safeguard_id": "8.12",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Include shadow providers, subprocessors, acquisitions, click-through terms, plan limitations, shared responsibility, concentration, unavailable evidence, emergency support, and residual data in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 影子提供商、分处理方、收购、点击条款、套餐限制、共享责任、集中度、证据不可得、紧急支持和残余数据 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-8.12-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "8.12",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-8.12-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "8.12",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-8.12-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "8.12",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-8.12-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "8.12",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-8.12-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "8.12",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind source owners, platform and security engineering, detection teams, incident responders, privacy, records management, and auditors to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 来源责任人、平台与安全工程、检测团队、事件响应、隐私、档案管理和审计方 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-8.12-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "8.12",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Name who may transition event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-8.12-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "8.12",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Name who may transition scheduled → started → observed → normalized → reconciled → dispositioned, with explicit partial and failed states, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 计划 → 启动 → 观测 → 归一化 → 对账 → 处置，并显式保留部分与失败状态，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-8.12-OWN-08",
          "local_code": "OWN-08",
          "display_code": "W08",
          "safeguard_id": "8.12",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Name who may transition discovered → owned → classified → contracted → configured → evidenced/monitored → incident/exception → renewed or exited, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 发现 → 确认责任 → 分类 → 签约 → 配置 → 取证/监测 → 事件/例外 → 续约或退出，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-8.12-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "8.12",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-8.12-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "8.12",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-8.12-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "8.12",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV3, GV29, M1, M2, M3) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV3, GV29, M1, M2, M3）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-8.12-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "8.12",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-8.12-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "8.12",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the governed log-source inventory and evidence platform as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把受治理的日志源清单与证据平台作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-8.12-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "8.12",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired.",
          "zh": "对生命周期“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-8.12-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "8.12",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle scheduled → started → observed → normalized → reconciled → dispositioned, with explicit partial and failed states.",
          "zh": "对生命周期“计划 → 启动 → 观测 → 归一化 → 对账 → 处置，并显式保留部分与失败状态”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-8.12-DAT-08",
          "local_code": "DAT-08",
          "display_code": "D08",
          "safeguard_id": "8.12",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle discovered → owned → classified → contracted → configured → evidenced/monitored → incident/exception → renewed or exited.",
          "zh": "对生命周期“发现 → 确认责任 → 分类 → 签约 → 配置 → 取证/监测 → 事件/例外 → 续约或退出”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-8.12-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "8.12",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 4.1, Safeguard 15.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 4.1、Safeguard 15.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-8.12-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "8.12",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-8.12-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "8.12",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-8.12-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "8.12",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-8.12-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "8.12",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile endpoints, identity, applications, databases, network, cloud/SaaS, providers, collectors, archives, detections, and review records and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 终端、身份、应用、数据库、网络、云/SaaS、提供商、采集器、归档、检测和审阅记录，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-8.12-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "8.12",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Require every connector carrying complete, attributable, timely, protected, searchable, and actionable security telemetry plus source health to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 完整、可归因、及时、受保护、可检索、可行动的安全遥测及来源健康 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-8.12-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "8.12",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Require every connector carrying coverage of every intended discovery vantage point, source, job, parser, and reconciliation path to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 所有预期发现视角、来源、任务、解析器和对账路径的覆盖 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-8.12-INT-08",
          "local_code": "INT-08",
          "display_code": "I08",
          "safeguard_id": "8.12",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Require every connector carrying provider identity, supplied capability, data and privilege path, criticality, contract, assurance, tenant control, incident duty, dependency, and exit to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 提供商身份、供应能力、数据与权限路径、关键度、合同、保证、租户控制、事件义务、依赖和退出 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-8.12-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "8.12",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Contract for log access, retention, clock, fields, incident availability and export; enable tenant audit, authentication/authorization, admin/support, data lifecycle and configuration events.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“合同约定日志访问、保留、时钟、字段、事件可用性和导出；启用租户认证/授权、管理/支持、数据生命周期和配置事件，经 API 或受保护存储拉取，监控缺口，并把关键证据保存在可能被攻陷的服务商之外。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-8.12-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "8.12",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-8.12-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "8.12",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-8.12-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "8.12",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-8.12-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "8.12",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the governed log-source inventory and evidence platform and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在受治理的日志源清单与证据平台中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-8.12-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "8.12",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Implement the explicit state machine event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-8.12-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "8.12",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Implement the explicit state machine scheduled → started → observed → normalized → reconciled → dispositioned, with explicit partial and failed states; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“计划 → 启动 → 观测 → 归一化 → 对账 → 处置，并显式保留部分与失败状态”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-8.12-CTL-08",
          "local_code": "CTL-08",
          "display_code": "C08",
          "safeguard_id": "8.12",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Implement the explicit state machine discovered → owned → classified → contracted → configured → evidenced/monitored → incident/exception → renewed or exited; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“发现 → 确认责任 → 分类 → 签约 → 配置 → 取证/监测 → 事件/例外 → 续约或退出”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-8.12-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "8.12",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-8.12-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "8.12",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-8.12-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "8.12",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-8.12-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "8.12",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-8.12-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "8.12",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in security-relevant events, actor and target identity, timestamps, decisions, outcomes, source health, retention, search, and custody; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 安全相关事件、行为者与目标身份、时间、决策、结果、来源健康、保留、检索和证据保管 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-8.12-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "8.12",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired; alert before each deadline becomes overdue.",
          "zh": "为“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-8.12-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "8.12",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for scheduled → started → observed → normalized → reconciled → dispositioned, with explicit partial and failed states; alert before each deadline becomes overdue.",
          "zh": "为“计划 → 启动 → 观测 → 归一化 → 对账 → 处置，并显式保留部分与失败状态”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-8.12-TIM-08",
          "local_code": "TIM-08",
          "display_code": "T08",
          "safeguard_id": "8.12",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for discovered → owned → classified → contracted → configured → evidenced/monitored → incident/exception → renewed or exited; alert before each deadline becomes overdue.",
          "zh": "为“发现 → 确认责任 → 分类 → 签约 → 配置 → 取证/监测 → 事件/例外 → 续约或退出”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-8.12-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "8.12",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “Provider plans may charge for logs, omit support actions or retain them briefly.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“服务商套餐可能额外收费、缺少支持行为或保留很短，需要升级套餐，否则降低依赖或补偿。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-8.12-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "8.12",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-8.12-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "8.12",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-8.12-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "8.12",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-8.12-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "8.12",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat missing fields, clock drift, parser failure, dropped events, duplicate delivery, pooled identities, privacy redaction, provider gaps, quota, and archive unreadability as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 字段缺失、时钟漂移、解析失败、事件丢失、重复投递、汇聚身份、隐私脱敏、提供商缺口、配额和归档不可读 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-8.12-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "8.12",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Treat clock skew, actor loss, field truncation, parser drift, dropped or duplicate events, privacy redaction, provider gaps, encrypted paths, quota, and archive failure as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 时钟偏移、行为者丢失、字段截断、解析漂移、事件丢失或重复、隐私脱敏、提供商缺口、加密路径、配额和归档故障 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-8.12-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "8.12",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Treat unreachable zones, short-lived objects, blind spots, rate limits, credential failure, encrypted or proprietary protocols, and silent sensors as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 不可达区域、短生对象、盲区、限流、凭据失败、加密或专有协议和静默传感器 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-8.12-EXC-08",
          "local_code": "EXC-08",
          "display_code": "X08",
          "safeguard_id": "8.12",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Treat shadow providers, subprocessors, acquisitions, click-through terms, plan limitations, shared responsibility, concentration, unavailable evidence, emergency support, and residual data as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 影子提供商、分处理方、收购、点击条款、套餐限制、共享责任、集中度、证据不可得、紧急支持和残余数据 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-8.12-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "8.12",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Perform tenant actions and provider-supported admin/data events, trace them to the enterprise store and verify identity, time, completeness and latency.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“执行租户动作和可支持的管理/数据事件，追到企业存储，核验身份、时间、完整度与时延；停导出或耗尽 API 限额测试健康发现，并抽样比对服务商 Console 历史。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-8.12-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "8.12",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-8.12-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "8.12",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 5 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、5 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-8.12-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "8.12",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-8.12-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "8.12",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the governed log-source inventory and evidence platform plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以受治理的日志源清单与证据平台和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-8.12-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "8.12",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Publish healthy, silent, partial, late, malformed, duplicate, unowned, unreviewed, alerted, investigated, and archived sources or events with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 健康、静默、部分、迟到、畸形、重复、无责任人、未审阅、已告警、已调查和已归档来源或事件，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-8.12-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "8.12",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Publish scheduled, successful, partial, failed, stale, blind, newly discovered, unmatched, and reconciled observations with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 计划、成功、部分、失败、陈旧、盲区、新发现、未匹配和已对账观测，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-8.12-EVD-08",
          "local_code": "EVD-08",
          "display_code": "E08",
          "safeguard_id": "8.12",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Publish known, unknown, critical, unclassified, contract-gap, evidence-current, evidence-stale, tenant-misconfigured, incident, concentrated, and exit-incomplete providers with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已知、未知、关键、未分类、合同缺口、证据当前、证据过期、租户误配、事件、集中和退出不完整提供商，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-8.12-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "8.12",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-8.12-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "8.12",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-8.12-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "8.12",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-8.12-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "8.12",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-8.12-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "8.12",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the governed log-source inventory and evidence platform; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护受治理的日志源清单与证据平台的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-8.12-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "8.12",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Restrict authority to change event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-8.12-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "8.12",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Restrict authority to change scheduled → started → observed → normalized → reconciled → dispositioned, with explicit partial and failed states; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“计划 → 启动 → 观测 → 归一化 → 对账 → 处置，并显式保留部分与失败状态”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-8.12-SEC-08",
          "local_code": "SEC-08",
          "display_code": "S08",
          "safeguard_id": "8.12",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Restrict authority to change discovered → owned → classified → contracted → configured → evidenced/monitored → incident/exception → renewed or exited; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“发现 → 确认责任 → 分类 → 签约 → 配置 → 取证/监测 → 事件/例外 → 续约或退出”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-8.12-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "8.12",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-8.12-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "8.12",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-8.12-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "8.12",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-8.12-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "8.12",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-8.12-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "8.12",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise allowed and denied canary events, collector and parser failure, clock skew, retention boundary, archive restore, provider export loss, and analyst review through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 允许与拒绝的金丝雀事件、采集器与解析器故障、时钟偏移、保留边界、归档恢复、提供商导出丢失和分析员审阅，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-8.12-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "8.12",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Run the positive control an allowed and denied canary event traced from source through review; exercise negative, stale, duplicate, bypass, and outage controls including source loss, parser/schema change, time skew, queue overflow, duplicate delivery, provider export outage, missed alert, and unreadable archive.",
          "zh": "运行正向控制“一项允许与拒绝金丝雀事件从来源贯穿到审阅”，并执行包含“来源丢失、解析器/模式变化、时钟偏移、队列溢出、重复投递、提供商导出中断、漏报和归档不可读”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-8.12-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "8.12",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Run the positive control a known object visible from each representative vantage point; exercise negative, stale, duplicate, bypass, and outage controls including an unknown and short-lived object, failed credential, blocked scan, silent sensor, parser drift, and uncovered segment.",
          "zh": "运行正向控制“从每个代表性视角可见的一项已知对象”，并执行包含“未知与短生对象、凭据失败、扫描受阻、传感器静默、解析漂移和未覆盖网段”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-8.12-TST-08",
          "local_code": "TST-08",
          "display_code": "V08",
          "safeguard_id": "8.12",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Run the positive control an approved provider with tested tenant controls, current evidence, notification path, and exit artifact; exercise negative, stale, duplicate, bypass, and outage controls including a shadow provider, missing clause, stale attestation, misconfigured tenant, unavailable export, subprocessor change, provider incident, and residual data after exit.",
          "zh": "运行正向控制“一家具备已测试租户控制、当前证据、通知路径和退出制品的获批提供商”，并执行包含“影子提供商、条款缺失、证明过期、租户误配、导出不可用、分处理方变化、提供商事件和退出后残余数据”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-8.12-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "8.12",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-8.12-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "8.12",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-8.12-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "8.12",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-8.12-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "8.12",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-8.12-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "8.12",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever endpoints, identity, applications, databases, network, cloud/SaaS, providers, collectors, archives, detections, and review records change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 终端、身份、应用、数据库、网络、云/SaaS、提供商、采集器、归档、检测和审阅记录 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-8.12-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "8.12",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Use healthy, silent, partial, late, malformed, duplicate, unowned, unreviewed, alerted, investigated, and archived sources or events to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 健康、静默、部分、迟到、畸形、重复、无责任人、未审阅、已告警、已调查和已归档来源或事件 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-8.12-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "8.12",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Use scheduled, successful, partial, failed, stale, blind, newly discovered, unmatched, and reconciled observations to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 计划、成功、部分、失败、陈旧、盲区、新发现、未匹配和已对账观测 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-8.12-OPS-08",
          "local_code": "OPS-08",
          "display_code": "R08",
          "safeguard_id": "8.12",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Use known, unknown, critical, unclassified, contract-gap, evidence-current, evidence-stale, tenant-misconfigured, incident, concentrated, and exit-incomplete providers to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已知、未知、关键、未分类、合同缺口、证据当前、证据过期、租户误配、事件、集中和退出不完整提供商 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "9.1",
      "control": 9,
      "title_en": "Ensure Use of Only Fully Supported Browsers and Email Clients",
      "title_zh": "受支持的浏览器与邮件客户端",
      "first_ig": 1,
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Software",
      "security_function": "Protect",
      "patterns": [
        "network",
        "vulnerability",
        "software_dev"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "2.1"
        ],
        "variables": [
          "GV5",
          "M1",
          "M2",
          "M3",
          "M4",
          "M5"
        ],
        "metric_branches": 3,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "Include every browser engine, embedded webview and mail client that users or automation can execute, together with edition, channel, version and update status.",
          "build": "Standardize products and channels, auto-update through trusted rings, block unsupported or portable alternatives and monitor vendor lifecycle and emergency releases.",
          "proof": "Enumerate executing and installed versions, compare to authoritative current/support channels and launch an old portable copy as a negative control.",
          "boundary": "The CAS measures repeat contradictory supported/unsupported definitions, so its false-positive/negative ratios cannot be trusted verbatim."
        },
        "zh": {
          "scope": "包括用户或自动化可执行的每种浏览器引擎、嵌入 WebView 和邮件客户端，以及版本线、渠道、版本和更新状态。",
          "build": "统一产品/渠道，经可信分批自动更新，阻断不支持或便携替代，监控厂商生命周期与紧急发布。",
          "proof": "枚举安装与正在执行的版本，对照权威当前/支持渠道，并启动旧便携副本作负控；验证更新、重启/激活和阻断。",
          "boundary": "CAS 对 M2-M5 的受支持/不支持定义重复矛盾，误报漏报公式不可直接用。"
        }
      },
      "category_counts": {
        "outcome": 8,
        "scope": 8,
        "ownership": 8,
        "data": 8,
        "integration": 8,
        "control": 8,
        "timing": 8,
        "exception": 8,
        "evidence": 8,
        "security": 8,
        "testing": 8,
        "operations": 8
      },
      "requirement_count": 96,
      "requirements": [
        {
          "code": "CIS-9.1-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "9.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Ensure Use of Only Fully Supported Browsers and Email Clients; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“受支持的浏览器与邮件客户端”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-9.1-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "9.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 9.1, official Asset Class Software, Security Function Protect, and IG1 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 9.1、官方资产类别“软件”、安全功能“保护”和首次出现的 IG1，并保存来源抓取日期。"
        },
        {
          "code": "CIS-9.1-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "9.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Include every browser engine, embedded webview and mail client that users or automation can execute, together with edition, channel, version and update status.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“包括用户或自动化可执行的每种浏览器引擎、嵌入 WebView 和邮件客户端，以及版本线、渠道、版本和更新状态。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-9.1-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "9.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-9.1-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "9.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Ensure Use of Only Fully Supported Browsers and Email Clients to its operating object—browser, email, DNS, URL, extension, attachment, sender-authentication, and mail-malware decisions across user and service traffic—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“受支持的浏览器与邮件客户端”连接到其运营对象——浏览器、邮件、DNS、URL、扩展、附件、发件人认证及邮件恶意软件在用户与服务流量中的决策——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-9.1-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "9.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "For Ensure Use of Only Fully Supported Browsers and Email Clients, express success as an observable decision over intended connectivity, trust zone, route, protocol, identity, management path, traffic decision, and observed outcome; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“受支持的浏览器与邮件客户端”，以 预期连接、信任区、路由、协议、身份、管理路径、流量决策和观察结果 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-9.1-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "9.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "For Ensure Use of Only Fully Supported Browsers and Email Clients, express success as an observable decision over affected artifact identity, exploitability, business consequence, remediation choice, deployed fix, compensating control, and residual exposure; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“受支持的浏览器与邮件客户端”，以 受影响制品身份、可利用性、业务后果、修复选择、已部署修复、补偿控制和残余暴露 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-9.1-OUT-08",
          "local_code": "OUT-08",
          "display_code": "O08",
          "safeguard_id": "9.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "For Ensure Use of Only Fully Supported Browsers and Email Clients, express success as an observable decision over source-to-production software identity, design invariant, component trust, build provenance, test result, deployment state, runtime outcome, and vulnerability response; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“受支持的浏览器与邮件客户端”，以 从源码到生产的软件身份、设计不变量、组件信任、构建来源、测试结果、部署状态、运行结果和漏洞响应 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-9.1-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "9.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-9.1-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "9.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-9.1-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "9.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-9.1-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "9.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-9.1-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "9.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across remote devices, encrypted DNS, QUIC, direct IPs, forwarding, mailing lists, nested or encrypted attachments, shared hosting, extensions, and alternate connectors; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 远程设备、加密 DNS、QUIC、直连 IP、转发、邮件列表、嵌套或加密附件、共享托管、扩展和备用连接器 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-9.1-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "9.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Include IPv6, overlays, east-west paths, remote and roaming devices, direct egress, alternate resolvers, QUIC, asymmetric routes, provider abstraction, and emergency consoles in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 IPv6、覆盖网络、东西向路径、远程与漫游设备、直接出口、替代解析器、QUIC、非对称路由、提供商抽象和紧急控制台 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-9.1-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "9.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Include unknown versions, false positives, unavailable fixes, vendor lag, ephemeral workloads, unscannable platforms, inherited dependencies, mitigation-only states, and recurrence in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 未知版本、误报、无可用修复、厂商滞后、短生工作负载、不可扫描平台、继承依赖、仅缓解状态和复发 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-9.1-SCP-08",
          "local_code": "SCP-08",
          "display_code": "P08",
          "safeguard_id": "9.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Include generated and copied code, forks, vendoring, transitive dependencies, mutable tags, build plugins, feature flags, tenant logic, secrets, emergency release, and provider components in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 生成与复制代码、分叉、vendoring、传递依赖、可变标签、构建插件、功能开关、租户逻辑、秘密、紧急发布和提供商组件 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-9.1-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "9.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-9.1-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "9.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-9.1-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "9.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-9.1-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "9.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-9.1-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "9.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind messaging and endpoint owners, network and email engineering, security operations, identity, privacy, and business workflow owners to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 消息与终端责任人、网络与邮件工程、安全运营、身份、隐私和业务流程责任人 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-9.1-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "9.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Name who may transition requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-9.1-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "9.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Name who may transition discovered → validated → prioritized → assigned → fixed/mitigated/excepted → deployed → retested → closed/reopened, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 发现 → 验证 → 定级 → 分派 → 修复/缓解/例外 → 部署 → 复测 → 关闭/重开，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-9.1-OWN-08",
          "local_code": "OWN-08",
          "display_code": "W08",
          "safeguard_id": "9.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Name who may transition designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-9.1-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "9.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-9.1-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "9.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-9.1-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "9.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV5, M1, M2, M3, M4, M5) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV5, M1, M2, M3, M4, M5）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-9.1-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "9.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-9.1-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "9.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the governed browser, mail, resolver, gateway, and exception policy set as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把受治理的浏览器、邮件、解析器、网关与例外策略集合作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-9.1-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "9.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired.",
          "zh": "对生命周期“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-9.1-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "9.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle discovered → validated → prioritized → assigned → fixed/mitigated/excepted → deployed → retested → closed/reopened.",
          "zh": "对生命周期“发现 → 验证 → 定级 → 分派 → 修复/缓解/例外 → 部署 → 复测 → 关闭/重开”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-9.1-DAT-08",
          "local_code": "DAT-08",
          "display_code": "D08",
          "safeguard_id": "9.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired.",
          "zh": "对生命周期“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-9.1-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "9.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 2.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 2.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-9.1-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "9.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-9.1-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "9.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-9.1-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "9.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-9.1-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "9.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile browser/MDM policy, mail tenants and gateways, DNS resolvers, secure web gateways, extension inventories, DMARC reports, endpoint telemetry, and provider logs and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 浏览器/MDM 策略、邮件租户与网关、DNS 解析器、安全 Web 网关、扩展清单、DMARC 报告、终端遥测和提供商日志，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-9.1-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "9.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Require every connector carrying intended connectivity, trust zone, route, protocol, identity, management path, traffic decision, and observed outcome to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 预期连接、信任区、路由、协议、身份、管理路径、流量决策和观察结果 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-9.1-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "9.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Require every connector carrying affected artifact identity, exploitability, business consequence, remediation choice, deployed fix, compensating control, and residual exposure to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 受影响制品身份、可利用性、业务后果、修复选择、已部署修复、补偿控制和残余暴露 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-9.1-INT-08",
          "local_code": "INT-08",
          "display_code": "I08",
          "safeguard_id": "9.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Require every connector carrying source-to-production software identity, design invariant, component trust, build provenance, test result, deployment state, runtime outcome, and vulnerability response to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 从源码到生产的软件身份、设计不变量、组件信任、构建来源、测试结果、部署状态、运行结果和漏洞响应 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-9.1-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "9.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Standardize products and channels, auto-update through trusted rings, block unsupported or portable alternatives and monitor vendor lifecycle and emergency releases.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“统一产品/渠道，经可信分批自动更新，阻断不支持或便携替代，监控厂商生命周期与紧急发布。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-9.1-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "9.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-9.1-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "9.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-9.1-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "9.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-9.1-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "9.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the governed browser, mail, resolver, gateway, and exception policy set and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在受治理的浏览器、邮件、解析器、网关与例外策略集合中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-9.1-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "9.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Implement the explicit state machine requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-9.1-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "9.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Implement the explicit state machine discovered → validated → prioritized → assigned → fixed/mitigated/excepted → deployed → retested → closed/reopened; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“发现 → 验证 → 定级 → 分派 → 修复/缓解/例外 → 部署 → 复测 → 关闭/重开”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-9.1-CTL-08",
          "local_code": "CTL-08",
          "display_code": "C08",
          "safeguard_id": "9.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Implement the explicit state machine designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-9.1-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "9.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-9.1-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "9.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-9.1-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "9.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-9.1-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "9.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-9.1-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "9.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in browser, email, DNS, URL, extension, attachment, sender-authentication, and mail-malware decisions across user and service traffic; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 浏览器、邮件、DNS、URL、扩展、附件、发件人认证及邮件恶意软件在用户与服务流量中的决策 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-9.1-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "9.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; alert before each deadline becomes overdue.",
          "zh": "为“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-9.1-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "9.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for discovered → validated → prioritized → assigned → fixed/mitigated/excepted → deployed → retested → closed/reopened; alert before each deadline becomes overdue.",
          "zh": "为“发现 → 验证 → 定级 → 分派 → 修复/缓解/例外 → 部署 → 复测 → 关闭/重开”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-9.1-TIM-08",
          "local_code": "TIM-08",
          "display_code": "T08",
          "safeguard_id": "9.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; alert before each deadline becomes overdue.",
          "zh": "为“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-9.1-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "9.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “The CAS measures repeat contradictory supported/unsupported definitions, so its false-positive/negative ratios cannot be trusted verbatim.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“CAS 对 M2-M5 的受支持/不支持定义重复矛盾，误报漏报公式不可直接用。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-9.1-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "9.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-9.1-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "9.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-9.1-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "9.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-9.1-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "9.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat remote devices, encrypted DNS, QUIC, direct IPs, forwarding, mailing lists, nested or encrypted attachments, shared hosting, extensions, and alternate connectors as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 远程设备、加密 DNS、QUIC、直连 IP、转发、邮件列表、嵌套或加密附件、共享托管、扩展和备用连接器 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-9.1-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "9.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Treat IPv6, overlays, east-west paths, remote and roaming devices, direct egress, alternate resolvers, QUIC, asymmetric routes, provider abstraction, and emergency consoles as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 IPv6、覆盖网络、东西向路径、远程与漫游设备、直接出口、替代解析器、QUIC、非对称路由、提供商抽象和紧急控制台 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-9.1-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "9.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Treat unknown versions, false positives, unavailable fixes, vendor lag, ephemeral workloads, unscannable platforms, inherited dependencies, mitigation-only states, and recurrence as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 未知版本、误报、无可用修复、厂商滞后、短生工作负载、不可扫描平台、继承依赖、仅缓解状态和复发 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-9.1-EXC-08",
          "local_code": "EXC-08",
          "display_code": "X08",
          "safeguard_id": "9.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Treat generated and copied code, forks, vendoring, transitive dependencies, mutable tags, build plugins, feature flags, tenant logic, secrets, emergency release, and provider components as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 生成与复制代码、分叉、vendoring、传递依赖、可变标签、构建插件、功能开关、租户逻辑、秘密、紧急发布和提供商组件 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-9.1-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "9.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Enumerate executing and installed versions, compare to authoritative current/support channels and launch an old portable copy as a negative control.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“枚举安装与正在执行的版本，对照权威当前/支持渠道，并启动旧便携副本作负控；验证更新、重启/激活和阻断。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-9.1-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "9.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-9.1-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "9.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 3 pinned CAS metric branch(es), 6 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 3 个指标分支、6 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-9.1-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "9.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-9.1-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "9.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the governed browser, mail, resolver, gateway, and exception policy set plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以受治理的浏览器、邮件、解析器、网关与例外策略集合和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-9.1-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "9.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Publish known, unknown, allowed, denied, shadow, bypassed, asymmetric, stale-rule, exception, and unobserved paths with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已知、未知、允许、拒绝、影子、绕过、非对称、陈旧规则、例外和未观测路径，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-9.1-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "9.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Publish open, validated, false-positive, overdue, mitigated, excepted, deployed-unverified, retest-failed, reopened, and exposure-weighted findings with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 开放、已验证、误报、逾期、已缓解、例外、已部署未验证、复测失败、重开和暴露加权发现，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-9.1-EVD-08",
          "local_code": "EVD-08",
          "display_code": "E08",
          "safeguard_id": "9.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Publish reviewed, unreviewed, reproducible, provenance-bound, vulnerable, test-failed, exception, deployed-unverified, drifted, rolled-back, and regression-protected releases with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已评审、未评审、可复现、来源绑定、存在漏洞、测试失败、例外、已部署未验证、漂移、已回滚和受回归保护发布物，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-9.1-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "9.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-9.1-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "9.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-9.1-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "9.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-9.1-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "9.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-9.1-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "9.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the governed browser, mail, resolver, gateway, and exception policy set; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护受治理的浏览器、邮件、解析器、网关与例外策略集合的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-9.1-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "9.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Restrict authority to change requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-9.1-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "9.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Restrict authority to change discovered → validated → prioritized → assigned → fixed/mitigated/excepted → deployed → retested → closed/reopened; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“发现 → 验证 → 定级 → 分派 → 修复/缓解/例外 → 部署 → 复测 → 关闭/重开”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-9.1-SEC-08",
          "local_code": "SEC-08",
          "display_code": "S08",
          "safeguard_id": "9.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Restrict authority to change designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-9.1-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "9.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-9.1-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "9.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-9.1-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "9.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-9.1-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "9.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-9.1-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "9.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise allowed and blocked destinations, spoofed and aligned mail, benign and dangerous file fixtures, extension permission changes, bypass paths, and provider outage through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 允许与阻断目的地、伪造与对齐邮件、安全与危险文件样本、扩展权限变化、绕过路径和提供商中断，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-9.1-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "9.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Run the positive control an approved flow over the required secure management or business path; exercise negative, stale, duplicate, bypass, and outage controls including an unapproved route, protocol downgrade, direct egress, alternate DNS/QUIC path, segmentation bypass, AAA loss, stale rule, and rollback failure.",
          "zh": "运行正向控制“通过规定安全管理或业务路径的一项获批流量”，并执行包含“未批准路由、协议降级、直接出口、替代 DNS/QUIC 路径、分段绕过、AAA 丢失、陈旧规则和回滚失败”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-9.1-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "9.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Run the positive control a known vulnerable artifact repaired and independently retested; exercise negative, stale, duplicate, bypass, and outage controls including credential failure, wrong version match, unavailable fix, mitigation bypass, failed deployment, rollback, recurring finding, and exposed unowned asset.",
          "zh": "运行正向控制“一项已知漏洞制品完成修复并独立复测”，并执行包含“凭据失败、版本误配、无可用修复、缓解绕过、部署失败、回滚、问题复发和外露无主资产”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-9.1-TST-08",
          "local_code": "TST-08",
          "display_code": "V08",
          "safeguard_id": "9.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Run the positive control a trusted build that preserves the security invariant through deployment and runtime; exercise negative, stale, duplicate, bypass, and outage controls including a substituted dependency, unreviewed change, poisoned build input, failed security test, bypass path, vulnerable release, rollback, and regression.",
          "zh": "运行正向控制“一个把安全不变量贯穿部署与运行的可信构建”，并执行包含“依赖替换、未评审变更、构建输入污染、安全测试失败、绕过路径、漏洞发布、回滚和回归”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-9.1-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "9.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-9.1-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "9.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-9.1-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "9.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-9.1-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "9.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-9.1-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "9.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever browser/MDM policy, mail tenants and gateways, DNS resolvers, secure web gateways, extension inventories, DMARC reports, endpoint telemetry, and provider logs change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 浏览器/MDM 策略、邮件租户与网关、DNS 解析器、安全 Web 网关、扩展清单、DMARC 报告、终端遥测和提供商日志 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-9.1-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "9.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Use known, unknown, allowed, denied, shadow, bypassed, asymmetric, stale-rule, exception, and unobserved paths to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已知、未知、允许、拒绝、影子、绕过、非对称、陈旧规则、例外和未观测路径 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-9.1-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "9.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Use open, validated, false-positive, overdue, mitigated, excepted, deployed-unverified, retest-failed, reopened, and exposure-weighted findings to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 开放、已验证、误报、逾期、已缓解、例外、已部署未验证、复测失败、重开和暴露加权发现 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-9.1-OPS-08",
          "local_code": "OPS-08",
          "display_code": "R08",
          "safeguard_id": "9.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Use reviewed, unreviewed, reproducible, provenance-bound, vulnerable, test-failed, exception, deployed-unverified, drifted, rolled-back, and regression-protected releases to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已评审、未评审、可复现、来源绑定、存在漏洞、测试失败、例外、已部署未验证、漂移、已回滚和受回归保护发布物 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "9.2",
      "control": 9,
      "title_en": "Use DNS Filtering Services",
      "title_zh": "DNS 恶意域名过滤",
      "first_ig": 1,
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Devices",
      "security_function": "Protect",
      "patterns": [
        "network"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "1.1",
          "4.1"
        ],
        "variables": [
          "GV1",
          "GV3",
          "GV5",
          "M1",
          "M2",
          "M3"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "Cover all end-user devices on-premises, remote and roaming, across IPv4/IPv6, VPN, browsers/applications using encrypted DNS and offline transition.",
          "build": "Enforce an approved security resolver or local agent, authenticate encrypted resolution, prevent unauthorized bypass and define category, threat-feed, exception and fail-open/closed policy.",
          "proof": "Query benign, malicious-test, newly registered or policy-blocked and allowed-exception domains through system, browser DoH, VPN and direct resolver paths.",
          "boundary": "Caching, hard-coded IPs, DNS over HTTPS, privacy relays and captive portals bypass ordinary settings."
        },
        "zh": {
          "scope": "覆盖所有内网、远程、漫游终端的 IPv4/IPv6、VPN，以及使用加密 DNS 的浏览器/应用和离线切换。",
          "build": "强制批准的安全解析器或本地 Agent，认证加密解析，防未授权绕过，并定义分类、威胁 Feed、例外和 Fail-open/closed；绑定用户/设备日志，保留带当前策略的受保护备用解析器。",
          "proof": "经系统、浏览器 DoH、VPN 和直连路径查询正常、恶意测试、新注册/策略拦截与例外域，验证动作、阻断页、日志、更新新鲜度和故障行为；覆盖率看实际路径。",
          "boundary": "缓存、硬编码 IP、DoH、隐私 Relay 和 Captive Portal 会绕开设置。"
        }
      },
      "category_counts": {
        "outcome": 6,
        "scope": 6,
        "ownership": 6,
        "data": 6,
        "integration": 6,
        "control": 6,
        "timing": 6,
        "exception": 6,
        "evidence": 6,
        "security": 6,
        "testing": 6,
        "operations": 6
      },
      "requirement_count": 72,
      "requirements": [
        {
          "code": "CIS-9.2-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "9.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Use DNS Filtering Services; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“DNS 恶意域名过滤”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-9.2-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "9.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 9.2, official Asset Class Devices, Security Function Protect, and IG1 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 9.2、官方资产类别“设备”、安全功能“保护”和首次出现的 IG1，并保存来源抓取日期。"
        },
        {
          "code": "CIS-9.2-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "9.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Cover all end-user devices on-premises, remote and roaming, across IPv4/IPv6, VPN, browsers/applications using encrypted DNS and offline transition.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“覆盖所有内网、远程、漫游终端的 IPv4/IPv6、VPN，以及使用加密 DNS 的浏览器/应用和离线切换。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-9.2-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "9.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-9.2-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "9.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Use DNS Filtering Services to its operating object—browser, email, DNS, URL, extension, attachment, sender-authentication, and mail-malware decisions across user and service traffic—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“DNS 恶意域名过滤”连接到其运营对象——浏览器、邮件、DNS、URL、扩展、附件、发件人认证及邮件恶意软件在用户与服务流量中的决策——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-9.2-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "9.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "For Use DNS Filtering Services, express success as an observable decision over intended connectivity, trust zone, route, protocol, identity, management path, traffic decision, and observed outcome; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“DNS 恶意域名过滤”，以 预期连接、信任区、路由、协议、身份、管理路径、流量决策和观察结果 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-9.2-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "9.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-9.2-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "9.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-9.2-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "9.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-9.2-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "9.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-9.2-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "9.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across remote devices, encrypted DNS, QUIC, direct IPs, forwarding, mailing lists, nested or encrypted attachments, shared hosting, extensions, and alternate connectors; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 远程设备、加密 DNS、QUIC、直连 IP、转发、邮件列表、嵌套或加密附件、共享托管、扩展和备用连接器 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-9.2-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "9.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Include IPv6, overlays, east-west paths, remote and roaming devices, direct egress, alternate resolvers, QUIC, asymmetric routes, provider abstraction, and emergency consoles in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 IPv6、覆盖网络、东西向路径、远程与漫游设备、直接出口、替代解析器、QUIC、非对称路由、提供商抽象和紧急控制台 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-9.2-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "9.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-9.2-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "9.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-9.2-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "9.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-9.2-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "9.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-9.2-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "9.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind messaging and endpoint owners, network and email engineering, security operations, identity, privacy, and business workflow owners to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 消息与终端责任人、网络与邮件工程、安全运营、身份、隐私和业务流程责任人 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-9.2-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "9.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Name who may transition requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-9.2-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "9.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-9.2-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "9.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-9.2-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "9.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV1, GV3, GV5, M1, M2, M3) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV1, GV3, GV5, M1, M2, M3）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-9.2-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "9.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-9.2-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "9.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the governed browser, mail, resolver, gateway, and exception policy set as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把受治理的浏览器、邮件、解析器、网关与例外策略集合作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-9.2-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "9.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired.",
          "zh": "对生命周期“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-9.2-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "9.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 1.1, Safeguard 4.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 1.1、Safeguard 4.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-9.2-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "9.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-9.2-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "9.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-9.2-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "9.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-9.2-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "9.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile browser/MDM policy, mail tenants and gateways, DNS resolvers, secure web gateways, extension inventories, DMARC reports, endpoint telemetry, and provider logs and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 浏览器/MDM 策略、邮件租户与网关、DNS 解析器、安全 Web 网关、扩展清单、DMARC 报告、终端遥测和提供商日志，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-9.2-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "9.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Require every connector carrying intended connectivity, trust zone, route, protocol, identity, management path, traffic decision, and observed outcome to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 预期连接、信任区、路由、协议、身份、管理路径、流量决策和观察结果 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-9.2-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "9.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Enforce an approved security resolver or local agent, authenticate encrypted resolution, prevent unauthorized bypass and define category, threat-feed, exception and fail-open/closed policy.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“强制批准的安全解析器或本地 Agent，认证加密解析，防未授权绕过，并定义分类、威胁 Feed、例外和 Fail-open/closed；绑定用户/设备日志，保留带当前策略的受保护备用解析器。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-9.2-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "9.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-9.2-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "9.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-9.2-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "9.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-9.2-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "9.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the governed browser, mail, resolver, gateway, and exception policy set and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在受治理的浏览器、邮件、解析器、网关与例外策略集合中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-9.2-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "9.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Implement the explicit state machine requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-9.2-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "9.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-9.2-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "9.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-9.2-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "9.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-9.2-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "9.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-9.2-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "9.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in browser, email, DNS, URL, extension, attachment, sender-authentication, and mail-malware decisions across user and service traffic; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 浏览器、邮件、DNS、URL、扩展、附件、发件人认证及邮件恶意软件在用户与服务流量中的决策 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-9.2-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "9.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; alert before each deadline becomes overdue.",
          "zh": "为“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-9.2-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "9.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “Caching, hard-coded IPs, DNS over HTTPS, privacy relays and captive portals bypass ordinary settings.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“缓存、硬编码 IP、DoH、隐私 Relay 和 Captive Portal 会绕开设置。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-9.2-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "9.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-9.2-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "9.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-9.2-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "9.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-9.2-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "9.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat remote devices, encrypted DNS, QUIC, direct IPs, forwarding, mailing lists, nested or encrypted attachments, shared hosting, extensions, and alternate connectors as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 远程设备、加密 DNS、QUIC、直连 IP、转发、邮件列表、嵌套或加密附件、共享托管、扩展和备用连接器 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-9.2-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "9.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Treat IPv6, overlays, east-west paths, remote and roaming devices, direct egress, alternate resolvers, QUIC, asymmetric routes, provider abstraction, and emergency consoles as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 IPv6、覆盖网络、东西向路径、远程与漫游设备、直接出口、替代解析器、QUIC、非对称路由、提供商抽象和紧急控制台 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-9.2-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "9.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Query benign, malicious-test, newly registered or policy-blocked and allowed-exception domains through system, browser DoH, VPN and direct resolver paths.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“经系统、浏览器 DoH、VPN 和直连路径查询正常、恶意测试、新注册/策略拦截与例外域，验证动作、阻断页、日志、更新新鲜度和故障行为；覆盖率看实际路径。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-9.2-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "9.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-9.2-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "9.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 6 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、6 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-9.2-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "9.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-9.2-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "9.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the governed browser, mail, resolver, gateway, and exception policy set plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以受治理的浏览器、邮件、解析器、网关与例外策略集合和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-9.2-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "9.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Publish known, unknown, allowed, denied, shadow, bypassed, asymmetric, stale-rule, exception, and unobserved paths with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已知、未知、允许、拒绝、影子、绕过、非对称、陈旧规则、例外和未观测路径，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-9.2-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "9.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-9.2-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "9.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-9.2-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "9.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-9.2-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "9.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-9.2-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "9.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the governed browser, mail, resolver, gateway, and exception policy set; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护受治理的浏览器、邮件、解析器、网关与例外策略集合的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-9.2-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "9.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Restrict authority to change requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-9.2-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "9.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-9.2-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "9.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-9.2-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "9.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-9.2-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "9.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-9.2-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "9.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise allowed and blocked destinations, spoofed and aligned mail, benign and dangerous file fixtures, extension permission changes, bypass paths, and provider outage through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 允许与阻断目的地、伪造与对齐邮件、安全与危险文件样本、扩展权限变化、绕过路径和提供商中断，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-9.2-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "9.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Run the positive control an approved flow over the required secure management or business path; exercise negative, stale, duplicate, bypass, and outage controls including an unapproved route, protocol downgrade, direct egress, alternate DNS/QUIC path, segmentation bypass, AAA loss, stale rule, and rollback failure.",
          "zh": "运行正向控制“通过规定安全管理或业务路径的一项获批流量”，并执行包含“未批准路由、协议降级、直接出口、替代 DNS/QUIC 路径、分段绕过、AAA 丢失、陈旧规则和回滚失败”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-9.2-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "9.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-9.2-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "9.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-9.2-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "9.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-9.2-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "9.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-9.2-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "9.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever browser/MDM policy, mail tenants and gateways, DNS resolvers, secure web gateways, extension inventories, DMARC reports, endpoint telemetry, and provider logs change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 浏览器/MDM 策略、邮件租户与网关、DNS 解析器、安全 Web 网关、扩展清单、DMARC 报告、终端遥测和提供商日志 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-9.2-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "9.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Use known, unknown, allowed, denied, shadow, bypassed, asymmetric, stale-rule, exception, and unobserved paths to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已知、未知、允许、拒绝、影子、绕过、非对称、陈旧规则、例外和未观测路径 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "9.3",
      "control": 9,
      "title_en": "Maintain and Enforce Network-Based URL Filters",
      "title_zh": "网络 URL 过滤",
      "first_ig": 2,
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Network",
      "security_function": "Protect",
      "patterns": [
        "network",
        "enforcement"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "1.1",
          "2.1",
          "4.1"
        ],
        "variables": [
          "GV1",
          "GV3",
          "GV5",
          "M1",
          "M2",
          "M3"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "Scope enterprise web traffic across office, remote, mobile, cloud workloads and applications, including HTTP(S), QUIC and alternate proxy paths.",
          "build": "Deploy secure web gateway/proxy, endpoint or network policy with continuously updated intelligence, authenticated user/device context, controlled exceptions and direct-egress prevention.",
          "proof": "Request approved, blocked, newly categorized, direct-IP, encoded, redirect and QUIC destinations from representative paths.",
          "boundary": "TLS pinning, end-to-end apps, CDNs and shared hosting limit URL inspection and can make IP blocking unsafe."
        },
        "zh": {
          "scope": "覆盖办公、远程、移动、云工作负载和应用的 Web 流量，包括 HTTP(S)、QUIC 与备用代理路径。",
          "build": "部署安全 Web 网关、代理、终端或网络策略，持续更新情报，绑定身份/设备，控制例外并阻断直出。",
          "proof": "从代表路径请求允许、被拦、新分类、直连 IP、编码、重定向和 QUIC 目的，验证业务、日志、证书/隐私、更新健康和例外到期；分别报告路径覆盖与绕过。",
          "boundary": "TLS Pin、端到端应用、CDN 和共享托管限制 URL 检查，按 IP 拦可能危险。"
        }
      },
      "category_counts": {
        "outcome": 7,
        "scope": 7,
        "ownership": 7,
        "data": 7,
        "integration": 7,
        "control": 7,
        "timing": 7,
        "exception": 7,
        "evidence": 7,
        "security": 7,
        "testing": 7,
        "operations": 7
      },
      "requirement_count": 84,
      "requirements": [
        {
          "code": "CIS-9.3-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "9.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Maintain and Enforce Network-Based URL Filters; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“网络 URL 过滤”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-9.3-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "9.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 9.3, official Asset Class Network, Security Function Protect, and IG2 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 9.3、官方资产类别“网络”、安全功能“保护”和首次出现的 IG2，并保存来源抓取日期。"
        },
        {
          "code": "CIS-9.3-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "9.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Scope enterprise web traffic across office, remote, mobile, cloud workloads and applications, including HTTP(S), QUIC and alternate proxy paths.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“覆盖办公、远程、移动、云工作负载和应用的 Web 流量，包括 HTTP(S)、QUIC 与备用代理路径。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-9.3-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "9.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-9.3-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "9.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Maintain and Enforce Network-Based URL Filters to its operating object—browser, email, DNS, URL, extension, attachment, sender-authentication, and mail-malware decisions across user and service traffic—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“网络 URL 过滤”连接到其运营对象——浏览器、邮件、DNS、URL、扩展、附件、发件人认证及邮件恶意软件在用户与服务流量中的决策——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-9.3-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "9.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "For Maintain and Enforce Network-Based URL Filters, express success as an observable decision over intended connectivity, trust zone, route, protocol, identity, management path, traffic decision, and observed outcome; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“网络 URL 过滤”，以 预期连接、信任区、路由、协议、身份、管理路径、流量决策和观察结果 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-9.3-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "9.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "For Maintain and Enforce Network-Based URL Filters, express success as an observable decision over an enforceable allow, deny, contain, quarantine, require, remove, or transform decision at the closest reliable control point; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“网络 URL 过滤”，以 在最近可靠控制点执行允许、拒绝、遏制、隔离、强制、移除或转换决策 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-9.3-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "9.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-9.3-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "9.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-9.3-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "9.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-9.3-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "9.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-9.3-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "9.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across remote devices, encrypted DNS, QUIC, direct IPs, forwarding, mailing lists, nested or encrypted attachments, shared hosting, extensions, and alternate connectors; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 远程设备、加密 DNS、QUIC、直连 IP、转发、邮件列表、嵌套或加密附件、共享托管、扩展和备用连接器 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-9.3-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "9.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Include IPv6, overlays, east-west paths, remote and roaming devices, direct egress, alternate resolvers, QUIC, asymmetric routes, provider abstraction, and emergency consoles in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 IPv6、覆盖网络、东西向路径、远程与漫游设备、直接出口、替代解析器、QUIC、非对称路由、提供商抽象和紧急控制台 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-9.3-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "9.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Include audit-only mode, unsupported platforms, local overrides, race conditions, cached state, alternate paths, fail-open behavior, and emergency bypass in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 仅审计模式、不支持平台、本地覆盖、竞态、缓存状态、替代路径、故障开放和紧急绕过 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-9.3-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "9.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-9.3-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "9.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-9.3-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "9.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-9.3-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "9.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-9.3-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "9.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind messaging and endpoint owners, network and email engineering, security operations, identity, privacy, and business workflow owners to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 消息与终端责任人、网络与邮件工程、安全运营、身份、隐私和业务流程责任人 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-9.3-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "9.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Name who may transition requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-9.3-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "9.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Name who may transition observe → evaluate → decide → enforce → verify outcome → rollback/close, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-9.3-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "9.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-9.3-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "9.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-9.3-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "9.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV1, GV3, GV5, M1, M2, M3) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV1, GV3, GV5, M1, M2, M3）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-9.3-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "9.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-9.3-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "9.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the governed browser, mail, resolver, gateway, and exception policy set as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把受治理的浏览器、邮件、解析器、网关与例外策略集合作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-9.3-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "9.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired.",
          "zh": "对生命周期“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-9.3-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "9.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle observe → evaluate → decide → enforce → verify outcome → rollback/close.",
          "zh": "对生命周期“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-9.3-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "9.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 1.1, Safeguard 2.1, Safeguard 4.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 1.1、Safeguard 2.1、Safeguard 4.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-9.3-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "9.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-9.3-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "9.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-9.3-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "9.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-9.3-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "9.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile browser/MDM policy, mail tenants and gateways, DNS resolvers, secure web gateways, extension inventories, DMARC reports, endpoint telemetry, and provider logs and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 浏览器/MDM 策略、邮件租户与网关、DNS 解析器、安全 Web 网关、扩展清单、DMARC 报告、终端遥测和提供商日志，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-9.3-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "9.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Require every connector carrying intended connectivity, trust zone, route, protocol, identity, management path, traffic decision, and observed outcome to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 预期连接、信任区、路由、协议、身份、管理路径、流量决策和观察结果 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-9.3-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "9.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Require every connector carrying an enforceable allow, deny, contain, quarantine, require, remove, or transform decision at the closest reliable control point to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 在最近可靠控制点执行允许、拒绝、遏制、隔离、强制、移除或转换决策 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-9.3-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "9.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Deploy secure web gateway/proxy, endpoint or network policy with continuously updated intelligence, authenticated user/device context, controlled exceptions and direct-egress prevention.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“部署安全 Web 网关、代理、终端或网络策略，持续更新情报，绑定身份/设备，控制例外并阻断直出。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-9.3-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "9.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-9.3-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "9.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-9.3-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "9.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-9.3-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "9.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the governed browser, mail, resolver, gateway, and exception policy set and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在受治理的浏览器、邮件、解析器、网关与例外策略集合中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-9.3-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "9.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Implement the explicit state machine requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-9.3-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "9.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Implement the explicit state machine observe → evaluate → decide → enforce → verify outcome → rollback/close; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-9.3-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "9.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-9.3-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "9.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-9.3-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "9.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-9.3-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "9.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-9.3-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "9.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in browser, email, DNS, URL, extension, attachment, sender-authentication, and mail-malware decisions across user and service traffic; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 浏览器、邮件、DNS、URL、扩展、附件、发件人认证及邮件恶意软件在用户与服务流量中的决策 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-9.3-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "9.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; alert before each deadline becomes overdue.",
          "zh": "为“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-9.3-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "9.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for observe → evaluate → decide → enforce → verify outcome → rollback/close; alert before each deadline becomes overdue.",
          "zh": "为“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-9.3-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "9.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “TLS pinning, end-to-end apps, CDNs and shared hosting limit URL inspection and can make IP blocking unsafe.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“TLS Pin、端到端应用、CDN 和共享托管限制 URL 检查，按 IP 拦可能危险。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-9.3-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "9.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-9.3-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "9.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-9.3-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "9.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-9.3-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "9.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat remote devices, encrypted DNS, QUIC, direct IPs, forwarding, mailing lists, nested or encrypted attachments, shared hosting, extensions, and alternate connectors as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 远程设备、加密 DNS、QUIC、直连 IP、转发、邮件列表、嵌套或加密附件、共享托管、扩展和备用连接器 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-9.3-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "9.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Treat IPv6, overlays, east-west paths, remote and roaming devices, direct egress, alternate resolvers, QUIC, asymmetric routes, provider abstraction, and emergency consoles as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 IPv6、覆盖网络、东西向路径、远程与漫游设备、直接出口、替代解析器、QUIC、非对称路由、提供商抽象和紧急控制台 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-9.3-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "9.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Treat audit-only mode, unsupported platforms, local overrides, race conditions, cached state, alternate paths, fail-open behavior, and emergency bypass as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 仅审计模式、不支持平台、本地覆盖、竞态、缓存状态、替代路径、故障开放和紧急绕过 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-9.3-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "9.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Request approved, blocked, newly categorized, direct-IP, encoded, redirect and QUIC destinations from representative paths.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“从代表路径请求允许、被拦、新分类、直连 IP、编码、重定向和 QUIC 目的，验证业务、日志、证书/隐私、更新健康和例外到期；分别报告路径覆盖与绕过。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-9.3-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "9.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-9.3-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "9.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 6 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、6 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-9.3-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "9.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-9.3-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "9.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the governed browser, mail, resolver, gateway, and exception policy set plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以受治理的浏览器、邮件、解析器、网关与例外策略集合和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-9.3-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "9.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Publish known, unknown, allowed, denied, shadow, bypassed, asymmetric, stale-rule, exception, and unobserved paths with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已知、未知、允许、拒绝、影子、绕过、非对称、陈旧规则、例外和未观测路径，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-9.3-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "9.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Publish eligible, enforcing, audit-only, failed, bypassed, excepted, rolled-back, and outcome-verified populations with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 适用、已执行、仅审计、失败、被绕过、例外、已回滚和结果已验证总体，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-9.3-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "9.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-9.3-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "9.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-9.3-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "9.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-9.3-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "9.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-9.3-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "9.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the governed browser, mail, resolver, gateway, and exception policy set; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护受治理的浏览器、邮件、解析器、网关与例外策略集合的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-9.3-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "9.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Restrict authority to change requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-9.3-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "9.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Restrict authority to change observe → evaluate → decide → enforce → verify outcome → rollback/close; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-9.3-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "9.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-9.3-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "9.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-9.3-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "9.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-9.3-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "9.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-9.3-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "9.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise allowed and blocked destinations, spoofed and aligned mail, benign and dangerous file fixtures, extension permission changes, bypass paths, and provider outage through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 允许与阻断目的地、伪造与对齐邮件、安全与危险文件样本、扩展权限变化、绕过路径和提供商中断，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-9.3-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "9.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Run the positive control an approved flow over the required secure management or business path; exercise negative, stale, duplicate, bypass, and outage controls including an unapproved route, protocol downgrade, direct egress, alternate DNS/QUIC path, segmentation bypass, AAA loss, stale rule, and rollback failure.",
          "zh": "运行正向控制“通过规定安全管理或业务路径的一项获批流量”，并执行包含“未批准路由、协议降级、直接出口、替代 DNS/QUIC 路径、分段绕过、AAA 丢失、陈旧规则和回滚失败”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-9.3-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "9.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Run the positive control an approved business action that completes through the enforced path; exercise negative, stale, duplicate, bypass, and outage controls including a prohibited action, alternate path, local override, stale policy, control outage, emergency bypass, and rollback failure.",
          "zh": "运行正向控制“通过受控路径完成的一项获批业务动作”，并执行包含“禁止动作、替代路径、本地覆盖、陈旧策略、控制中断、紧急绕过和回滚失败”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-9.3-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "9.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-9.3-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "9.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-9.3-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "9.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-9.3-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "9.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-9.3-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "9.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever browser/MDM policy, mail tenants and gateways, DNS resolvers, secure web gateways, extension inventories, DMARC reports, endpoint telemetry, and provider logs change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 浏览器/MDM 策略、邮件租户与网关、DNS 解析器、安全 Web 网关、扩展清单、DMARC 报告、终端遥测和提供商日志 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-9.3-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "9.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Use known, unknown, allowed, denied, shadow, bypassed, asymmetric, stale-rule, exception, and unobserved paths to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已知、未知、允许、拒绝、影子、绕过、非对称、陈旧规则、例外和未观测路径 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-9.3-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "9.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Use eligible, enforcing, audit-only, failed, bypassed, excepted, rolled-back, and outcome-verified populations to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 适用、已执行、仅审计、失败、被绕过、例外、已回滚和结果已验证总体 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "9.4",
      "control": 9,
      "title_en": "Restrict Unnecessary or Unauthorized Browser and Email Client Extensions",
      "title_zh": "浏览器与邮件扩展",
      "first_ig": 2,
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Applications",
      "security_function": "Protect",
      "patterns": [
        "network",
        "software_dev",
        "enforcement"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "1.1",
          "2.1"
        ],
        "variables": [
          "GV1",
          "GV5",
          "M1",
          "M2",
          "M3",
          "M4",
          "M5"
        ],
        "metric_branches": 2,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "Include browser extensions, add-ons, native messaging hosts, mail plugins and sideloaded/developer components across every profile and channel.",
          "build": "Default-deny or centrally allowlist required components, force-install only managed ones, block developer mode and unapproved stores, review permission/version changes, and remove unnecessary extensions.",
          "proof": "Install an approved extension, an unapproved store item, a sideloaded copy and an approved ID requesting new permissions.",
          "boundary": "An approved extension can be sold or its update channel compromised; continuous publisher/permission review matters."
        },
        "zh": {
          "scope": "包括每个 Profile/渠道的浏览器扩展、Add-on、Native Messaging Host、邮件插件和侧载/开发组件。",
          "build": "默认拒绝或中央 Allowlist，仅强装受管项，禁开发模式和未批准商店，审查权限/版本变化，移除无必要扩展；同时清点设备与云同步 Profile，并防用户改策略。",
          "proof": "安装批准扩展、未批准商店项、侧载副本和请求新权限的批准 ID，验证执行、更新、同步和移除；把有效 Profile 与批准集合比较并监测篡改。",
          "boundary": "获批扩展可被出售或更新链受损，发布者/权限需持续复核。"
        }
      },
      "category_counts": {
        "outcome": 8,
        "scope": 8,
        "ownership": 8,
        "data": 8,
        "integration": 8,
        "control": 8,
        "timing": 8,
        "exception": 8,
        "evidence": 8,
        "security": 8,
        "testing": 8,
        "operations": 8
      },
      "requirement_count": 96,
      "requirements": [
        {
          "code": "CIS-9.4-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "9.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Restrict Unnecessary or Unauthorized Browser and Email Client Extensions; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“浏览器与邮件扩展”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-9.4-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "9.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 9.4, official Asset Class Applications, Security Function Protect, and IG2 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 9.4、官方资产类别“应用”、安全功能“保护”和首次出现的 IG2，并保存来源抓取日期。"
        },
        {
          "code": "CIS-9.4-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "9.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Include browser extensions, add-ons, native messaging hosts, mail plugins and sideloaded/developer components across every profile and channel.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“包括每个 Profile/渠道的浏览器扩展、Add-on、Native Messaging Host、邮件插件和侧载/开发组件。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-9.4-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "9.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-9.4-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "9.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Restrict Unnecessary or Unauthorized Browser and Email Client Extensions to its operating object—browser, email, DNS, URL, extension, attachment, sender-authentication, and mail-malware decisions across user and service traffic—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“浏览器与邮件扩展”连接到其运营对象——浏览器、邮件、DNS、URL、扩展、附件、发件人认证及邮件恶意软件在用户与服务流量中的决策——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-9.4-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "9.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "For Restrict Unnecessary or Unauthorized Browser and Email Client Extensions, express success as an observable decision over intended connectivity, trust zone, route, protocol, identity, management path, traffic decision, and observed outcome; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“浏览器与邮件扩展”，以 预期连接、信任区、路由、协议、身份、管理路径、流量决策和观察结果 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-9.4-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "9.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "For Restrict Unnecessary or Unauthorized Browser and Email Client Extensions, express success as an observable decision over source-to-production software identity, design invariant, component trust, build provenance, test result, deployment state, runtime outcome, and vulnerability response; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“浏览器与邮件扩展”，以 从源码到生产的软件身份、设计不变量、组件信任、构建来源、测试结果、部署状态、运行结果和漏洞响应 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-9.4-OUT-08",
          "local_code": "OUT-08",
          "display_code": "O08",
          "safeguard_id": "9.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "For Restrict Unnecessary or Unauthorized Browser and Email Client Extensions, express success as an observable decision over an enforceable allow, deny, contain, quarantine, require, remove, or transform decision at the closest reliable control point; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“浏览器与邮件扩展”，以 在最近可靠控制点执行允许、拒绝、遏制、隔离、强制、移除或转换决策 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-9.4-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "9.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-9.4-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "9.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-9.4-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "9.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-9.4-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "9.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-9.4-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "9.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across remote devices, encrypted DNS, QUIC, direct IPs, forwarding, mailing lists, nested or encrypted attachments, shared hosting, extensions, and alternate connectors; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 远程设备、加密 DNS、QUIC、直连 IP、转发、邮件列表、嵌套或加密附件、共享托管、扩展和备用连接器 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-9.4-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "9.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Include IPv6, overlays, east-west paths, remote and roaming devices, direct egress, alternate resolvers, QUIC, asymmetric routes, provider abstraction, and emergency consoles in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 IPv6、覆盖网络、东西向路径、远程与漫游设备、直接出口、替代解析器、QUIC、非对称路由、提供商抽象和紧急控制台 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-9.4-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "9.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Include generated and copied code, forks, vendoring, transitive dependencies, mutable tags, build plugins, feature flags, tenant logic, secrets, emergency release, and provider components in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 生成与复制代码、分叉、vendoring、传递依赖、可变标签、构建插件、功能开关、租户逻辑、秘密、紧急发布和提供商组件 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-9.4-SCP-08",
          "local_code": "SCP-08",
          "display_code": "P08",
          "safeguard_id": "9.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Include audit-only mode, unsupported platforms, local overrides, race conditions, cached state, alternate paths, fail-open behavior, and emergency bypass in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 仅审计模式、不支持平台、本地覆盖、竞态、缓存状态、替代路径、故障开放和紧急绕过 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-9.4-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "9.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-9.4-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "9.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-9.4-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "9.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-9.4-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "9.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-9.4-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "9.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind messaging and endpoint owners, network and email engineering, security operations, identity, privacy, and business workflow owners to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 消息与终端责任人、网络与邮件工程、安全运营、身份、隐私和业务流程责任人 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-9.4-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "9.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Name who may transition requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-9.4-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "9.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Name who may transition designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-9.4-OWN-08",
          "local_code": "OWN-08",
          "display_code": "W08",
          "safeguard_id": "9.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Name who may transition observe → evaluate → decide → enforce → verify outcome → rollback/close, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-9.4-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "9.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-9.4-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "9.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-9.4-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "9.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV1, GV5, M1, M2, M3, M4, M5) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV1, GV5, M1, M2, M3, M4, M5）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-9.4-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "9.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-9.4-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "9.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the governed browser, mail, resolver, gateway, and exception policy set as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把受治理的浏览器、邮件、解析器、网关与例外策略集合作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-9.4-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "9.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired.",
          "zh": "对生命周期“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-9.4-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "9.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired.",
          "zh": "对生命周期“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-9.4-DAT-08",
          "local_code": "DAT-08",
          "display_code": "D08",
          "safeguard_id": "9.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle observe → evaluate → decide → enforce → verify outcome → rollback/close.",
          "zh": "对生命周期“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-9.4-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "9.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 1.1, Safeguard 2.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 1.1、Safeguard 2.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-9.4-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "9.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-9.4-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "9.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-9.4-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "9.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-9.4-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "9.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile browser/MDM policy, mail tenants and gateways, DNS resolvers, secure web gateways, extension inventories, DMARC reports, endpoint telemetry, and provider logs and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 浏览器/MDM 策略、邮件租户与网关、DNS 解析器、安全 Web 网关、扩展清单、DMARC 报告、终端遥测和提供商日志，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-9.4-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "9.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Require every connector carrying intended connectivity, trust zone, route, protocol, identity, management path, traffic decision, and observed outcome to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 预期连接、信任区、路由、协议、身份、管理路径、流量决策和观察结果 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-9.4-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "9.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Require every connector carrying source-to-production software identity, design invariant, component trust, build provenance, test result, deployment state, runtime outcome, and vulnerability response to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 从源码到生产的软件身份、设计不变量、组件信任、构建来源、测试结果、部署状态、运行结果和漏洞响应 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-9.4-INT-08",
          "local_code": "INT-08",
          "display_code": "I08",
          "safeguard_id": "9.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Require every connector carrying an enforceable allow, deny, contain, quarantine, require, remove, or transform decision at the closest reliable control point to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 在最近可靠控制点执行允许、拒绝、遏制、隔离、强制、移除或转换决策 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-9.4-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "9.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Default-deny or centrally allowlist required components, force-install only managed ones, block developer mode and unapproved stores, review permission/version changes, and remove unnecessary extensions.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“默认拒绝或中央 Allowlist，仅强装受管项，禁开发模式和未批准商店，审查权限/版本变化，移除无必要扩展；同时清点设备与云同步 Profile，并防用户改策略。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-9.4-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "9.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-9.4-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "9.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-9.4-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "9.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-9.4-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "9.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the governed browser, mail, resolver, gateway, and exception policy set and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在受治理的浏览器、邮件、解析器、网关与例外策略集合中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-9.4-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "9.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Implement the explicit state machine requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-9.4-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "9.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Implement the explicit state machine designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-9.4-CTL-08",
          "local_code": "CTL-08",
          "display_code": "C08",
          "safeguard_id": "9.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Implement the explicit state machine observe → evaluate → decide → enforce → verify outcome → rollback/close; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-9.4-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "9.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-9.4-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "9.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-9.4-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "9.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-9.4-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "9.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-9.4-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "9.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in browser, email, DNS, URL, extension, attachment, sender-authentication, and mail-malware decisions across user and service traffic; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 浏览器、邮件、DNS、URL、扩展、附件、发件人认证及邮件恶意软件在用户与服务流量中的决策 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-9.4-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "9.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; alert before each deadline becomes overdue.",
          "zh": "为“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-9.4-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "9.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; alert before each deadline becomes overdue.",
          "zh": "为“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-9.4-TIM-08",
          "local_code": "TIM-08",
          "display_code": "T08",
          "safeguard_id": "9.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for observe → evaluate → decide → enforce → verify outcome → rollback/close; alert before each deadline becomes overdue.",
          "zh": "为“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-9.4-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "9.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “An approved extension can be sold or its update channel compromised; continuous publisher/permission review matters.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“获批扩展可被出售或更新链受损，发布者/权限需持续复核。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-9.4-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "9.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-9.4-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "9.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-9.4-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "9.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-9.4-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "9.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat remote devices, encrypted DNS, QUIC, direct IPs, forwarding, mailing lists, nested or encrypted attachments, shared hosting, extensions, and alternate connectors as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 远程设备、加密 DNS、QUIC、直连 IP、转发、邮件列表、嵌套或加密附件、共享托管、扩展和备用连接器 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-9.4-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "9.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Treat IPv6, overlays, east-west paths, remote and roaming devices, direct egress, alternate resolvers, QUIC, asymmetric routes, provider abstraction, and emergency consoles as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 IPv6、覆盖网络、东西向路径、远程与漫游设备、直接出口、替代解析器、QUIC、非对称路由、提供商抽象和紧急控制台 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-9.4-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "9.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Treat generated and copied code, forks, vendoring, transitive dependencies, mutable tags, build plugins, feature flags, tenant logic, secrets, emergency release, and provider components as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 生成与复制代码、分叉、vendoring、传递依赖、可变标签、构建插件、功能开关、租户逻辑、秘密、紧急发布和提供商组件 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-9.4-EXC-08",
          "local_code": "EXC-08",
          "display_code": "X08",
          "safeguard_id": "9.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Treat audit-only mode, unsupported platforms, local overrides, race conditions, cached state, alternate paths, fail-open behavior, and emergency bypass as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 仅审计模式、不支持平台、本地覆盖、竞态、缓存状态、替代路径、故障开放和紧急绕过 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-9.4-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "9.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Install an approved extension, an unapproved store item, a sideloaded copy and an approved ID requesting new permissions.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“安装批准扩展、未批准商店项、侧载副本和请求新权限的批准 ID，验证执行、更新、同步和移除；把有效 Profile 与批准集合比较并监测篡改。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-9.4-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "9.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-9.4-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "9.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 2 pinned CAS metric branch(es), 7 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 2 个指标分支、7 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-9.4-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "9.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-9.4-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "9.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the governed browser, mail, resolver, gateway, and exception policy set plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以受治理的浏览器、邮件、解析器、网关与例外策略集合和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-9.4-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "9.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Publish known, unknown, allowed, denied, shadow, bypassed, asymmetric, stale-rule, exception, and unobserved paths with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已知、未知、允许、拒绝、影子、绕过、非对称、陈旧规则、例外和未观测路径，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-9.4-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "9.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Publish reviewed, unreviewed, reproducible, provenance-bound, vulnerable, test-failed, exception, deployed-unverified, drifted, rolled-back, and regression-protected releases with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已评审、未评审、可复现、来源绑定、存在漏洞、测试失败、例外、已部署未验证、漂移、已回滚和受回归保护发布物，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-9.4-EVD-08",
          "local_code": "EVD-08",
          "display_code": "E08",
          "safeguard_id": "9.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Publish eligible, enforcing, audit-only, failed, bypassed, excepted, rolled-back, and outcome-verified populations with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 适用、已执行、仅审计、失败、被绕过、例外、已回滚和结果已验证总体，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-9.4-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "9.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-9.4-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "9.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-9.4-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "9.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-9.4-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "9.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-9.4-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "9.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the governed browser, mail, resolver, gateway, and exception policy set; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护受治理的浏览器、邮件、解析器、网关与例外策略集合的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-9.4-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "9.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Restrict authority to change requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-9.4-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "9.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Restrict authority to change designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-9.4-SEC-08",
          "local_code": "SEC-08",
          "display_code": "S08",
          "safeguard_id": "9.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Restrict authority to change observe → evaluate → decide → enforce → verify outcome → rollback/close; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-9.4-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "9.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-9.4-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "9.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-9.4-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "9.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-9.4-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "9.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-9.4-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "9.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise allowed and blocked destinations, spoofed and aligned mail, benign and dangerous file fixtures, extension permission changes, bypass paths, and provider outage through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 允许与阻断目的地、伪造与对齐邮件、安全与危险文件样本、扩展权限变化、绕过路径和提供商中断，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-9.4-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "9.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Run the positive control an approved flow over the required secure management or business path; exercise negative, stale, duplicate, bypass, and outage controls including an unapproved route, protocol downgrade, direct egress, alternate DNS/QUIC path, segmentation bypass, AAA loss, stale rule, and rollback failure.",
          "zh": "运行正向控制“通过规定安全管理或业务路径的一项获批流量”，并执行包含“未批准路由、协议降级、直接出口、替代 DNS/QUIC 路径、分段绕过、AAA 丢失、陈旧规则和回滚失败”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-9.4-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "9.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Run the positive control a trusted build that preserves the security invariant through deployment and runtime; exercise negative, stale, duplicate, bypass, and outage controls including a substituted dependency, unreviewed change, poisoned build input, failed security test, bypass path, vulnerable release, rollback, and regression.",
          "zh": "运行正向控制“一个把安全不变量贯穿部署与运行的可信构建”，并执行包含“依赖替换、未评审变更、构建输入污染、安全测试失败、绕过路径、漏洞发布、回滚和回归”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-9.4-TST-08",
          "local_code": "TST-08",
          "display_code": "V08",
          "safeguard_id": "9.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Run the positive control an approved business action that completes through the enforced path; exercise negative, stale, duplicate, bypass, and outage controls including a prohibited action, alternate path, local override, stale policy, control outage, emergency bypass, and rollback failure.",
          "zh": "运行正向控制“通过受控路径完成的一项获批业务动作”，并执行包含“禁止动作、替代路径、本地覆盖、陈旧策略、控制中断、紧急绕过和回滚失败”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-9.4-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "9.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-9.4-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "9.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-9.4-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "9.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-9.4-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "9.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-9.4-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "9.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever browser/MDM policy, mail tenants and gateways, DNS resolvers, secure web gateways, extension inventories, DMARC reports, endpoint telemetry, and provider logs change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 浏览器/MDM 策略、邮件租户与网关、DNS 解析器、安全 Web 网关、扩展清单、DMARC 报告、终端遥测和提供商日志 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-9.4-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "9.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Use known, unknown, allowed, denied, shadow, bypassed, asymmetric, stale-rule, exception, and unobserved paths to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已知、未知、允许、拒绝、影子、绕过、非对称、陈旧规则、例外和未观测路径 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-9.4-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "9.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Use reviewed, unreviewed, reproducible, provenance-bound, vulnerable, test-failed, exception, deployed-unverified, drifted, rolled-back, and regression-protected releases to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已评审、未评审、可复现、来源绑定、存在漏洞、测试失败、例外、已部署未验证、漂移、已回滚和受回归保护发布物 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-9.4-OPS-08",
          "local_code": "OPS-08",
          "display_code": "R08",
          "safeguard_id": "9.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Use eligible, enforcing, audit-only, failed, bypassed, excepted, rolled-back, and outcome-verified populations to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 适用、已执行、仅审计、失败、被绕过、例外、已回滚和结果已验证总体 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "9.5",
      "control": 9,
      "title_en": "Implement DMARC",
      "title_zh": "DMARC、SPF 与 DKIM",
      "first_ig": 2,
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Network",
      "security_function": "Protect",
      "patterns": [
        "network"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "2.1"
        ],
        "variables": [
          "M1",
          "M2",
          "M3",
          "M4",
          "M5",
          "M6"
        ],
        "metric_branches": 1,
        "has_assumptions": true,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "The boundary includes every organizational and parked domain, subdomain, outbound sender, third-party mail platform and inbound verifier.",
          "build": "Inventory senders, configure scoped SPF below lookup limits, protect and rotate DKIM keys, publish DMARC reporting, analyze legitimate alignment, then progress from monitoring to quarantine/reject with explicit percentages and subdomain policy.",
          "proof": "Send aligned valid, SPF-only, DKIM-only, misaligned, spoofed and forwarded/list messages to representative receivers; verify authentication results, policy action and aggregate reports.",
          "boundary": "Forwarding can break SPF and mailing lists can alter DKIM; alignment and ARC decisions need testing."
        },
        "zh": {
          "scope": "包括所有组织域、停放域、子域、出站发件方、第三方邮件平台和入站验证器。",
          "build": "清点发件源，配置不超 DNS Lookup 的 SPF，保护/轮换 DKIM Key，发布 DMARC 报告，分析合法对齐，再从观察推进到 Quarantine/Reject，写明比例和子域策略；入站也验证，治理第三方发件。",
          "proof": "向代表收件方发送对齐有效、仅 SPF、仅 DKIM、错对齐、伪造和转发/邮件列表测试，验证 Authentication-Results、动作与聚合报告；监控每个域未知发件、失败趋势和 DNS 变化，非发信域设拒绝。",
          "boundary": "转发会破坏 SPF，邮件列表可能改 DKIM，需测试对齐和 ARC。"
        }
      },
      "category_counts": {
        "outcome": 6,
        "scope": 6,
        "ownership": 6,
        "data": 6,
        "integration": 6,
        "control": 6,
        "timing": 6,
        "exception": 6,
        "evidence": 6,
        "security": 6,
        "testing": 6,
        "operations": 6
      },
      "requirement_count": 72,
      "requirements": [
        {
          "code": "CIS-9.5-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "9.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Implement DMARC; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“DMARC、SPF 与 DKIM”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-9.5-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "9.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 9.5, official Asset Class Network, Security Function Protect, and IG2 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 9.5、官方资产类别“网络”、安全功能“保护”和首次出现的 IG2，并保存来源抓取日期。"
        },
        {
          "code": "CIS-9.5-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "9.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “The boundary includes every organizational and parked domain, subdomain, outbound sender, third-party mail platform and inbound verifier.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“包括所有组织域、停放域、子域、出站发件方、第三方邮件平台和入站验证器。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-9.5-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "9.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-9.5-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "9.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Implement DMARC to its operating object—browser, email, DNS, URL, extension, attachment, sender-authentication, and mail-malware decisions across user and service traffic—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“DMARC、SPF 与 DKIM”连接到其运营对象——浏览器、邮件、DNS、URL、扩展、附件、发件人认证及邮件恶意软件在用户与服务流量中的决策——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-9.5-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "9.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "For Implement DMARC, express success as an observable decision over intended connectivity, trust zone, route, protocol, identity, management path, traffic decision, and observed outcome; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“DMARC、SPF 与 DKIM”，以 预期连接、信任区、路由、协议、身份、管理路径、流量决策和观察结果 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-9.5-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "9.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-9.5-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "9.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-9.5-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "9.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-9.5-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "9.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-9.5-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "9.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across remote devices, encrypted DNS, QUIC, direct IPs, forwarding, mailing lists, nested or encrypted attachments, shared hosting, extensions, and alternate connectors; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 远程设备、加密 DNS、QUIC、直连 IP、转发、邮件列表、嵌套或加密附件、共享托管、扩展和备用连接器 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-9.5-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "9.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Include IPv6, overlays, east-west paths, remote and roaming devices, direct egress, alternate resolvers, QUIC, asymmetric routes, provider abstraction, and emergency consoles in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 IPv6、覆盖网络、东西向路径、远程与漫游设备、直接出口、替代解析器、QUIC、非对称路由、提供商抽象和紧急控制台 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-9.5-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "9.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-9.5-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "9.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-9.5-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "9.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-9.5-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "9.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-9.5-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "9.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind messaging and endpoint owners, network and email engineering, security operations, identity, privacy, and business workflow owners to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 消息与终端责任人、网络与邮件工程、安全运营、身份、隐私和业务流程责任人 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-9.5-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "9.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Name who may transition requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-9.5-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "9.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-9.5-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "9.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-9.5-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "9.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (M1, M2, M3, M4, M5, M6) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（M1, M2, M3, M4, M5, M6）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-9.5-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "9.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-9.5-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "9.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the governed browser, mail, resolver, gateway, and exception policy set as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把受治理的浏览器、邮件、解析器、网关与例外策略集合作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-9.5-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "9.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired.",
          "zh": "对生命周期“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-9.5-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "9.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 2.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 2.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-9.5-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "9.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-9.5-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "9.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-9.5-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "9.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-9.5-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "9.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile browser/MDM policy, mail tenants and gateways, DNS resolvers, secure web gateways, extension inventories, DMARC reports, endpoint telemetry, and provider logs and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 浏览器/MDM 策略、邮件租户与网关、DNS 解析器、安全 Web 网关、扩展清单、DMARC 报告、终端遥测和提供商日志，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-9.5-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "9.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Require every connector carrying intended connectivity, trust zone, route, protocol, identity, management path, traffic decision, and observed outcome to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 预期连接、信任区、路由、协议、身份、管理路径、流量决策和观察结果 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-9.5-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "9.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Inventory senders, configure scoped SPF below lookup limits, protect and rotate DKIM keys, publish DMARC reporting, analyze legitimate alignment, then progress from monitoring to quarantine/reject with explicit percentages and subdomain policy.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“清点发件源，配置不超 DNS Lookup 的 SPF，保护/轮换 DKIM Key，发布 DMARC 报告，分析合法对齐，再从观察推进到 Quarantine/Reject，写明比例和子域策略；入站也验证，治理第三方发件。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-9.5-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "9.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-9.5-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "9.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-9.5-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "9.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-9.5-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "9.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the governed browser, mail, resolver, gateway, and exception policy set and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在受治理的浏览器、邮件、解析器、网关与例外策略集合中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-9.5-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "9.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Implement the explicit state machine requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-9.5-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "9.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-9.5-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "9.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-9.5-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "9.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-9.5-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "9.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-9.5-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "9.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in browser, email, DNS, URL, extension, attachment, sender-authentication, and mail-malware decisions across user and service traffic; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 浏览器、邮件、DNS、URL、扩展、附件、发件人认证及邮件恶意软件在用户与服务流量中的决策 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-9.5-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "9.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; alert before each deadline becomes overdue.",
          "zh": "为“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-9.5-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "9.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “Forwarding can break SPF and mailing lists can alter DKIM; alignment and ARC decisions need testing.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“转发会破坏 SPF，邮件列表可能改 DKIM，需测试对齐和 ARC。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-9.5-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "9.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-9.5-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "9.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-9.5-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "9.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-9.5-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "9.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat remote devices, encrypted DNS, QUIC, direct IPs, forwarding, mailing lists, nested or encrypted attachments, shared hosting, extensions, and alternate connectors as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 远程设备、加密 DNS、QUIC、直连 IP、转发、邮件列表、嵌套或加密附件、共享托管、扩展和备用连接器 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-9.5-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "9.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Treat IPv6, overlays, east-west paths, remote and roaming devices, direct egress, alternate resolvers, QUIC, asymmetric routes, provider abstraction, and emergency consoles as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 IPv6、覆盖网络、东西向路径、远程与漫游设备、直接出口、替代解析器、QUIC、非对称路由、提供商抽象和紧急控制台 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-9.5-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "9.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Send aligned valid, SPF-only, DKIM-only, misaligned, spoofed and forwarded/list messages to representative receivers; verify authentication results, policy action and aggregate reports.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“向代表收件方发送对齐有效、仅 SPF、仅 DKIM、错对齐、伪造和转发/邮件列表测试，验证 Authentication-Results、动作与聚合报告；监控每个域未知发件、失败趋势和 DNS 变化，非发信域设拒绝。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-9.5-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "9.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-9.5-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "9.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 6 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、6 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-9.5-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "9.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-9.5-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "9.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the governed browser, mail, resolver, gateway, and exception policy set plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以受治理的浏览器、邮件、解析器、网关与例外策略集合和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-9.5-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "9.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Publish known, unknown, allowed, denied, shadow, bypassed, asymmetric, stale-rule, exception, and unobserved paths with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已知、未知、允许、拒绝、影子、绕过、非对称、陈旧规则、例外和未观测路径，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-9.5-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "9.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-9.5-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "9.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-9.5-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "9.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-9.5-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "9.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-9.5-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "9.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the governed browser, mail, resolver, gateway, and exception policy set; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护受治理的浏览器、邮件、解析器、网关与例外策略集合的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-9.5-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "9.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Restrict authority to change requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-9.5-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "9.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-9.5-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "9.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-9.5-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "9.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-9.5-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "9.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-9.5-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "9.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise allowed and blocked destinations, spoofed and aligned mail, benign and dangerous file fixtures, extension permission changes, bypass paths, and provider outage through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 允许与阻断目的地、伪造与对齐邮件、安全与危险文件样本、扩展权限变化、绕过路径和提供商中断，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-9.5-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "9.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Run the positive control an approved flow over the required secure management or business path; exercise negative, stale, duplicate, bypass, and outage controls including an unapproved route, protocol downgrade, direct egress, alternate DNS/QUIC path, segmentation bypass, AAA loss, stale rule, and rollback failure.",
          "zh": "运行正向控制“通过规定安全管理或业务路径的一项获批流量”，并执行包含“未批准路由、协议降级、直接出口、替代 DNS/QUIC 路径、分段绕过、AAA 丢失、陈旧规则和回滚失败”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-9.5-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "9.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-9.5-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "9.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-9.5-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "9.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-9.5-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "9.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-9.5-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "9.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever browser/MDM policy, mail tenants and gateways, DNS resolvers, secure web gateways, extension inventories, DMARC reports, endpoint telemetry, and provider logs change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 浏览器/MDM 策略、邮件租户与网关、DNS 解析器、安全 Web 网关、扩展清单、DMARC 报告、终端遥测和提供商日志 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-9.5-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "9.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Use known, unknown, allowed, denied, shadow, bypassed, asymmetric, stale-rule, exception, and unobserved paths to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已知、未知、允许、拒绝、影子、绕过、非对称、陈旧规则、例外和未观测路径 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "9.6",
      "control": 9,
      "title_en": "Block Unnecessary File Types",
      "title_zh": "高风险附件类型",
      "first_ig": 2,
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Network",
      "security_function": "Protect",
      "patterns": [
        "network",
        "enforcement"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "1.1",
          "4.1"
        ],
        "variables": [
          "GV1",
          "GV3",
          "M1",
          "M2",
          "M3"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "The population is inbound email attachments and archive contents across every mail route, tenant, alias and provider; file type must be determined by content and nested structure, not extension alone.",
          "build": "At the mail gateway or cloud service, reject, quarantine or sanitize disallowed types; inspect MIME, magic, archives and links, control password-protected content, and provide an approved secure transfer alternative.",
          "proof": "Send benign required files, renamed executable, double extension, nested archive, encrypted archive and macro sample through internal/external routes.",
          "boundary": "File-type blocking leaves allowed document content, links and cloud shares exposed to other attack paths."
        },
        "zh": {
          "scope": "总体是经所有邮件路由、租户、别名和服务商进入的附件及压缩包内容；类型应按内容和嵌套识别，不能只看扩展名。",
          "build": "在邮件网关/云服务拒绝、隔离或净化不允许类型，检查 MIME、Magic、压缩嵌套和链接，控制密码包，并提供获批安全传输替代；按收件人/用途版本化规则，例外有发件反馈和分析审查。",
          "proof": "从内外、转发和备用路由发送正常必需文件、改名可执行、双扩展、嵌套包、加密包和宏样本，验证动作、通知、隔离访问、日志和例外到期；覆盖所有 MX/Connector 与直投路径。",
          "boundary": "拦类型不代表允许文档安全，攻击者可用链接/云分享。"
        }
      },
      "category_counts": {
        "outcome": 7,
        "scope": 7,
        "ownership": 7,
        "data": 7,
        "integration": 7,
        "control": 7,
        "timing": 7,
        "exception": 7,
        "evidence": 7,
        "security": 7,
        "testing": 7,
        "operations": 7
      },
      "requirement_count": 84,
      "requirements": [
        {
          "code": "CIS-9.6-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "9.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Block Unnecessary File Types; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“高风险附件类型”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-9.6-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "9.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 9.6, official Asset Class Network, Security Function Protect, and IG2 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 9.6、官方资产类别“网络”、安全功能“保护”和首次出现的 IG2，并保存来源抓取日期。"
        },
        {
          "code": "CIS-9.6-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "9.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “The population is inbound email attachments and archive contents across every mail route, tenant, alias and provider; file type must be determined by content and nested structure, not extension alone.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“总体是经所有邮件路由、租户、别名和服务商进入的附件及压缩包内容；类型应按内容和嵌套识别，不能只看扩展名。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-9.6-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "9.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-9.6-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "9.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Block Unnecessary File Types to its operating object—browser, email, DNS, URL, extension, attachment, sender-authentication, and mail-malware decisions across user and service traffic—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“高风险附件类型”连接到其运营对象——浏览器、邮件、DNS、URL、扩展、附件、发件人认证及邮件恶意软件在用户与服务流量中的决策——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-9.6-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "9.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "For Block Unnecessary File Types, express success as an observable decision over intended connectivity, trust zone, route, protocol, identity, management path, traffic decision, and observed outcome; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“高风险附件类型”，以 预期连接、信任区、路由、协议、身份、管理路径、流量决策和观察结果 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-9.6-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "9.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "For Block Unnecessary File Types, express success as an observable decision over an enforceable allow, deny, contain, quarantine, require, remove, or transform decision at the closest reliable control point; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“高风险附件类型”，以 在最近可靠控制点执行允许、拒绝、遏制、隔离、强制、移除或转换决策 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-9.6-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "9.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-9.6-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "9.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-9.6-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "9.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-9.6-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "9.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-9.6-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "9.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across remote devices, encrypted DNS, QUIC, direct IPs, forwarding, mailing lists, nested or encrypted attachments, shared hosting, extensions, and alternate connectors; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 远程设备、加密 DNS、QUIC、直连 IP、转发、邮件列表、嵌套或加密附件、共享托管、扩展和备用连接器 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-9.6-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "9.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Include IPv6, overlays, east-west paths, remote and roaming devices, direct egress, alternate resolvers, QUIC, asymmetric routes, provider abstraction, and emergency consoles in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 IPv6、覆盖网络、东西向路径、远程与漫游设备、直接出口、替代解析器、QUIC、非对称路由、提供商抽象和紧急控制台 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-9.6-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "9.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Include audit-only mode, unsupported platforms, local overrides, race conditions, cached state, alternate paths, fail-open behavior, and emergency bypass in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 仅审计模式、不支持平台、本地覆盖、竞态、缓存状态、替代路径、故障开放和紧急绕过 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-9.6-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "9.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-9.6-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "9.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-9.6-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "9.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-9.6-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "9.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-9.6-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "9.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind messaging and endpoint owners, network and email engineering, security operations, identity, privacy, and business workflow owners to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 消息与终端责任人、网络与邮件工程、安全运营、身份、隐私和业务流程责任人 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-9.6-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "9.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Name who may transition requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-9.6-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "9.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Name who may transition observe → evaluate → decide → enforce → verify outcome → rollback/close, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-9.6-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "9.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-9.6-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "9.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-9.6-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "9.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV1, GV3, M1, M2, M3) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV1, GV3, M1, M2, M3）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-9.6-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "9.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-9.6-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "9.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the governed browser, mail, resolver, gateway, and exception policy set as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把受治理的浏览器、邮件、解析器、网关与例外策略集合作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-9.6-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "9.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired.",
          "zh": "对生命周期“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-9.6-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "9.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle observe → evaluate → decide → enforce → verify outcome → rollback/close.",
          "zh": "对生命周期“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-9.6-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "9.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 1.1, Safeguard 4.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 1.1、Safeguard 4.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-9.6-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "9.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-9.6-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "9.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-9.6-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "9.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-9.6-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "9.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile browser/MDM policy, mail tenants and gateways, DNS resolvers, secure web gateways, extension inventories, DMARC reports, endpoint telemetry, and provider logs and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 浏览器/MDM 策略、邮件租户与网关、DNS 解析器、安全 Web 网关、扩展清单、DMARC 报告、终端遥测和提供商日志，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-9.6-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "9.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Require every connector carrying intended connectivity, trust zone, route, protocol, identity, management path, traffic decision, and observed outcome to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 预期连接、信任区、路由、协议、身份、管理路径、流量决策和观察结果 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-9.6-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "9.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Require every connector carrying an enforceable allow, deny, contain, quarantine, require, remove, or transform decision at the closest reliable control point to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 在最近可靠控制点执行允许、拒绝、遏制、隔离、强制、移除或转换决策 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-9.6-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "9.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “At the mail gateway or cloud service, reject, quarantine or sanitize disallowed types; inspect MIME, magic, archives and links, control password-protected content, and provide an approved secure transfer alternative.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“在邮件网关/云服务拒绝、隔离或净化不允许类型，检查 MIME、Magic、压缩嵌套和链接，控制密码包，并提供获批安全传输替代；按收件人/用途版本化规则，例外有发件反馈和分析审查。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-9.6-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "9.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-9.6-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "9.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-9.6-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "9.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-9.6-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "9.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the governed browser, mail, resolver, gateway, and exception policy set and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在受治理的浏览器、邮件、解析器、网关与例外策略集合中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-9.6-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "9.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Implement the explicit state machine requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-9.6-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "9.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Implement the explicit state machine observe → evaluate → decide → enforce → verify outcome → rollback/close; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-9.6-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "9.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-9.6-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "9.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-9.6-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "9.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-9.6-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "9.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-9.6-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "9.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in browser, email, DNS, URL, extension, attachment, sender-authentication, and mail-malware decisions across user and service traffic; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 浏览器、邮件、DNS、URL、扩展、附件、发件人认证及邮件恶意软件在用户与服务流量中的决策 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-9.6-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "9.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; alert before each deadline becomes overdue.",
          "zh": "为“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-9.6-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "9.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for observe → evaluate → decide → enforce → verify outcome → rollback/close; alert before each deadline becomes overdue.",
          "zh": "为“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-9.6-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "9.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “File-type blocking leaves allowed document content, links and cloud shares exposed to other attack paths.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“拦类型不代表允许文档安全，攻击者可用链接/云分享。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-9.6-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "9.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-9.6-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "9.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-9.6-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "9.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-9.6-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "9.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat remote devices, encrypted DNS, QUIC, direct IPs, forwarding, mailing lists, nested or encrypted attachments, shared hosting, extensions, and alternate connectors as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 远程设备、加密 DNS、QUIC、直连 IP、转发、邮件列表、嵌套或加密附件、共享托管、扩展和备用连接器 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-9.6-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "9.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Treat IPv6, overlays, east-west paths, remote and roaming devices, direct egress, alternate resolvers, QUIC, asymmetric routes, provider abstraction, and emergency consoles as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 IPv6、覆盖网络、东西向路径、远程与漫游设备、直接出口、替代解析器、QUIC、非对称路由、提供商抽象和紧急控制台 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-9.6-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "9.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Treat audit-only mode, unsupported platforms, local overrides, race conditions, cached state, alternate paths, fail-open behavior, and emergency bypass as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 仅审计模式、不支持平台、本地覆盖、竞态、缓存状态、替代路径、故障开放和紧急绕过 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-9.6-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "9.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Send benign required files, renamed executable, double extension, nested archive, encrypted archive and macro sample through internal/external routes.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“从内外、转发和备用路由发送正常必需文件、改名可执行、双扩展、嵌套包、加密包和宏样本，验证动作、通知、隔离访问、日志和例外到期；覆盖所有 MX/Connector 与直投路径。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-9.6-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "9.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-9.6-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "9.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 5 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、5 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-9.6-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "9.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-9.6-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "9.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the governed browser, mail, resolver, gateway, and exception policy set plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以受治理的浏览器、邮件、解析器、网关与例外策略集合和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-9.6-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "9.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Publish known, unknown, allowed, denied, shadow, bypassed, asymmetric, stale-rule, exception, and unobserved paths with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已知、未知、允许、拒绝、影子、绕过、非对称、陈旧规则、例外和未观测路径，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-9.6-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "9.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Publish eligible, enforcing, audit-only, failed, bypassed, excepted, rolled-back, and outcome-verified populations with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 适用、已执行、仅审计、失败、被绕过、例外、已回滚和结果已验证总体，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-9.6-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "9.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-9.6-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "9.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-9.6-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "9.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-9.6-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "9.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-9.6-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "9.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the governed browser, mail, resolver, gateway, and exception policy set; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护受治理的浏览器、邮件、解析器、网关与例外策略集合的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-9.6-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "9.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Restrict authority to change requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-9.6-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "9.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Restrict authority to change observe → evaluate → decide → enforce → verify outcome → rollback/close; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-9.6-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "9.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-9.6-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "9.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-9.6-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "9.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-9.6-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "9.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-9.6-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "9.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise allowed and blocked destinations, spoofed and aligned mail, benign and dangerous file fixtures, extension permission changes, bypass paths, and provider outage through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 允许与阻断目的地、伪造与对齐邮件、安全与危险文件样本、扩展权限变化、绕过路径和提供商中断，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-9.6-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "9.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Run the positive control an approved flow over the required secure management or business path; exercise negative, stale, duplicate, bypass, and outage controls including an unapproved route, protocol downgrade, direct egress, alternate DNS/QUIC path, segmentation bypass, AAA loss, stale rule, and rollback failure.",
          "zh": "运行正向控制“通过规定安全管理或业务路径的一项获批流量”，并执行包含“未批准路由、协议降级、直接出口、替代 DNS/QUIC 路径、分段绕过、AAA 丢失、陈旧规则和回滚失败”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-9.6-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "9.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Run the positive control an approved business action that completes through the enforced path; exercise negative, stale, duplicate, bypass, and outage controls including a prohibited action, alternate path, local override, stale policy, control outage, emergency bypass, and rollback failure.",
          "zh": "运行正向控制“通过受控路径完成的一项获批业务动作”，并执行包含“禁止动作、替代路径、本地覆盖、陈旧策略、控制中断、紧急绕过和回滚失败”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-9.6-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "9.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-9.6-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "9.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-9.6-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "9.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-9.6-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "9.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-9.6-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "9.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever browser/MDM policy, mail tenants and gateways, DNS resolvers, secure web gateways, extension inventories, DMARC reports, endpoint telemetry, and provider logs change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 浏览器/MDM 策略、邮件租户与网关、DNS 解析器、安全 Web 网关、扩展清单、DMARC 报告、终端遥测和提供商日志 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-9.6-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "9.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Use known, unknown, allowed, denied, shadow, bypassed, asymmetric, stale-rule, exception, and unobserved paths to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已知、未知、允许、拒绝、影子、绕过、非对称、陈旧规则、例外和未观测路径 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-9.6-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "9.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Use eligible, enforcing, audit-only, failed, bypassed, excepted, rolled-back, and outcome-verified populations to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 适用、已执行、仅审计、失败、被绕过、例外、已回滚和结果已验证总体 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "9.7",
      "control": 9,
      "title_en": "Deploy and Maintain Email Server Anti-Malware Protections",
      "title_zh": "邮件系统反恶意软件",
      "first_ig": 3,
      "implementation_groups": [
        3
      ],
      "asset_class": "Network",
      "security_function": "Protect",
      "patterns": [
        "network",
        "enforcement"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "1.1",
          "4.1"
        ],
        "variables": [
          "GV1",
          "GV3",
          "M1",
          "M2",
          "M3"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "Cover inbound, outbound and internal mail flow, attachments, URLs and collaboration messages where the service supports malware inspection, including alternate connectors and provider routing.",
          "build": "Enable layered provider/gateway scanning, sandbox risky supported content, update engines automatically, quarantine safely and connect verdicts to endpoint/incident response.",
          "proof": "Use industry-safe test files and benign detonation fixtures through external, internal, forwarded and alternate routes; verify block/quarantine, verdict, user notice, release control and telemetry.",
          "boundary": "A configured product may skip internal mail, large files, encrypted archives or unsupported formats."
        },
        "zh": {
          "scope": "覆盖入站、出站和内部邮件的附件、URL 与协作消息，包括备用 Connector/服务商路由。",
          "build": "启用服务商/网关多层扫描，对支持的高风险内容沙箱，自动更新引擎，安全隔离并把判定接事件响应；保护管理旁路，租户/MX 变化后测路由，监控引擎/更新/导出。",
          "proof": "用行业安全测试文件与无害沙箱 Fixture 经外部、内部、转发和替代路径验证阻断/隔离、判定、通知、放行与遥测；检查加密/密码包政策和扫描服务故障告警。",
          "boundary": "配置产品可能跳过内部邮件、大文件、加密包或不支持类型。"
        }
      },
      "category_counts": {
        "outcome": 7,
        "scope": 7,
        "ownership": 7,
        "data": 7,
        "integration": 7,
        "control": 7,
        "timing": 7,
        "exception": 7,
        "evidence": 7,
        "security": 7,
        "testing": 7,
        "operations": 7
      },
      "requirement_count": 84,
      "requirements": [
        {
          "code": "CIS-9.7-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "9.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Deploy and Maintain Email Server Anti-Malware Protections; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“邮件系统反恶意软件”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-9.7-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "9.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 9.7, official Asset Class Network, Security Function Protect, and IG3 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 9.7、官方资产类别“网络”、安全功能“保护”和首次出现的 IG3，并保存来源抓取日期。"
        },
        {
          "code": "CIS-9.7-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "9.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Cover inbound, outbound and internal mail flow, attachments, URLs and collaboration messages where the service supports malware inspection, including alternate connectors and provider routing.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“覆盖入站、出站和内部邮件的附件、URL 与协作消息，包括备用 Connector/服务商路由。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-9.7-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "9.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-9.7-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "9.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Deploy and Maintain Email Server Anti-Malware Protections to its operating object—browser, email, DNS, URL, extension, attachment, sender-authentication, and mail-malware decisions across user and service traffic—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“邮件系统反恶意软件”连接到其运营对象——浏览器、邮件、DNS、URL、扩展、附件、发件人认证及邮件恶意软件在用户与服务流量中的决策——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-9.7-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "9.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "For Deploy and Maintain Email Server Anti-Malware Protections, express success as an observable decision over intended connectivity, trust zone, route, protocol, identity, management path, traffic decision, and observed outcome; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“邮件系统反恶意软件”，以 预期连接、信任区、路由、协议、身份、管理路径、流量决策和观察结果 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-9.7-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "9.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "For Deploy and Maintain Email Server Anti-Malware Protections, express success as an observable decision over an enforceable allow, deny, contain, quarantine, require, remove, or transform decision at the closest reliable control point; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“邮件系统反恶意软件”，以 在最近可靠控制点执行允许、拒绝、遏制、隔离、强制、移除或转换决策 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-9.7-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "9.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-9.7-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "9.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-9.7-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "9.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-9.7-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "9.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-9.7-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "9.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across remote devices, encrypted DNS, QUIC, direct IPs, forwarding, mailing lists, nested or encrypted attachments, shared hosting, extensions, and alternate connectors; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 远程设备、加密 DNS、QUIC、直连 IP、转发、邮件列表、嵌套或加密附件、共享托管、扩展和备用连接器 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-9.7-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "9.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Include IPv6, overlays, east-west paths, remote and roaming devices, direct egress, alternate resolvers, QUIC, asymmetric routes, provider abstraction, and emergency consoles in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 IPv6、覆盖网络、东西向路径、远程与漫游设备、直接出口、替代解析器、QUIC、非对称路由、提供商抽象和紧急控制台 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-9.7-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "9.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Include audit-only mode, unsupported platforms, local overrides, race conditions, cached state, alternate paths, fail-open behavior, and emergency bypass in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 仅审计模式、不支持平台、本地覆盖、竞态、缓存状态、替代路径、故障开放和紧急绕过 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-9.7-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "9.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-9.7-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "9.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-9.7-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "9.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-9.7-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "9.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-9.7-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "9.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind messaging and endpoint owners, network and email engineering, security operations, identity, privacy, and business workflow owners to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 消息与终端责任人、网络与邮件工程、安全运营、身份、隐私和业务流程责任人 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-9.7-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "9.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Name who may transition requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-9.7-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "9.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Name who may transition observe → evaluate → decide → enforce → verify outcome → rollback/close, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-9.7-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "9.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-9.7-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "9.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-9.7-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "9.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV1, GV3, M1, M2, M3) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV1, GV3, M1, M2, M3）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-9.7-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "9.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-9.7-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "9.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the governed browser, mail, resolver, gateway, and exception policy set as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把受治理的浏览器、邮件、解析器、网关与例外策略集合作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-9.7-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "9.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired.",
          "zh": "对生命周期“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-9.7-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "9.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle observe → evaluate → decide → enforce → verify outcome → rollback/close.",
          "zh": "对生命周期“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-9.7-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "9.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 1.1, Safeguard 4.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 1.1、Safeguard 4.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-9.7-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "9.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-9.7-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "9.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-9.7-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "9.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-9.7-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "9.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile browser/MDM policy, mail tenants and gateways, DNS resolvers, secure web gateways, extension inventories, DMARC reports, endpoint telemetry, and provider logs and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 浏览器/MDM 策略、邮件租户与网关、DNS 解析器、安全 Web 网关、扩展清单、DMARC 报告、终端遥测和提供商日志，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-9.7-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "9.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Require every connector carrying intended connectivity, trust zone, route, protocol, identity, management path, traffic decision, and observed outcome to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 预期连接、信任区、路由、协议、身份、管理路径、流量决策和观察结果 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-9.7-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "9.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Require every connector carrying an enforceable allow, deny, contain, quarantine, require, remove, or transform decision at the closest reliable control point to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 在最近可靠控制点执行允许、拒绝、遏制、隔离、强制、移除或转换决策 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-9.7-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "9.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Enable layered provider/gateway scanning, sandbox risky supported content, update engines automatically, quarantine safely and connect verdicts to endpoint/incident response.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“启用服务商/网关多层扫描，对支持的高风险内容沙箱，自动更新引擎，安全隔离并把判定接事件响应；保护管理旁路，租户/MX 变化后测路由，监控引擎/更新/导出。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-9.7-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "9.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-9.7-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "9.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-9.7-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "9.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-9.7-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "9.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the governed browser, mail, resolver, gateway, and exception policy set and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在受治理的浏览器、邮件、解析器、网关与例外策略集合中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-9.7-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "9.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Implement the explicit state machine requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-9.7-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "9.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Implement the explicit state machine observe → evaluate → decide → enforce → verify outcome → rollback/close; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-9.7-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "9.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-9.7-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "9.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-9.7-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "9.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-9.7-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "9.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-9.7-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "9.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in browser, email, DNS, URL, extension, attachment, sender-authentication, and mail-malware decisions across user and service traffic; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 浏览器、邮件、DNS、URL、扩展、附件、发件人认证及邮件恶意软件在用户与服务流量中的决策 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-9.7-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "9.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; alert before each deadline becomes overdue.",
          "zh": "为“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-9.7-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "9.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for observe → evaluate → decide → enforce → verify outcome → rollback/close; alert before each deadline becomes overdue.",
          "zh": "为“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-9.7-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "9.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “A configured product may skip internal mail, large files, encrypted archives or unsupported formats.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“配置产品可能跳过内部邮件、大文件、加密包或不支持类型。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-9.7-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "9.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-9.7-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "9.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-9.7-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "9.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-9.7-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "9.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat remote devices, encrypted DNS, QUIC, direct IPs, forwarding, mailing lists, nested or encrypted attachments, shared hosting, extensions, and alternate connectors as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 远程设备、加密 DNS、QUIC、直连 IP、转发、邮件列表、嵌套或加密附件、共享托管、扩展和备用连接器 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-9.7-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "9.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Treat IPv6, overlays, east-west paths, remote and roaming devices, direct egress, alternate resolvers, QUIC, asymmetric routes, provider abstraction, and emergency consoles as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 IPv6、覆盖网络、东西向路径、远程与漫游设备、直接出口、替代解析器、QUIC、非对称路由、提供商抽象和紧急控制台 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-9.7-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "9.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Treat audit-only mode, unsupported platforms, local overrides, race conditions, cached state, alternate paths, fail-open behavior, and emergency bypass as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 仅审计模式、不支持平台、本地覆盖、竞态、缓存状态、替代路径、故障开放和紧急绕过 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-9.7-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "9.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Use industry-safe test files and benign detonation fixtures through external, internal, forwarded and alternate routes; verify block/quarantine, verdict, user notice, release control and telemetry.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“用行业安全测试文件与无害沙箱 Fixture 经外部、内部、转发和替代路径验证阻断/隔离、判定、通知、放行与遥测；检查加密/密码包政策和扫描服务故障告警。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-9.7-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "9.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-9.7-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "9.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 5 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、5 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-9.7-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "9.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-9.7-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "9.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the governed browser, mail, resolver, gateway, and exception policy set plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以受治理的浏览器、邮件、解析器、网关与例外策略集合和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-9.7-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "9.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Publish known, unknown, allowed, denied, shadow, bypassed, asymmetric, stale-rule, exception, and unobserved paths with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已知、未知、允许、拒绝、影子、绕过、非对称、陈旧规则、例外和未观测路径，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-9.7-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "9.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Publish eligible, enforcing, audit-only, failed, bypassed, excepted, rolled-back, and outcome-verified populations with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 适用、已执行、仅审计、失败、被绕过、例外、已回滚和结果已验证总体，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-9.7-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "9.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-9.7-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "9.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-9.7-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "9.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-9.7-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "9.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-9.7-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "9.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the governed browser, mail, resolver, gateway, and exception policy set; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护受治理的浏览器、邮件、解析器、网关与例外策略集合的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-9.7-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "9.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Restrict authority to change requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-9.7-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "9.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Restrict authority to change observe → evaluate → decide → enforce → verify outcome → rollback/close; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-9.7-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "9.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-9.7-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "9.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-9.7-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "9.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-9.7-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "9.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-9.7-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "9.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise allowed and blocked destinations, spoofed and aligned mail, benign and dangerous file fixtures, extension permission changes, bypass paths, and provider outage through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 允许与阻断目的地、伪造与对齐邮件、安全与危险文件样本、扩展权限变化、绕过路径和提供商中断，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-9.7-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "9.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Run the positive control an approved flow over the required secure management or business path; exercise negative, stale, duplicate, bypass, and outage controls including an unapproved route, protocol downgrade, direct egress, alternate DNS/QUIC path, segmentation bypass, AAA loss, stale rule, and rollback failure.",
          "zh": "运行正向控制“通过规定安全管理或业务路径的一项获批流量”，并执行包含“未批准路由、协议降级、直接出口、替代 DNS/QUIC 路径、分段绕过、AAA 丢失、陈旧规则和回滚失败”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-9.7-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "9.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Run the positive control an approved business action that completes through the enforced path; exercise negative, stale, duplicate, bypass, and outage controls including a prohibited action, alternate path, local override, stale policy, control outage, emergency bypass, and rollback failure.",
          "zh": "运行正向控制“通过受控路径完成的一项获批业务动作”，并执行包含“禁止动作、替代路径、本地覆盖、陈旧策略、控制中断、紧急绕过和回滚失败”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-9.7-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "9.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-9.7-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "9.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-9.7-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "9.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-9.7-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "9.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-9.7-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "9.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever browser/MDM policy, mail tenants and gateways, DNS resolvers, secure web gateways, extension inventories, DMARC reports, endpoint telemetry, and provider logs change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 浏览器/MDM 策略、邮件租户与网关、DNS 解析器、安全 Web 网关、扩展清单、DMARC 报告、终端遥测和提供商日志 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-9.7-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "9.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Use known, unknown, allowed, denied, shadow, bypassed, asymmetric, stale-rule, exception, and unobserved paths to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已知、未知、允许、拒绝、影子、绕过、非对称、陈旧规则、例外和未观测路径 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-9.7-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "9.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Use eligible, enforcing, audit-only, failed, bypassed, excepted, rolled-back, and outcome-verified populations to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 适用、已执行、仅审计、失败、被绕过、例外、已回滚和结果已验证总体 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "10.1",
      "control": 10,
      "title_en": "Deploy and Maintain Anti-Malware Software",
      "title_zh": "反恶意软件覆盖",
      "first_ig": 1,
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Devices",
      "security_function": "Detect",
      "patterns": [
        "enforcement",
        "software_dev"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "1.1",
          "2.1",
          "4.1"
        ],
        "variables": [
          "GV1",
          "GV3",
          "GV5",
          "GV30",
          "GV31",
          "GV32",
          "M1",
          "M2",
          "M3",
          "M4",
          "M5",
          "M6"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "Include every enterprise asset capable of an anti-malware control, with platform-appropriate endpoint, workload, cloud or native protection; explicitly enumerate unsupported IoT/OT, appliances, containers and serverless services.",
          "build": "Deploy approved software through standard builds, enable real-time and scheduled protection appropriate to workload, protect tamper settings, centralize alerts and reconcile health to the asset inventory.",
          "proof": "Use safe industry test artifacts and configuration canaries to verify prevention/detection, quarantine, alert, update and response on each platform class.",
          "boundary": "On-demand scans while real-time protection is disabled cannot support a runtime claim."
        },
        "zh": {
          "scope": "包括一切能部署反恶意软件控制的企业资产，按平台采用终端、工作负载、云原生等保护，并明确列出不支持的 IoT/OT、设备、容器、Serverless。",
          "build": "标准构建部署批准软件，按工作负载启用实时/计划保护，防篡改，集中告警，并把健康与资产台账对账；传统 Agent 不适合时用镜像、Runtime 或网络控制。",
          "proof": "各平台用安全行业测试制品和配置金丝雀验证防护/检测、隔离、告警、更新与响应；覆盖率是近期健康、正确配置且回报的合格资产，单列仅按需、禁用、陈旧和不支持。",
          "boundary": "实时保护关闭时的按需扫描不能支撑运行兼容/保护结论。"
        }
      },
      "category_counts": {
        "outcome": 7,
        "scope": 7,
        "ownership": 7,
        "data": 7,
        "integration": 7,
        "control": 7,
        "timing": 7,
        "exception": 7,
        "evidence": 7,
        "security": 7,
        "testing": 7,
        "operations": 7
      },
      "requirement_count": 84,
      "requirements": [
        {
          "code": "CIS-10.1-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "10.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Deploy and Maintain Anti-Malware Software; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“反恶意软件覆盖”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-10.1-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "10.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 10.1, official Asset Class Devices, Security Function Detect, and IG1 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 10.1、官方资产类别“设备”、安全功能“检测”和首次出现的 IG1，并保存来源抓取日期。"
        },
        {
          "code": "CIS-10.1-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "10.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Include every enterprise asset capable of an anti-malware control, with platform-appropriate endpoint, workload, cloud or native protection; explicitly enumerate unsupported IoT/OT, appliances, containers and serverless services.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“包括一切能部署反恶意软件控制的企业资产，按平台采用终端、工作负载、云原生等保护，并明确列出不支持的 IoT/OT、设备、容器、Serverless。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-10.1-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "10.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-10.1-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "10.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Deploy and Maintain Anti-Malware Software to its operating object—anti-malware eligibility, deployment, health, content freshness, policy, exclusions, detections, prevention, quarantine, and response—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“反恶意软件覆盖”连接到其运营对象——反恶意软件适用性、部署、健康、内容新鲜度、策略、排除项、检测、阻断、隔离和响应——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-10.1-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "10.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "For Deploy and Maintain Anti-Malware Software, express success as an observable decision over an enforceable allow, deny, contain, quarantine, require, remove, or transform decision at the closest reliable control point; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“反恶意软件覆盖”，以 在最近可靠控制点执行允许、拒绝、遏制、隔离、强制、移除或转换决策 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-10.1-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "10.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "For Deploy and Maintain Anti-Malware Software, express success as an observable decision over source-to-production software identity, design invariant, component trust, build provenance, test result, deployment state, runtime outcome, and vulnerability response; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“反恶意软件覆盖”，以 从源码到生产的软件身份、设计不变量、组件信任、构建来源、测试结果、部署状态、运行结果和漏洞响应 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-10.1-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "10.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-10.1-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "10.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-10.1-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "10.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-10.1-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "10.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-10.1-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "10.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across unsupported IoT/OT, containers, serverless, offline assets, stale content, behavior-only products, exclusions, tamper, performance modes, and conflicting agents; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 不支持的 IoT/OT、容器、Serverless、离线资产、陈旧内容、纯行为产品、排除项、篡改、性能模式和代理冲突 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-10.1-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "10.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Include audit-only mode, unsupported platforms, local overrides, race conditions, cached state, alternate paths, fail-open behavior, and emergency bypass in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 仅审计模式、不支持平台、本地覆盖、竞态、缓存状态、替代路径、故障开放和紧急绕过 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-10.1-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "10.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Include generated and copied code, forks, vendoring, transitive dependencies, mutable tags, build plugins, feature flags, tenant logic, secrets, emergency release, and provider components in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 生成与复制代码、分叉、vendoring、传递依赖、可变标签、构建插件、功能开关、租户逻辑、秘密、紧急发布和提供商组件 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-10.1-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "10.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-10.1-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "10.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-10.1-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "10.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-10.1-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "10.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-10.1-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "10.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind endpoint and platform engineering, workload owners, security operations, change management, and risk owners to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 终端与平台工程、工作负载责任人、安全运营、变更管理和风险责任人 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-10.1-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "10.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Name who may transition observe → evaluate → decide → enforce → verify outcome → rollback/close, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-10.1-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "10.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Name who may transition designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-10.1-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "10.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-10.1-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "10.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-10.1-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "10.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV1, GV3, GV5, GV30, GV31, GV32, M1, M2, M3, M4, M5, M6) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV1, GV3, GV5, GV30, GV31, GV32, M1, M2, M3, M4, M5, M6）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-10.1-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "10.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-10.1-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "10.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the endpoint and workload protection policy and health authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把终端与工作负载防护策略及健康权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-10.1-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "10.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle observe → evaluate → decide → enforce → verify outcome → rollback/close.",
          "zh": "对生命周期“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-10.1-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "10.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired.",
          "zh": "对生命周期“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-10.1-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "10.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 1.1, Safeguard 2.1, Safeguard 4.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 1.1、Safeguard 2.1、Safeguard 4.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-10.1-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "10.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-10.1-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "10.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-10.1-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "10.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-10.1-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "10.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile asset inventory, endpoint/workload platforms, cloud-native controls, image and runtime scanners, update services, exclusions, alerts, and response records and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 资产清单、终端/工作负载平台、云原生控制、镜像与运行时扫描、更新服务、排除项、告警和响应记录，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-10.1-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "10.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Require every connector carrying an enforceable allow, deny, contain, quarantine, require, remove, or transform decision at the closest reliable control point to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 在最近可靠控制点执行允许、拒绝、遏制、隔离、强制、移除或转换决策 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-10.1-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "10.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Require every connector carrying source-to-production software identity, design invariant, component trust, build provenance, test result, deployment state, runtime outcome, and vulnerability response to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 从源码到生产的软件身份、设计不变量、组件信任、构建来源、测试结果、部署状态、运行结果和漏洞响应 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-10.1-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "10.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Deploy approved software through standard builds, enable real-time and scheduled protection appropriate to workload, protect tamper settings, centralize alerts and reconcile health to the asset inventory.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“标准构建部署批准软件，按工作负载启用实时/计划保护，防篡改，集中告警，并把健康与资产台账对账；传统 Agent 不适合时用镜像、Runtime 或网络控制。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-10.1-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "10.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-10.1-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "10.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-10.1-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "10.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-10.1-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "10.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the endpoint and workload protection policy and health authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在终端与工作负载防护策略及健康权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-10.1-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "10.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Implement the explicit state machine observe → evaluate → decide → enforce → verify outcome → rollback/close; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-10.1-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "10.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Implement the explicit state machine designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-10.1-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "10.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-10.1-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "10.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-10.1-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "10.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-10.1-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "10.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-10.1-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "10.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in anti-malware eligibility, deployment, health, content freshness, policy, exclusions, detections, prevention, quarantine, and response; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 反恶意软件适用性、部署、健康、内容新鲜度、策略、排除项、检测、阻断、隔离和响应 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-10.1-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "10.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for observe → evaluate → decide → enforce → verify outcome → rollback/close; alert before each deadline becomes overdue.",
          "zh": "为“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-10.1-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "10.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; alert before each deadline becomes overdue.",
          "zh": "为“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-10.1-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "10.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “On-demand scans while real-time protection is disabled cannot support a runtime claim.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“实时保护关闭时的按需扫描不能支撑运行兼容/保护结论。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-10.1-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "10.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-10.1-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "10.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-10.1-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "10.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-10.1-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "10.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat unsupported IoT/OT, containers, serverless, offline assets, stale content, behavior-only products, exclusions, tamper, performance modes, and conflicting agents as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 不支持的 IoT/OT、容器、Serverless、离线资产、陈旧内容、纯行为产品、排除项、篡改、性能模式和代理冲突 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-10.1-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "10.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Treat audit-only mode, unsupported platforms, local overrides, race conditions, cached state, alternate paths, fail-open behavior, and emergency bypass as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 仅审计模式、不支持平台、本地覆盖、竞态、缓存状态、替代路径、故障开放和紧急绕过 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-10.1-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "10.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Treat generated and copied code, forks, vendoring, transitive dependencies, mutable tags, build plugins, feature flags, tenant logic, secrets, emergency release, and provider components as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 生成与复制代码、分叉、vendoring、传递依赖、可变标签、构建插件、功能开关、租户逻辑、秘密、紧急发布和提供商组件 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-10.1-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "10.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Use safe industry test artifacts and configuration canaries to verify prevention/detection, quarantine, alert, update and response on each platform class.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“各平台用安全行业测试制品和配置金丝雀验证防护/检测、隔离、告警、更新与响应；覆盖率是近期健康、正确配置且回报的合格资产，单列仅按需、禁用、陈旧和不支持。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-10.1-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "10.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-10.1-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "10.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 12 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、12 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-10.1-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "10.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-10.1-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "10.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the endpoint and workload protection policy and health authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以终端与工作负载防护策略及健康权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-10.1-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "10.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Publish eligible, enforcing, audit-only, failed, bypassed, excepted, rolled-back, and outcome-verified populations with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 适用、已执行、仅审计、失败、被绕过、例外、已回滚和结果已验证总体，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-10.1-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "10.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Publish reviewed, unreviewed, reproducible, provenance-bound, vulnerable, test-failed, exception, deployed-unverified, drifted, rolled-back, and regression-protected releases with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已评审、未评审、可复现、来源绑定、存在漏洞、测试失败、例外、已部署未验证、漂移、已回滚和受回归保护发布物，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-10.1-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "10.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-10.1-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "10.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-10.1-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "10.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-10.1-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "10.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-10.1-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "10.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the endpoint and workload protection policy and health authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护终端与工作负载防护策略及健康权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-10.1-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "10.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Restrict authority to change observe → evaluate → decide → enforce → verify outcome → rollback/close; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-10.1-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "10.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Restrict authority to change designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-10.1-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "10.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-10.1-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "10.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-10.1-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "10.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-10.1-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "10.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-10.1-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "10.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise safe test artifacts, current and stale content, disabled protection, exclusion abuse, removable media, exploit behavior, quarantine, and update outage through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 安全测试样本、当前与陈旧内容、关闭防护、排除项滥用、可移动介质、利用行为、隔离和更新中断，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-10.1-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "10.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Run the positive control an approved business action that completes through the enforced path; exercise negative, stale, duplicate, bypass, and outage controls including a prohibited action, alternate path, local override, stale policy, control outage, emergency bypass, and rollback failure.",
          "zh": "运行正向控制“通过受控路径完成的一项获批业务动作”，并执行包含“禁止动作、替代路径、本地覆盖、陈旧策略、控制中断、紧急绕过和回滚失败”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-10.1-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "10.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Run the positive control a trusted build that preserves the security invariant through deployment and runtime; exercise negative, stale, duplicate, bypass, and outage controls including a substituted dependency, unreviewed change, poisoned build input, failed security test, bypass path, vulnerable release, rollback, and regression.",
          "zh": "运行正向控制“一个把安全不变量贯穿部署与运行的可信构建”，并执行包含“依赖替换、未评审变更、构建输入污染、安全测试失败、绕过路径、漏洞发布、回滚和回归”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-10.1-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "10.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-10.1-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "10.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-10.1-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "10.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-10.1-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "10.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-10.1-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "10.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever asset inventory, endpoint/workload platforms, cloud-native controls, image and runtime scanners, update services, exclusions, alerts, and response records change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 资产清单、终端/工作负载平台、云原生控制、镜像与运行时扫描、更新服务、排除项、告警和响应记录 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-10.1-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "10.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Use eligible, enforcing, audit-only, failed, bypassed, excepted, rolled-back, and outcome-verified populations to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 适用、已执行、仅审计、失败、被绕过、例外、已回滚和结果已验证总体 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-10.1-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "10.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Use reviewed, unreviewed, reproducible, provenance-bound, vulnerable, test-failed, exception, deployed-unverified, drifted, rolled-back, and regression-protected releases to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已评审、未评审、可复现、来源绑定、存在漏洞、测试失败、例外、已部署未验证、漂移、已回滚和受回归保护发布物 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "10.2",
      "control": 10,
      "title_en": "Configure Automatic Anti-Malware Signature Updates",
      "title_zh": "恶意软件特征自动更新",
      "first_ig": 1,
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Devices",
      "security_function": "Protect",
      "patterns": [
        "enforcement"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "10.1"
        ],
        "variables": [
          "GV3",
          "GV30",
          "GV32",
          "M1",
          "M2",
          "M3"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "The requirement covers signature, reputation, model, rule and engine content used by each deployed anti-malware product, including offline and update-relay populations.",
          "build": "Use vendor-authenticated channels or controlled mirrors, configure frequent automatic retrieval, monitor content age and failed/rejected updates, stage engine changes where needed and provide a secure offline import workflow.",
          "proof": "Record actual engine/content versions and publisher times, block the update path in a test group and verify alert/recovery, then deliver a known safe detection introduced by a new content set.",
          "boundary": "Air-gapped and intermittently connected assets need bounded manual transfer and receipts."
        },
        "zh": {
          "scope": "覆盖每个反恶意软件使用的签名、声誉、模型、规则和引擎内容，包括离线与更新 Relay 资产。",
          "build": "用厂商认证通道或受控镜像频繁自动取回，监控内容年龄和失败/拒绝，必要时分批引擎变化，并提供安全离线导入；保护代理、证书和仓库设置。",
          "proof": "记录真实引擎/内容版本与发布时间，在测试组阻断更新路径，验证告警/恢复，再投递只有新内容能识别的安全样本；覆盖率用全部有能力资产作分母，不能只看已安装。",
          "boundary": "气隙与间歇在线资产需有期限的手工传输和回执。"
        }
      },
      "category_counts": {
        "outcome": 6,
        "scope": 6,
        "ownership": 6,
        "data": 6,
        "integration": 6,
        "control": 6,
        "timing": 6,
        "exception": 6,
        "evidence": 6,
        "security": 6,
        "testing": 6,
        "operations": 6
      },
      "requirement_count": 72,
      "requirements": [
        {
          "code": "CIS-10.2-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "10.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Configure Automatic Anti-Malware Signature Updates; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“恶意软件特征自动更新”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-10.2-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "10.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 10.2, official Asset Class Devices, Security Function Protect, and IG1 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 10.2、官方资产类别“设备”、安全功能“保护”和首次出现的 IG1，并保存来源抓取日期。"
        },
        {
          "code": "CIS-10.2-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "10.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “The requirement covers signature, reputation, model, rule and engine content used by each deployed anti-malware product, including offline and update-relay populations.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“覆盖每个反恶意软件使用的签名、声誉、模型、规则和引擎内容，包括离线与更新 Relay 资产。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-10.2-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "10.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-10.2-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "10.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Configure Automatic Anti-Malware Signature Updates to its operating object—anti-malware eligibility, deployment, health, content freshness, policy, exclusions, detections, prevention, quarantine, and response—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“恶意软件特征自动更新”连接到其运营对象——反恶意软件适用性、部署、健康、内容新鲜度、策略、排除项、检测、阻断、隔离和响应——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-10.2-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "10.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "For Configure Automatic Anti-Malware Signature Updates, express success as an observable decision over an enforceable allow, deny, contain, quarantine, require, remove, or transform decision at the closest reliable control point; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“恶意软件特征自动更新”，以 在最近可靠控制点执行允许、拒绝、遏制、隔离、强制、移除或转换决策 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-10.2-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "10.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-10.2-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "10.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-10.2-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "10.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-10.2-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "10.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-10.2-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "10.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across unsupported IoT/OT, containers, serverless, offline assets, stale content, behavior-only products, exclusions, tamper, performance modes, and conflicting agents; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 不支持的 IoT/OT、容器、Serverless、离线资产、陈旧内容、纯行为产品、排除项、篡改、性能模式和代理冲突 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-10.2-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "10.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Include audit-only mode, unsupported platforms, local overrides, race conditions, cached state, alternate paths, fail-open behavior, and emergency bypass in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 仅审计模式、不支持平台、本地覆盖、竞态、缓存状态、替代路径、故障开放和紧急绕过 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-10.2-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "10.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-10.2-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "10.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-10.2-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "10.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-10.2-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "10.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-10.2-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "10.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind endpoint and platform engineering, workload owners, security operations, change management, and risk owners to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 终端与平台工程、工作负载责任人、安全运营、变更管理和风险责任人 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-10.2-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "10.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Name who may transition observe → evaluate → decide → enforce → verify outcome → rollback/close, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-10.2-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "10.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-10.2-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "10.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-10.2-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "10.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV3, GV30, GV32, M1, M2, M3) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV3, GV30, GV32, M1, M2, M3）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-10.2-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "10.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-10.2-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "10.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the endpoint and workload protection policy and health authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把终端与工作负载防护策略及健康权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-10.2-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "10.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle observe → evaluate → decide → enforce → verify outcome → rollback/close.",
          "zh": "对生命周期“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-10.2-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "10.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 10.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 10.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-10.2-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "10.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-10.2-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "10.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-10.2-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "10.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-10.2-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "10.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile asset inventory, endpoint/workload platforms, cloud-native controls, image and runtime scanners, update services, exclusions, alerts, and response records and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 资产清单、终端/工作负载平台、云原生控制、镜像与运行时扫描、更新服务、排除项、告警和响应记录，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-10.2-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "10.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Require every connector carrying an enforceable allow, deny, contain, quarantine, require, remove, or transform decision at the closest reliable control point to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 在最近可靠控制点执行允许、拒绝、遏制、隔离、强制、移除或转换决策 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-10.2-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "10.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Use vendor-authenticated channels or controlled mirrors, configure frequent automatic retrieval, monitor content age and failed/rejected updates, stage engine changes where needed and provide a secure offline import workflow.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“用厂商认证通道或受控镜像频繁自动取回，监控内容年龄和失败/拒绝，必要时分批引擎变化，并提供安全离线导入；保护代理、证书和仓库设置。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-10.2-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "10.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-10.2-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "10.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-10.2-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "10.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-10.2-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "10.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the endpoint and workload protection policy and health authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在终端与工作负载防护策略及健康权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-10.2-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "10.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Implement the explicit state machine observe → evaluate → decide → enforce → verify outcome → rollback/close; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-10.2-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "10.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-10.2-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "10.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-10.2-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "10.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-10.2-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "10.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-10.2-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "10.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in anti-malware eligibility, deployment, health, content freshness, policy, exclusions, detections, prevention, quarantine, and response; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 反恶意软件适用性、部署、健康、内容新鲜度、策略、排除项、检测、阻断、隔离和响应 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-10.2-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "10.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for observe → evaluate → decide → enforce → verify outcome → rollback/close; alert before each deadline becomes overdue.",
          "zh": "为“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-10.2-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "10.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “Air-gapped and intermittently connected assets need bounded manual transfer and receipts.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“气隙与间歇在线资产需有期限的手工传输和回执。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-10.2-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "10.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-10.2-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "10.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-10.2-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "10.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-10.2-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "10.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat unsupported IoT/OT, containers, serverless, offline assets, stale content, behavior-only products, exclusions, tamper, performance modes, and conflicting agents as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 不支持的 IoT/OT、容器、Serverless、离线资产、陈旧内容、纯行为产品、排除项、篡改、性能模式和代理冲突 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-10.2-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "10.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Treat audit-only mode, unsupported platforms, local overrides, race conditions, cached state, alternate paths, fail-open behavior, and emergency bypass as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 仅审计模式、不支持平台、本地覆盖、竞态、缓存状态、替代路径、故障开放和紧急绕过 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-10.2-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "10.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Record actual engine/content versions and publisher times, block the update path in a test group and verify alert/recovery, then deliver a known safe detection introduced by a new content set.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“记录真实引擎/内容版本与发布时间，在测试组阻断更新路径，验证告警/恢复，再投递只有新内容能识别的安全样本；覆盖率用全部有能力资产作分母，不能只看已安装。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-10.2-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "10.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-10.2-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "10.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 6 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、6 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-10.2-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "10.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-10.2-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "10.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the endpoint and workload protection policy and health authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以终端与工作负载防护策略及健康权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-10.2-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "10.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Publish eligible, enforcing, audit-only, failed, bypassed, excepted, rolled-back, and outcome-verified populations with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 适用、已执行、仅审计、失败、被绕过、例外、已回滚和结果已验证总体，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-10.2-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "10.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-10.2-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "10.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-10.2-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "10.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-10.2-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "10.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-10.2-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "10.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the endpoint and workload protection policy and health authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护终端与工作负载防护策略及健康权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-10.2-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "10.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Restrict authority to change observe → evaluate → decide → enforce → verify outcome → rollback/close; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-10.2-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "10.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-10.2-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "10.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-10.2-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "10.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-10.2-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "10.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-10.2-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "10.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise safe test artifacts, current and stale content, disabled protection, exclusion abuse, removable media, exploit behavior, quarantine, and update outage through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 安全测试样本、当前与陈旧内容、关闭防护、排除项滥用、可移动介质、利用行为、隔离和更新中断，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-10.2-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "10.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Run the positive control an approved business action that completes through the enforced path; exercise negative, stale, duplicate, bypass, and outage controls including a prohibited action, alternate path, local override, stale policy, control outage, emergency bypass, and rollback failure.",
          "zh": "运行正向控制“通过受控路径完成的一项获批业务动作”，并执行包含“禁止动作、替代路径、本地覆盖、陈旧策略、控制中断、紧急绕过和回滚失败”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-10.2-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "10.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-10.2-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "10.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-10.2-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "10.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-10.2-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "10.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-10.2-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "10.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever asset inventory, endpoint/workload platforms, cloud-native controls, image and runtime scanners, update services, exclusions, alerts, and response records change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 资产清单、终端/工作负载平台、云原生控制、镜像与运行时扫描、更新服务、排除项、告警和响应记录 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-10.2-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "10.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Use eligible, enforcing, audit-only, failed, bypassed, excepted, rolled-back, and outcome-verified populations to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 适用、已执行、仅审计、失败、被绕过、例外、已回滚和结果已验证总体 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "10.3",
      "control": 10,
      "title_en": "Disable Autorun and Autoplay for Removable Media",
      "title_zh": "禁用可移动介质自动运行",
      "first_ig": 1,
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Devices",
      "security_function": "Protect",
      "patterns": [
        "enforcement"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "1.1",
          "4.1"
        ],
        "variables": [
          "GV1",
          "GV3",
          "M1",
          "M2",
          "M3"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "Scope every asset and account path capable of executing content automatically when removable or mounted media appears, including AutoRun/AutoPlay, desktop handlers, virtual media, disk images and device-specific launch functions.",
          "build": "Disable auto-execution through secure baselines, prevent ordinary override and apply to all media types and user profiles.",
          "proof": "Insert safe media containing autorun metadata, mixed content and a virtual-media image under standard and admin users; verify no code launches, policy remains after update/reboot and an attempted change alerts.",
          "boundary": "Disabling the UI prompt is not necessarily disabling handler execution."
        },
        "zh": {
          "scope": "覆盖所有能在可移动/挂载介质出现时自动执行内容的资产和账户路径，包括 AutoRun/AutoPlay、桌面 Handler、虚拟介质、磁盘镜像和设备特定启动功能。",
          "build": "在安全基线禁自动执行，阻止普通用户恢复，覆盖所有介质类型和用户 Profile；结合设备控制、Allowlisting 和扫描，并记录会自动挂虚拟/维修介质的业务流程。",
          "proof": "在普通与管理用户下插入含 Autorun Metadata、混合内容和虚拟介质镜像的安全样本，确认无代码启动，重启/更新后策略仍在，尝试更改会告警；检查有效配置而非分配策略。",
          "boundary": "关掉 UI 提示未必关掉 Handler 执行。"
        }
      },
      "category_counts": {
        "outcome": 6,
        "scope": 6,
        "ownership": 6,
        "data": 6,
        "integration": 6,
        "control": 6,
        "timing": 6,
        "exception": 6,
        "evidence": 6,
        "security": 6,
        "testing": 6,
        "operations": 6
      },
      "requirement_count": 72,
      "requirements": [
        {
          "code": "CIS-10.3-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "10.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Disable Autorun and Autoplay for Removable Media; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“禁用可移动介质自动运行”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-10.3-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "10.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 10.3, official Asset Class Devices, Security Function Protect, and IG1 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 10.3、官方资产类别“设备”、安全功能“保护”和首次出现的 IG1，并保存来源抓取日期。"
        },
        {
          "code": "CIS-10.3-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "10.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Scope every asset and account path capable of executing content automatically when removable or mounted media appears, including AutoRun/AutoPlay, desktop handlers, virtual media, disk images and device-specific launch functions.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“覆盖所有能在可移动/挂载介质出现时自动执行内容的资产和账户路径，包括 AutoRun/AutoPlay、桌面 Handler、虚拟介质、磁盘镜像和设备特定启动功能。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-10.3-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "10.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-10.3-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "10.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Disable Autorun and Autoplay for Removable Media to its operating object—anti-malware eligibility, deployment, health, content freshness, policy, exclusions, detections, prevention, quarantine, and response—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“禁用可移动介质自动运行”连接到其运营对象——反恶意软件适用性、部署、健康、内容新鲜度、策略、排除项、检测、阻断、隔离和响应——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-10.3-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "10.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "For Disable Autorun and Autoplay for Removable Media, express success as an observable decision over an enforceable allow, deny, contain, quarantine, require, remove, or transform decision at the closest reliable control point; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“禁用可移动介质自动运行”，以 在最近可靠控制点执行允许、拒绝、遏制、隔离、强制、移除或转换决策 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-10.3-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "10.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-10.3-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "10.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-10.3-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "10.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-10.3-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "10.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-10.3-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "10.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across unsupported IoT/OT, containers, serverless, offline assets, stale content, behavior-only products, exclusions, tamper, performance modes, and conflicting agents; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 不支持的 IoT/OT、容器、Serverless、离线资产、陈旧内容、纯行为产品、排除项、篡改、性能模式和代理冲突 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-10.3-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "10.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Include audit-only mode, unsupported platforms, local overrides, race conditions, cached state, alternate paths, fail-open behavior, and emergency bypass in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 仅审计模式、不支持平台、本地覆盖、竞态、缓存状态、替代路径、故障开放和紧急绕过 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-10.3-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "10.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-10.3-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "10.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-10.3-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "10.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-10.3-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "10.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-10.3-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "10.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind endpoint and platform engineering, workload owners, security operations, change management, and risk owners to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 终端与平台工程、工作负载责任人、安全运营、变更管理和风险责任人 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-10.3-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "10.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Name who may transition observe → evaluate → decide → enforce → verify outcome → rollback/close, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-10.3-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "10.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-10.3-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "10.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-10.3-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "10.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV1, GV3, M1, M2, M3) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV1, GV3, M1, M2, M3）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-10.3-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "10.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-10.3-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "10.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the endpoint and workload protection policy and health authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把终端与工作负载防护策略及健康权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-10.3-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "10.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle observe → evaluate → decide → enforce → verify outcome → rollback/close.",
          "zh": "对生命周期“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-10.3-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "10.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 1.1, Safeguard 4.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 1.1、Safeguard 4.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-10.3-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "10.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-10.3-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "10.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-10.3-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "10.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-10.3-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "10.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile asset inventory, endpoint/workload platforms, cloud-native controls, image and runtime scanners, update services, exclusions, alerts, and response records and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 资产清单、终端/工作负载平台、云原生控制、镜像与运行时扫描、更新服务、排除项、告警和响应记录，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-10.3-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "10.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Require every connector carrying an enforceable allow, deny, contain, quarantine, require, remove, or transform decision at the closest reliable control point to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 在最近可靠控制点执行允许、拒绝、遏制、隔离、强制、移除或转换决策 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-10.3-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "10.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Disable auto-execution through secure baselines, prevent ordinary override and apply to all media types and user profiles.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“在安全基线禁自动执行，阻止普通用户恢复，覆盖所有介质类型和用户 Profile；结合设备控制、Allowlisting 和扫描，并记录会自动挂虚拟/维修介质的业务流程。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-10.3-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "10.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-10.3-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "10.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-10.3-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "10.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-10.3-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "10.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the endpoint and workload protection policy and health authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在终端与工作负载防护策略及健康权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-10.3-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "10.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Implement the explicit state machine observe → evaluate → decide → enforce → verify outcome → rollback/close; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-10.3-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "10.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-10.3-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "10.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-10.3-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "10.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-10.3-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "10.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-10.3-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "10.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in anti-malware eligibility, deployment, health, content freshness, policy, exclusions, detections, prevention, quarantine, and response; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 反恶意软件适用性、部署、健康、内容新鲜度、策略、排除项、检测、阻断、隔离和响应 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-10.3-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "10.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for observe → evaluate → decide → enforce → verify outcome → rollback/close; alert before each deadline becomes overdue.",
          "zh": "为“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-10.3-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "10.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “Disabling the UI prompt is not necessarily disabling handler execution.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“关掉 UI 提示未必关掉 Handler 执行。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-10.3-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "10.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-10.3-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "10.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-10.3-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "10.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-10.3-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "10.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat unsupported IoT/OT, containers, serverless, offline assets, stale content, behavior-only products, exclusions, tamper, performance modes, and conflicting agents as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 不支持的 IoT/OT、容器、Serverless、离线资产、陈旧内容、纯行为产品、排除项、篡改、性能模式和代理冲突 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-10.3-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "10.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Treat audit-only mode, unsupported platforms, local overrides, race conditions, cached state, alternate paths, fail-open behavior, and emergency bypass as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 仅审计模式、不支持平台、本地覆盖、竞态、缓存状态、替代路径、故障开放和紧急绕过 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-10.3-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "10.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Insert safe media containing autorun metadata, mixed content and a virtual-media image under standard and admin users; verify no code launches, policy remains after update/reboot and an attempted change alerts.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“在普通与管理用户下插入含 Autorun Metadata、混合内容和虚拟介质镜像的安全样本，确认无代码启动，重启/更新后策略仍在，尝试更改会告警；检查有效配置而非分配策略。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-10.3-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "10.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-10.3-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "10.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 5 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、5 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-10.3-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "10.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-10.3-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "10.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the endpoint and workload protection policy and health authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以终端与工作负载防护策略及健康权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-10.3-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "10.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Publish eligible, enforcing, audit-only, failed, bypassed, excepted, rolled-back, and outcome-verified populations with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 适用、已执行、仅审计、失败、被绕过、例外、已回滚和结果已验证总体，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-10.3-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "10.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-10.3-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "10.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-10.3-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "10.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-10.3-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "10.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-10.3-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "10.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the endpoint and workload protection policy and health authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护终端与工作负载防护策略及健康权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-10.3-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "10.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Restrict authority to change observe → evaluate → decide → enforce → verify outcome → rollback/close; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-10.3-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "10.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-10.3-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "10.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-10.3-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "10.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-10.3-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "10.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-10.3-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "10.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise safe test artifacts, current and stale content, disabled protection, exclusion abuse, removable media, exploit behavior, quarantine, and update outage through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 安全测试样本、当前与陈旧内容、关闭防护、排除项滥用、可移动介质、利用行为、隔离和更新中断，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-10.3-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "10.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Run the positive control an approved business action that completes through the enforced path; exercise negative, stale, duplicate, bypass, and outage controls including a prohibited action, alternate path, local override, stale policy, control outage, emergency bypass, and rollback failure.",
          "zh": "运行正向控制“通过受控路径完成的一项获批业务动作”，并执行包含“禁止动作、替代路径、本地覆盖、陈旧策略、控制中断、紧急绕过和回滚失败”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-10.3-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "10.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-10.3-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "10.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-10.3-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "10.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-10.3-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "10.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-10.3-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "10.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever asset inventory, endpoint/workload platforms, cloud-native controls, image and runtime scanners, update services, exclusions, alerts, and response records change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 资产清单、终端/工作负载平台、云原生控制、镜像与运行时扫描、更新服务、排除项、告警和响应记录 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-10.3-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "10.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Use eligible, enforcing, audit-only, failed, bypassed, excepted, rolled-back, and outcome-verified populations to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 适用、已执行、仅审计、失败、被绕过、例外、已回滚和结果已验证总体 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "10.4",
      "control": 10,
      "title_en": "Configure Automatic Anti-Malware Scanning of Removable Media",
      "title_zh": "可移动介质自动扫描",
      "first_ig": 2,
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Devices",
      "security_function": "Detect",
      "patterns": [
        "enforcement"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "4.1",
          "10.1"
        ],
        "variables": [
          "GV3",
          "GV30",
          "GV32",
          "M1",
          "M2",
          "M3"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "Eligible assets are those that accept removable media and run supported anti-malware protection; media, virtual mounts and encrypted volumes must be accounted for.",
          "build": "Configure scan-on-mount or before-open, current content and quarantine, block access until completion for higher-risk zones, and log media/device identity and result.",
          "proof": "Insert clean, safe test-detection, nested archive and encrypted media; verify access sequencing, detection/quarantine, user notice and central log.",
          "boundary": "Large media can cause unacceptable delay; define size/time behavior without silently skipping."
        },
        "zh": {
          "scope": "合格资产是既接受可移动介质又运行受支持反恶意软件的设备；介质、虚拟挂载和加密卷都要算。",
          "build": "配置挂载即扫或打开前扫，保持内容当前并隔离；高风险区完成前阻断访问，记录介质/设备身份和结果。",
          "proof": "插入干净、安全检测、嵌套包和加密介质，验证访问顺序、检测/隔离、通知和中央日志。",
          "boundary": "大介质会导致延迟，需定义大小/超时行为而不能静默跳过。"
        }
      },
      "category_counts": {
        "outcome": 6,
        "scope": 6,
        "ownership": 6,
        "data": 6,
        "integration": 6,
        "control": 6,
        "timing": 6,
        "exception": 6,
        "evidence": 6,
        "security": 6,
        "testing": 6,
        "operations": 6
      },
      "requirement_count": 72,
      "requirements": [
        {
          "code": "CIS-10.4-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "10.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Configure Automatic Anti-Malware Scanning of Removable Media; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“可移动介质自动扫描”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-10.4-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "10.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 10.4, official Asset Class Devices, Security Function Detect, and IG2 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 10.4、官方资产类别“设备”、安全功能“检测”和首次出现的 IG2，并保存来源抓取日期。"
        },
        {
          "code": "CIS-10.4-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "10.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Eligible assets are those that accept removable media and run supported anti-malware protection; media, virtual mounts and encrypted volumes must be accounted for.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“合格资产是既接受可移动介质又运行受支持反恶意软件的设备；介质、虚拟挂载和加密卷都要算。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-10.4-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "10.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-10.4-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "10.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Configure Automatic Anti-Malware Scanning of Removable Media to its operating object—anti-malware eligibility, deployment, health, content freshness, policy, exclusions, detections, prevention, quarantine, and response—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“可移动介质自动扫描”连接到其运营对象——反恶意软件适用性、部署、健康、内容新鲜度、策略、排除项、检测、阻断、隔离和响应——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-10.4-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "10.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "For Configure Automatic Anti-Malware Scanning of Removable Media, express success as an observable decision over an enforceable allow, deny, contain, quarantine, require, remove, or transform decision at the closest reliable control point; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“可移动介质自动扫描”，以 在最近可靠控制点执行允许、拒绝、遏制、隔离、强制、移除或转换决策 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-10.4-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "10.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-10.4-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "10.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-10.4-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "10.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-10.4-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "10.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-10.4-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "10.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across unsupported IoT/OT, containers, serverless, offline assets, stale content, behavior-only products, exclusions, tamper, performance modes, and conflicting agents; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 不支持的 IoT/OT、容器、Serverless、离线资产、陈旧内容、纯行为产品、排除项、篡改、性能模式和代理冲突 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-10.4-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "10.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Include audit-only mode, unsupported platforms, local overrides, race conditions, cached state, alternate paths, fail-open behavior, and emergency bypass in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 仅审计模式、不支持平台、本地覆盖、竞态、缓存状态、替代路径、故障开放和紧急绕过 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-10.4-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "10.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-10.4-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "10.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-10.4-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "10.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-10.4-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "10.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-10.4-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "10.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind endpoint and platform engineering, workload owners, security operations, change management, and risk owners to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 终端与平台工程、工作负载责任人、安全运营、变更管理和风险责任人 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-10.4-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "10.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Name who may transition observe → evaluate → decide → enforce → verify outcome → rollback/close, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-10.4-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "10.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-10.4-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "10.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-10.4-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "10.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV3, GV30, GV32, M1, M2, M3) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV3, GV30, GV32, M1, M2, M3）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-10.4-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "10.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-10.4-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "10.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the endpoint and workload protection policy and health authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把终端与工作负载防护策略及健康权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-10.4-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "10.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle observe → evaluate → decide → enforce → verify outcome → rollback/close.",
          "zh": "对生命周期“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-10.4-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "10.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 4.1, Safeguard 10.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 4.1、Safeguard 10.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-10.4-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "10.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-10.4-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "10.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-10.4-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "10.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-10.4-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "10.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile asset inventory, endpoint/workload platforms, cloud-native controls, image and runtime scanners, update services, exclusions, alerts, and response records and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 资产清单、终端/工作负载平台、云原生控制、镜像与运行时扫描、更新服务、排除项、告警和响应记录，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-10.4-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "10.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Require every connector carrying an enforceable allow, deny, contain, quarantine, require, remove, or transform decision at the closest reliable control point to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 在最近可靠控制点执行允许、拒绝、遏制、隔离、强制、移除或转换决策 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-10.4-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "10.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Configure scan-on-mount or before-open, current content and quarantine, block access until completion for higher-risk zones, and log media/device identity and result.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“配置挂载即扫或打开前扫，保持内容当前并隔离；高风险区完成前阻断访问，记录介质/设备身份和结果。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-10.4-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "10.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-10.4-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "10.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-10.4-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "10.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-10.4-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "10.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the endpoint and workload protection policy and health authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在终端与工作负载防护策略及健康权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-10.4-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "10.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Implement the explicit state machine observe → evaluate → decide → enforce → verify outcome → rollback/close; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-10.4-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "10.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-10.4-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "10.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-10.4-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "10.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-10.4-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "10.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-10.4-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "10.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in anti-malware eligibility, deployment, health, content freshness, policy, exclusions, detections, prevention, quarantine, and response; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 反恶意软件适用性、部署、健康、内容新鲜度、策略、排除项、检测、阻断、隔离和响应 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-10.4-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "10.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for observe → evaluate → decide → enforce → verify outcome → rollback/close; alert before each deadline becomes overdue.",
          "zh": "为“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-10.4-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "10.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “Large media can cause unacceptable delay; define size/time behavior without silently skipping.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“大介质会导致延迟，需定义大小/超时行为而不能静默跳过。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-10.4-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "10.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-10.4-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "10.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-10.4-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "10.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-10.4-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "10.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat unsupported IoT/OT, containers, serverless, offline assets, stale content, behavior-only products, exclusions, tamper, performance modes, and conflicting agents as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 不支持的 IoT/OT、容器、Serverless、离线资产、陈旧内容、纯行为产品、排除项、篡改、性能模式和代理冲突 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-10.4-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "10.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Treat audit-only mode, unsupported platforms, local overrides, race conditions, cached state, alternate paths, fail-open behavior, and emergency bypass as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 仅审计模式、不支持平台、本地覆盖、竞态、缓存状态、替代路径、故障开放和紧急绕过 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-10.4-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "10.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Insert clean, safe test-detection, nested archive and encrypted media; verify access sequencing, detection/quarantine, user notice and central log.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“插入干净、安全检测、嵌套包和加密介质，验证访问顺序、检测/隔离、通知和中央日志。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-10.4-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "10.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-10.4-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "10.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 6 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、6 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-10.4-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "10.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-10.4-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "10.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the endpoint and workload protection policy and health authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以终端与工作负载防护策略及健康权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-10.4-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "10.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Publish eligible, enforcing, audit-only, failed, bypassed, excepted, rolled-back, and outcome-verified populations with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 适用、已执行、仅审计、失败、被绕过、例外、已回滚和结果已验证总体，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-10.4-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "10.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-10.4-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "10.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-10.4-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "10.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-10.4-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "10.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-10.4-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "10.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the endpoint and workload protection policy and health authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护终端与工作负载防护策略及健康权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-10.4-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "10.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Restrict authority to change observe → evaluate → decide → enforce → verify outcome → rollback/close; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-10.4-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "10.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-10.4-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "10.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-10.4-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "10.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-10.4-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "10.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-10.4-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "10.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise safe test artifacts, current and stale content, disabled protection, exclusion abuse, removable media, exploit behavior, quarantine, and update outage through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 安全测试样本、当前与陈旧内容、关闭防护、排除项滥用、可移动介质、利用行为、隔离和更新中断，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-10.4-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "10.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Run the positive control an approved business action that completes through the enforced path; exercise negative, stale, duplicate, bypass, and outage controls including a prohibited action, alternate path, local override, stale policy, control outage, emergency bypass, and rollback failure.",
          "zh": "运行正向控制“通过受控路径完成的一项获批业务动作”，并执行包含“禁止动作、替代路径、本地覆盖、陈旧策略、控制中断、紧急绕过和回滚失败”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-10.4-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "10.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-10.4-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "10.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-10.4-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "10.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-10.4-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "10.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-10.4-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "10.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever asset inventory, endpoint/workload platforms, cloud-native controls, image and runtime scanners, update services, exclusions, alerts, and response records change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 资产清单、终端/工作负载平台、云原生控制、镜像与运行时扫描、更新服务、排除项、告警和响应记录 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-10.4-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "10.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Use eligible, enforcing, audit-only, failed, bypassed, excepted, rolled-back, and outcome-verified populations to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 适用、已执行、仅审计、失败、被绕过、例外、已回滚和结果已验证总体 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "10.5",
      "control": 10,
      "title_en": "Enable Anti-Exploitation Features",
      "title_zh": "反利用缓解",
      "first_ig": 2,
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Devices",
      "security_function": "Protect",
      "patterns": [
        "enforcement"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "1.1",
          "4.1"
        ],
        "variables": [
          "GV1",
          "GV3",
          "M1",
          "M2",
          "M3"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "Scope hardware, OS, runtime, browser and application mitigations such as DEP/NX, ASLR, control-flow protection, sandboxing, code signing and platform integrity on every supported asset/software role.",
          "build": "Enable supported mitigations through baselines and build/runtime policy, test application compatibility, prevent downgrade and record narrowly scoped per-process exceptions.",
          "proof": "Inspect effective runtime state and launch benign compatibility/exploit-mitigation test fixtures in a lab, verifying prevention and telemetry.",
          "boundary": "A feature enabled globally may be disabled for the vulnerable process; legacy applications can require exceptions."
        },
        "zh": {
          "scope": "覆盖硬件、OS、Runtime、浏览器和应用的 DEP/NX、ASLR、控制流保护、沙箱、代码签名、平台完整性等缓解；默认能力因架构、编译器、兼容与工作负载而异。",
          "build": "通过基线与构建/运行策略启用支持功能，做应用兼容，阻止降级，并记录窄的逐进程例外；持续更新 OS、固件和应用，因为缓解依赖实现，不能修复所有漏洞。",
          "proof": "检查真实运行状态，在实验室运行无害兼容/缓解 Fixture，验证阻断和遥测；尝试关闭功能测篡改发现。",
          "boundary": "全局启用可能在易受害进程上被关闭；旧应用可有例外。"
        }
      },
      "category_counts": {
        "outcome": 6,
        "scope": 6,
        "ownership": 6,
        "data": 6,
        "integration": 6,
        "control": 6,
        "timing": 6,
        "exception": 6,
        "evidence": 6,
        "security": 6,
        "testing": 6,
        "operations": 6
      },
      "requirement_count": 72,
      "requirements": [
        {
          "code": "CIS-10.5-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "10.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Enable Anti-Exploitation Features; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“反利用缓解”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-10.5-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "10.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 10.5, official Asset Class Devices, Security Function Protect, and IG2 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 10.5、官方资产类别“设备”、安全功能“保护”和首次出现的 IG2，并保存来源抓取日期。"
        },
        {
          "code": "CIS-10.5-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "10.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Scope hardware, OS, runtime, browser and application mitigations such as DEP/NX, ASLR, control-flow protection, sandboxing, code signing and platform integrity on every supported asset/software role.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“覆盖硬件、OS、Runtime、浏览器和应用的 DEP/NX、ASLR、控制流保护、沙箱、代码签名、平台完整性等缓解；默认能力因架构、编译器、兼容与工作负载而异。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-10.5-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "10.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-10.5-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "10.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Enable Anti-Exploitation Features to its operating object—anti-malware eligibility, deployment, health, content freshness, policy, exclusions, detections, prevention, quarantine, and response—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“反利用缓解”连接到其运营对象——反恶意软件适用性、部署、健康、内容新鲜度、策略、排除项、检测、阻断、隔离和响应——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-10.5-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "10.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "For Enable Anti-Exploitation Features, express success as an observable decision over an enforceable allow, deny, contain, quarantine, require, remove, or transform decision at the closest reliable control point; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“反利用缓解”，以 在最近可靠控制点执行允许、拒绝、遏制、隔离、强制、移除或转换决策 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-10.5-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "10.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-10.5-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "10.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-10.5-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "10.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-10.5-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "10.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-10.5-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "10.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across unsupported IoT/OT, containers, serverless, offline assets, stale content, behavior-only products, exclusions, tamper, performance modes, and conflicting agents; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 不支持的 IoT/OT、容器、Serverless、离线资产、陈旧内容、纯行为产品、排除项、篡改、性能模式和代理冲突 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-10.5-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "10.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Include audit-only mode, unsupported platforms, local overrides, race conditions, cached state, alternate paths, fail-open behavior, and emergency bypass in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 仅审计模式、不支持平台、本地覆盖、竞态、缓存状态、替代路径、故障开放和紧急绕过 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-10.5-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "10.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-10.5-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "10.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-10.5-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "10.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-10.5-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "10.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-10.5-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "10.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind endpoint and platform engineering, workload owners, security operations, change management, and risk owners to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 终端与平台工程、工作负载责任人、安全运营、变更管理和风险责任人 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-10.5-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "10.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Name who may transition observe → evaluate → decide → enforce → verify outcome → rollback/close, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-10.5-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "10.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-10.5-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "10.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-10.5-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "10.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV1, GV3, M1, M2, M3) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV1, GV3, M1, M2, M3）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-10.5-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "10.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-10.5-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "10.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the endpoint and workload protection policy and health authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把终端与工作负载防护策略及健康权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-10.5-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "10.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle observe → evaluate → decide → enforce → verify outcome → rollback/close.",
          "zh": "对生命周期“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-10.5-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "10.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 1.1, Safeguard 4.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 1.1、Safeguard 4.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-10.5-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "10.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-10.5-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "10.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-10.5-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "10.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-10.5-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "10.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile asset inventory, endpoint/workload platforms, cloud-native controls, image and runtime scanners, update services, exclusions, alerts, and response records and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 资产清单、终端/工作负载平台、云原生控制、镜像与运行时扫描、更新服务、排除项、告警和响应记录，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-10.5-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "10.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Require every connector carrying an enforceable allow, deny, contain, quarantine, require, remove, or transform decision at the closest reliable control point to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 在最近可靠控制点执行允许、拒绝、遏制、隔离、强制、移除或转换决策 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-10.5-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "10.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Enable supported mitigations through baselines and build/runtime policy, test application compatibility, prevent downgrade and record narrowly scoped per-process exceptions.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“通过基线与构建/运行策略启用支持功能，做应用兼容，阻止降级，并记录窄的逐进程例外；持续更新 OS、固件和应用，因为缓解依赖实现，不能修复所有漏洞。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-10.5-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "10.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-10.5-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "10.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-10.5-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "10.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-10.5-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "10.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the endpoint and workload protection policy and health authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在终端与工作负载防护策略及健康权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-10.5-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "10.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Implement the explicit state machine observe → evaluate → decide → enforce → verify outcome → rollback/close; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-10.5-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "10.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-10.5-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "10.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-10.5-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "10.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-10.5-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "10.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-10.5-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "10.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in anti-malware eligibility, deployment, health, content freshness, policy, exclusions, detections, prevention, quarantine, and response; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 反恶意软件适用性、部署、健康、内容新鲜度、策略、排除项、检测、阻断、隔离和响应 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-10.5-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "10.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for observe → evaluate → decide → enforce → verify outcome → rollback/close; alert before each deadline becomes overdue.",
          "zh": "为“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-10.5-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "10.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “A feature enabled globally may be disabled for the vulnerable process; legacy applications can require exceptions.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“全局启用可能在易受害进程上被关闭；旧应用可有例外。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-10.5-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "10.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-10.5-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "10.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-10.5-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "10.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-10.5-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "10.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat unsupported IoT/OT, containers, serverless, offline assets, stale content, behavior-only products, exclusions, tamper, performance modes, and conflicting agents as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 不支持的 IoT/OT、容器、Serverless、离线资产、陈旧内容、纯行为产品、排除项、篡改、性能模式和代理冲突 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-10.5-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "10.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Treat audit-only mode, unsupported platforms, local overrides, race conditions, cached state, alternate paths, fail-open behavior, and emergency bypass as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 仅审计模式、不支持平台、本地覆盖、竞态、缓存状态、替代路径、故障开放和紧急绕过 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-10.5-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "10.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Inspect effective runtime state and launch benign compatibility/exploit-mitigation test fixtures in a lab, verifying prevention and telemetry.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“检查真实运行状态，在实验室运行无害兼容/缓解 Fixture，验证阻断和遥测；尝试关闭功能测篡改发现。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-10.5-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "10.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-10.5-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "10.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 5 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、5 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-10.5-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "10.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-10.5-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "10.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the endpoint and workload protection policy and health authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以终端与工作负载防护策略及健康权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-10.5-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "10.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Publish eligible, enforcing, audit-only, failed, bypassed, excepted, rolled-back, and outcome-verified populations with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 适用、已执行、仅审计、失败、被绕过、例外、已回滚和结果已验证总体，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-10.5-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "10.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-10.5-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "10.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-10.5-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "10.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-10.5-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "10.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-10.5-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "10.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the endpoint and workload protection policy and health authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护终端与工作负载防护策略及健康权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-10.5-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "10.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Restrict authority to change observe → evaluate → decide → enforce → verify outcome → rollback/close; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-10.5-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "10.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-10.5-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "10.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-10.5-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "10.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-10.5-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "10.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-10.5-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "10.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise safe test artifacts, current and stale content, disabled protection, exclusion abuse, removable media, exploit behavior, quarantine, and update outage through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 安全测试样本、当前与陈旧内容、关闭防护、排除项滥用、可移动介质、利用行为、隔离和更新中断，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-10.5-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "10.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Run the positive control an approved business action that completes through the enforced path; exercise negative, stale, duplicate, bypass, and outage controls including a prohibited action, alternate path, local override, stale policy, control outage, emergency bypass, and rollback failure.",
          "zh": "运行正向控制“通过受控路径完成的一项获批业务动作”，并执行包含“禁止动作、替代路径、本地覆盖、陈旧策略、控制中断、紧急绕过和回滚失败”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-10.5-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "10.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-10.5-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "10.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-10.5-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "10.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-10.5-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "10.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-10.5-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "10.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever asset inventory, endpoint/workload platforms, cloud-native controls, image and runtime scanners, update services, exclusions, alerts, and response records change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 资产清单、终端/工作负载平台、云原生控制、镜像与运行时扫描、更新服务、排除项、告警和响应记录 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-10.5-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "10.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Use eligible, enforcing, audit-only, failed, bypassed, excepted, rolled-back, and outcome-verified populations to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 适用、已执行、仅审计、失败、被绕过、例外、已回滚和结果已验证总体 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "10.6",
      "control": 10,
      "title_en": "Centrally Manage Anti-Malware Software",
      "title_zh": "集中管理反恶意软件",
      "first_ig": 2,
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Devices",
      "security_function": "Protect",
      "patterns": [
        "enforcement",
        "software_dev"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "1.1",
          "2.1",
          "10.1"
        ],
        "variables": [
          "GV30",
          "GV31",
          "M1",
          "M2",
          "M3"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "Central management covers policy, health, updates, detections, response, exclusions and tamper state for every deployed product and tenant.",
          "build": "Enroll assets automatically, use role-based protected administration, standardize policies, monitor heartbeats and drift, integrate incident workflows and retain emergency rollback.",
          "proof": "Change a test policy, isolate or scan a canary endpoint, then verify delivery, result and rollback.",
          "boundary": "Multiple consoles may be necessary across sovereign, OT or provider boundaries but require federated inventory and response."
        },
        "zh": {
          "scope": "中央管理覆盖所有部署产品/租户的策略、健康、更新、检测、响应、排除与防篡改；只数多少产品“中央配置”，会漏掉未管资产和断连 Agent。",
          "build": "自动注册资产，以 RBAC 保护管理，标准化策略，监测心跳/漂移，接入事件流程并保留紧急回滚；Console 与资产台账双向对账，必要时分离安全管理与终端管理。",
          "proof": "对金丝雀端点下发策略、隔离或扫描并验证送达、结果与回滚；停 Agent、克隆身份、断连设备测试陈旧/重复发现。",
          "boundary": "主权、OT 或服务商边界可能需要多个 Console，但需联邦台账与响应。"
        }
      },
      "category_counts": {
        "outcome": 7,
        "scope": 7,
        "ownership": 7,
        "data": 7,
        "integration": 7,
        "control": 7,
        "timing": 7,
        "exception": 7,
        "evidence": 7,
        "security": 7,
        "testing": 7,
        "operations": 7
      },
      "requirement_count": 84,
      "requirements": [
        {
          "code": "CIS-10.6-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "10.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Centrally Manage Anti-Malware Software; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“集中管理反恶意软件”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-10.6-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "10.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 10.6, official Asset Class Devices, Security Function Protect, and IG2 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 10.6、官方资产类别“设备”、安全功能“保护”和首次出现的 IG2，并保存来源抓取日期。"
        },
        {
          "code": "CIS-10.6-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "10.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Central management covers policy, health, updates, detections, response, exclusions and tamper state for every deployed product and tenant.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“中央管理覆盖所有部署产品/租户的策略、健康、更新、检测、响应、排除与防篡改；只数多少产品“中央配置”，会漏掉未管资产和断连 Agent。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-10.6-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "10.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-10.6-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "10.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Centrally Manage Anti-Malware Software to its operating object—anti-malware eligibility, deployment, health, content freshness, policy, exclusions, detections, prevention, quarantine, and response—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“集中管理反恶意软件”连接到其运营对象——反恶意软件适用性、部署、健康、内容新鲜度、策略、排除项、检测、阻断、隔离和响应——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-10.6-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "10.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "For Centrally Manage Anti-Malware Software, express success as an observable decision over an enforceable allow, deny, contain, quarantine, require, remove, or transform decision at the closest reliable control point; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“集中管理反恶意软件”，以 在最近可靠控制点执行允许、拒绝、遏制、隔离、强制、移除或转换决策 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-10.6-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "10.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "For Centrally Manage Anti-Malware Software, express success as an observable decision over source-to-production software identity, design invariant, component trust, build provenance, test result, deployment state, runtime outcome, and vulnerability response; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“集中管理反恶意软件”，以 从源码到生产的软件身份、设计不变量、组件信任、构建来源、测试结果、部署状态、运行结果和漏洞响应 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-10.6-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "10.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-10.6-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "10.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-10.6-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "10.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-10.6-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "10.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-10.6-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "10.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across unsupported IoT/OT, containers, serverless, offline assets, stale content, behavior-only products, exclusions, tamper, performance modes, and conflicting agents; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 不支持的 IoT/OT、容器、Serverless、离线资产、陈旧内容、纯行为产品、排除项、篡改、性能模式和代理冲突 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-10.6-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "10.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Include audit-only mode, unsupported platforms, local overrides, race conditions, cached state, alternate paths, fail-open behavior, and emergency bypass in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 仅审计模式、不支持平台、本地覆盖、竞态、缓存状态、替代路径、故障开放和紧急绕过 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-10.6-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "10.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Include generated and copied code, forks, vendoring, transitive dependencies, mutable tags, build plugins, feature flags, tenant logic, secrets, emergency release, and provider components in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 生成与复制代码、分叉、vendoring、传递依赖、可变标签、构建插件、功能开关、租户逻辑、秘密、紧急发布和提供商组件 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-10.6-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "10.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-10.6-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "10.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-10.6-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "10.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-10.6-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "10.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-10.6-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "10.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind endpoint and platform engineering, workload owners, security operations, change management, and risk owners to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 终端与平台工程、工作负载责任人、安全运营、变更管理和风险责任人 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-10.6-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "10.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Name who may transition observe → evaluate → decide → enforce → verify outcome → rollback/close, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-10.6-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "10.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Name who may transition designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-10.6-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "10.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-10.6-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "10.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-10.6-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "10.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV30, GV31, M1, M2, M3) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV30, GV31, M1, M2, M3）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-10.6-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "10.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-10.6-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "10.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the endpoint and workload protection policy and health authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把终端与工作负载防护策略及健康权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-10.6-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "10.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle observe → evaluate → decide → enforce → verify outcome → rollback/close.",
          "zh": "对生命周期“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-10.6-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "10.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired.",
          "zh": "对生命周期“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-10.6-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "10.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 1.1, Safeguard 2.1, Safeguard 10.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 1.1、Safeguard 2.1、Safeguard 10.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-10.6-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "10.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-10.6-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "10.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-10.6-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "10.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-10.6-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "10.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile asset inventory, endpoint/workload platforms, cloud-native controls, image and runtime scanners, update services, exclusions, alerts, and response records and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 资产清单、终端/工作负载平台、云原生控制、镜像与运行时扫描、更新服务、排除项、告警和响应记录，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-10.6-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "10.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Require every connector carrying an enforceable allow, deny, contain, quarantine, require, remove, or transform decision at the closest reliable control point to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 在最近可靠控制点执行允许、拒绝、遏制、隔离、强制、移除或转换决策 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-10.6-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "10.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Require every connector carrying source-to-production software identity, design invariant, component trust, build provenance, test result, deployment state, runtime outcome, and vulnerability response to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 从源码到生产的软件身份、设计不变量、组件信任、构建来源、测试结果、部署状态、运行结果和漏洞响应 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-10.6-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "10.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Enroll assets automatically, use role-based protected administration, standardize policies, monitor heartbeats and drift, integrate incident workflows and retain emergency rollback.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“自动注册资产，以 RBAC 保护管理，标准化策略，监测心跳/漂移，接入事件流程并保留紧急回滚；Console 与资产台账双向对账，必要时分离安全管理与终端管理。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-10.6-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "10.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-10.6-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "10.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-10.6-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "10.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-10.6-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "10.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the endpoint and workload protection policy and health authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在终端与工作负载防护策略及健康权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-10.6-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "10.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Implement the explicit state machine observe → evaluate → decide → enforce → verify outcome → rollback/close; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-10.6-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "10.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Implement the explicit state machine designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-10.6-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "10.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-10.6-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "10.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-10.6-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "10.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-10.6-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "10.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-10.6-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "10.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in anti-malware eligibility, deployment, health, content freshness, policy, exclusions, detections, prevention, quarantine, and response; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 反恶意软件适用性、部署、健康、内容新鲜度、策略、排除项、检测、阻断、隔离和响应 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-10.6-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "10.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for observe → evaluate → decide → enforce → verify outcome → rollback/close; alert before each deadline becomes overdue.",
          "zh": "为“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-10.6-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "10.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; alert before each deadline becomes overdue.",
          "zh": "为“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-10.6-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "10.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “Multiple consoles may be necessary across sovereign, OT or provider boundaries but require federated inventory and response.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“主权、OT 或服务商边界可能需要多个 Console，但需联邦台账与响应。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-10.6-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "10.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-10.6-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "10.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-10.6-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "10.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-10.6-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "10.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat unsupported IoT/OT, containers, serverless, offline assets, stale content, behavior-only products, exclusions, tamper, performance modes, and conflicting agents as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 不支持的 IoT/OT、容器、Serverless、离线资产、陈旧内容、纯行为产品、排除项、篡改、性能模式和代理冲突 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-10.6-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "10.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Treat audit-only mode, unsupported platforms, local overrides, race conditions, cached state, alternate paths, fail-open behavior, and emergency bypass as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 仅审计模式、不支持平台、本地覆盖、竞态、缓存状态、替代路径、故障开放和紧急绕过 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-10.6-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "10.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Treat generated and copied code, forks, vendoring, transitive dependencies, mutable tags, build plugins, feature flags, tenant logic, secrets, emergency release, and provider components as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 生成与复制代码、分叉、vendoring、传递依赖、可变标签、构建插件、功能开关、租户逻辑、秘密、紧急发布和提供商组件 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-10.6-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "10.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Change a test policy, isolate or scan a canary endpoint, then verify delivery, result and rollback.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“对金丝雀端点下发策略、隔离或扫描并验证送达、结果与回滚；停 Agent、克隆身份、断连设备测试陈旧/重复发现。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-10.6-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "10.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-10.6-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "10.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 5 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、5 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-10.6-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "10.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-10.6-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "10.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the endpoint and workload protection policy and health authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以终端与工作负载防护策略及健康权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-10.6-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "10.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Publish eligible, enforcing, audit-only, failed, bypassed, excepted, rolled-back, and outcome-verified populations with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 适用、已执行、仅审计、失败、被绕过、例外、已回滚和结果已验证总体，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-10.6-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "10.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Publish reviewed, unreviewed, reproducible, provenance-bound, vulnerable, test-failed, exception, deployed-unverified, drifted, rolled-back, and regression-protected releases with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已评审、未评审、可复现、来源绑定、存在漏洞、测试失败、例外、已部署未验证、漂移、已回滚和受回归保护发布物，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-10.6-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "10.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-10.6-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "10.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-10.6-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "10.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-10.6-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "10.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-10.6-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "10.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the endpoint and workload protection policy and health authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护终端与工作负载防护策略及健康权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-10.6-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "10.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Restrict authority to change observe → evaluate → decide → enforce → verify outcome → rollback/close; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-10.6-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "10.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Restrict authority to change designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-10.6-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "10.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-10.6-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "10.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-10.6-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "10.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-10.6-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "10.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-10.6-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "10.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise safe test artifacts, current and stale content, disabled protection, exclusion abuse, removable media, exploit behavior, quarantine, and update outage through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 安全测试样本、当前与陈旧内容、关闭防护、排除项滥用、可移动介质、利用行为、隔离和更新中断，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-10.6-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "10.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Run the positive control an approved business action that completes through the enforced path; exercise negative, stale, duplicate, bypass, and outage controls including a prohibited action, alternate path, local override, stale policy, control outage, emergency bypass, and rollback failure.",
          "zh": "运行正向控制“通过受控路径完成的一项获批业务动作”，并执行包含“禁止动作、替代路径、本地覆盖、陈旧策略、控制中断、紧急绕过和回滚失败”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-10.6-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "10.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Run the positive control a trusted build that preserves the security invariant through deployment and runtime; exercise negative, stale, duplicate, bypass, and outage controls including a substituted dependency, unreviewed change, poisoned build input, failed security test, bypass path, vulnerable release, rollback, and regression.",
          "zh": "运行正向控制“一个把安全不变量贯穿部署与运行的可信构建”，并执行包含“依赖替换、未评审变更、构建输入污染、安全测试失败、绕过路径、漏洞发布、回滚和回归”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-10.6-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "10.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-10.6-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "10.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-10.6-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "10.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-10.6-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "10.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-10.6-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "10.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever asset inventory, endpoint/workload platforms, cloud-native controls, image and runtime scanners, update services, exclusions, alerts, and response records change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 资产清单、终端/工作负载平台、云原生控制、镜像与运行时扫描、更新服务、排除项、告警和响应记录 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-10.6-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "10.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Use eligible, enforcing, audit-only, failed, bypassed, excepted, rolled-back, and outcome-verified populations to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 适用、已执行、仅审计、失败、被绕过、例外、已回滚和结果已验证总体 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-10.6-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "10.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Use reviewed, unreviewed, reproducible, provenance-bound, vulnerable, test-failed, exception, deployed-unverified, drifted, rolled-back, and regression-protected releases to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已评审、未评审、可复现、来源绑定、存在漏洞、测试失败、例外、已部署未验证、漂移、已回滚和受回归保护发布物 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "10.7",
      "control": 10,
      "title_en": "Use Behavior-Based Anti-Malware Software",
      "title_zh": "基于行为的恶意软件防护",
      "first_ig": 2,
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Devices",
      "security_function": "Detect",
      "patterns": [
        "enforcement",
        "software_dev"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "1.1",
          "2.1",
          "4.1"
        ],
        "variables": [
          "GV1",
          "GV3",
          "GV5",
          "M1",
          "M2",
          "M3",
          "M4",
          "M5"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "Include assets and workloads where behavior telemetry and prevention can observe process, memory, file, identity or network actions; declare which platforms, containers, cloud workloads and scripts are covered.",
          "build": "Enable behavior/EDR capabilities, tune prevention by asset role, protect sensors, centralize high-fidelity telemetry and connect containment to incident response.",
          "proof": "Run safe simulations of suspicious child processes, credential-access-like behavior, persistence and ransomware-like file activity under approved test scope, alongside benign administrative controls.",
          "boundary": "Behavior products can miss living-off-the-land, kernel, cloud-control-plane and low-and-slow activity and can generate false positives."
        },
        "zh": {
          "scope": "包括行为遥测/防护能观察进程、内存、文件、身份或网络动作的资产/工作负载，明确平台、容器、云和脚本覆盖。",
          "build": "启用行为/EDR，按资产角色调优防护，保护 Sensor，集中高保真遥测并连接遏制；设基线与例外，不能整类抑制技术或忽略可信父进程滥用。",
          "proof": "在批准范围安全模拟可疑子进程、凭据访问类行为、持久化和勒索式文件活动，同时跑正常管理员对照；验证检测/阻断/遏制、证据与分析动作，并记录端点安全状态和版本。",
          "boundary": "行为产品会漏 Living-off-the-land、内核、云控制面和低慢活动，也会误报。"
        }
      },
      "category_counts": {
        "outcome": 7,
        "scope": 7,
        "ownership": 7,
        "data": 7,
        "integration": 7,
        "control": 7,
        "timing": 7,
        "exception": 7,
        "evidence": 7,
        "security": 7,
        "testing": 7,
        "operations": 7
      },
      "requirement_count": 84,
      "requirements": [
        {
          "code": "CIS-10.7-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "10.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Use Behavior-Based Anti-Malware Software; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“基于行为的恶意软件防护”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-10.7-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "10.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 10.7, official Asset Class Devices, Security Function Detect, and IG2 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 10.7、官方资产类别“设备”、安全功能“检测”和首次出现的 IG2，并保存来源抓取日期。"
        },
        {
          "code": "CIS-10.7-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "10.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Include assets and workloads where behavior telemetry and prevention can observe process, memory, file, identity or network actions; declare which platforms, containers, cloud workloads and scripts are covered.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“包括行为遥测/防护能观察进程、内存、文件、身份或网络动作的资产/工作负载，明确平台、容器、云和脚本覆盖。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-10.7-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "10.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-10.7-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "10.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Use Behavior-Based Anti-Malware Software to its operating object—anti-malware eligibility, deployment, health, content freshness, policy, exclusions, detections, prevention, quarantine, and response—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“基于行为的恶意软件防护”连接到其运营对象——反恶意软件适用性、部署、健康、内容新鲜度、策略、排除项、检测、阻断、隔离和响应——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-10.7-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "10.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "For Use Behavior-Based Anti-Malware Software, express success as an observable decision over an enforceable allow, deny, contain, quarantine, require, remove, or transform decision at the closest reliable control point; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“基于行为的恶意软件防护”，以 在最近可靠控制点执行允许、拒绝、遏制、隔离、强制、移除或转换决策 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-10.7-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "10.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "For Use Behavior-Based Anti-Malware Software, express success as an observable decision over source-to-production software identity, design invariant, component trust, build provenance, test result, deployment state, runtime outcome, and vulnerability response; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“基于行为的恶意软件防护”，以 从源码到生产的软件身份、设计不变量、组件信任、构建来源、测试结果、部署状态、运行结果和漏洞响应 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-10.7-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "10.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-10.7-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "10.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-10.7-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "10.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-10.7-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "10.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-10.7-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "10.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across unsupported IoT/OT, containers, serverless, offline assets, stale content, behavior-only products, exclusions, tamper, performance modes, and conflicting agents; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 不支持的 IoT/OT、容器、Serverless、离线资产、陈旧内容、纯行为产品、排除项、篡改、性能模式和代理冲突 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-10.7-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "10.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Include audit-only mode, unsupported platforms, local overrides, race conditions, cached state, alternate paths, fail-open behavior, and emergency bypass in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 仅审计模式、不支持平台、本地覆盖、竞态、缓存状态、替代路径、故障开放和紧急绕过 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-10.7-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "10.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Include generated and copied code, forks, vendoring, transitive dependencies, mutable tags, build plugins, feature flags, tenant logic, secrets, emergency release, and provider components in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 生成与复制代码、分叉、vendoring、传递依赖、可变标签、构建插件、功能开关、租户逻辑、秘密、紧急发布和提供商组件 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-10.7-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "10.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-10.7-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "10.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-10.7-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "10.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-10.7-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "10.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-10.7-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "10.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind endpoint and platform engineering, workload owners, security operations, change management, and risk owners to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 终端与平台工程、工作负载责任人、安全运营、变更管理和风险责任人 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-10.7-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "10.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Name who may transition observe → evaluate → decide → enforce → verify outcome → rollback/close, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-10.7-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "10.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Name who may transition designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-10.7-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "10.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-10.7-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "10.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-10.7-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "10.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV1, GV3, GV5, M1, M2, M3, M4, M5) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV1, GV3, GV5, M1, M2, M3, M4, M5）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-10.7-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "10.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-10.7-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "10.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the endpoint and workload protection policy and health authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把终端与工作负载防护策略及健康权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-10.7-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "10.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle observe → evaluate → decide → enforce → verify outcome → rollback/close.",
          "zh": "对生命周期“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-10.7-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "10.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired.",
          "zh": "对生命周期“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-10.7-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "10.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 1.1, Safeguard 2.1, Safeguard 4.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 1.1、Safeguard 2.1、Safeguard 4.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-10.7-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "10.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-10.7-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "10.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-10.7-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "10.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-10.7-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "10.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile asset inventory, endpoint/workload platforms, cloud-native controls, image and runtime scanners, update services, exclusions, alerts, and response records and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 资产清单、终端/工作负载平台、云原生控制、镜像与运行时扫描、更新服务、排除项、告警和响应记录，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-10.7-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "10.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Require every connector carrying an enforceable allow, deny, contain, quarantine, require, remove, or transform decision at the closest reliable control point to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 在最近可靠控制点执行允许、拒绝、遏制、隔离、强制、移除或转换决策 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-10.7-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "10.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Require every connector carrying source-to-production software identity, design invariant, component trust, build provenance, test result, deployment state, runtime outcome, and vulnerability response to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 从源码到生产的软件身份、设计不变量、组件信任、构建来源、测试结果、部署状态、运行结果和漏洞响应 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-10.7-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "10.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Enable behavior/EDR capabilities, tune prevention by asset role, protect sensors, centralize high-fidelity telemetry and connect containment to incident response.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“启用行为/EDR，按资产角色调优防护，保护 Sensor，集中高保真遥测并连接遏制；设基线与例外，不能整类抑制技术或忽略可信父进程滥用。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-10.7-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "10.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-10.7-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "10.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-10.7-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "10.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-10.7-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "10.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the endpoint and workload protection policy and health authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在终端与工作负载防护策略及健康权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-10.7-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "10.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Implement the explicit state machine observe → evaluate → decide → enforce → verify outcome → rollback/close; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-10.7-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "10.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Implement the explicit state machine designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-10.7-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "10.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-10.7-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "10.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-10.7-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "10.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-10.7-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "10.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-10.7-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "10.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in anti-malware eligibility, deployment, health, content freshness, policy, exclusions, detections, prevention, quarantine, and response; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 反恶意软件适用性、部署、健康、内容新鲜度、策略、排除项、检测、阻断、隔离和响应 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-10.7-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "10.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for observe → evaluate → decide → enforce → verify outcome → rollback/close; alert before each deadline becomes overdue.",
          "zh": "为“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-10.7-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "10.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; alert before each deadline becomes overdue.",
          "zh": "为“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-10.7-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "10.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “Behavior products can miss living-off-the-land, kernel, cloud-control-plane and low-and-slow activity and can generate false positives.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“行为产品会漏 Living-off-the-land、内核、云控制面和低慢活动，也会误报。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-10.7-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "10.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-10.7-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "10.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-10.7-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "10.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-10.7-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "10.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat unsupported IoT/OT, containers, serverless, offline assets, stale content, behavior-only products, exclusions, tamper, performance modes, and conflicting agents as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 不支持的 IoT/OT、容器、Serverless、离线资产、陈旧内容、纯行为产品、排除项、篡改、性能模式和代理冲突 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-10.7-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "10.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Treat audit-only mode, unsupported platforms, local overrides, race conditions, cached state, alternate paths, fail-open behavior, and emergency bypass as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 仅审计模式、不支持平台、本地覆盖、竞态、缓存状态、替代路径、故障开放和紧急绕过 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-10.7-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "10.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Treat generated and copied code, forks, vendoring, transitive dependencies, mutable tags, build plugins, feature flags, tenant logic, secrets, emergency release, and provider components as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 生成与复制代码、分叉、vendoring、传递依赖、可变标签、构建插件、功能开关、租户逻辑、秘密、紧急发布和提供商组件 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-10.7-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "10.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Run safe simulations of suspicious child processes, credential-access-like behavior, persistence and ransomware-like file activity under approved test scope, alongside benign administrative controls.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“在批准范围安全模拟可疑子进程、凭据访问类行为、持久化和勒索式文件活动，同时跑正常管理员对照；验证检测/阻断/遏制、证据与分析动作，并记录端点安全状态和版本。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-10.7-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "10.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-10.7-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "10.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 8 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、8 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-10.7-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "10.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-10.7-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "10.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the endpoint and workload protection policy and health authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以终端与工作负载防护策略及健康权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-10.7-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "10.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Publish eligible, enforcing, audit-only, failed, bypassed, excepted, rolled-back, and outcome-verified populations with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 适用、已执行、仅审计、失败、被绕过、例外、已回滚和结果已验证总体，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-10.7-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "10.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Publish reviewed, unreviewed, reproducible, provenance-bound, vulnerable, test-failed, exception, deployed-unverified, drifted, rolled-back, and regression-protected releases with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已评审、未评审、可复现、来源绑定、存在漏洞、测试失败、例外、已部署未验证、漂移、已回滚和受回归保护发布物，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-10.7-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "10.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-10.7-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "10.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-10.7-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "10.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-10.7-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "10.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-10.7-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "10.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the endpoint and workload protection policy and health authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护终端与工作负载防护策略及健康权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-10.7-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "10.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Restrict authority to change observe → evaluate → decide → enforce → verify outcome → rollback/close; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-10.7-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "10.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Restrict authority to change designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-10.7-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "10.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-10.7-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "10.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-10.7-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "10.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-10.7-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "10.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-10.7-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "10.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise safe test artifacts, current and stale content, disabled protection, exclusion abuse, removable media, exploit behavior, quarantine, and update outage through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 安全测试样本、当前与陈旧内容、关闭防护、排除项滥用、可移动介质、利用行为、隔离和更新中断，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-10.7-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "10.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Run the positive control an approved business action that completes through the enforced path; exercise negative, stale, duplicate, bypass, and outage controls including a prohibited action, alternate path, local override, stale policy, control outage, emergency bypass, and rollback failure.",
          "zh": "运行正向控制“通过受控路径完成的一项获批业务动作”，并执行包含“禁止动作、替代路径、本地覆盖、陈旧策略、控制中断、紧急绕过和回滚失败”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-10.7-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "10.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Run the positive control a trusted build that preserves the security invariant through deployment and runtime; exercise negative, stale, duplicate, bypass, and outage controls including a substituted dependency, unreviewed change, poisoned build input, failed security test, bypass path, vulnerable release, rollback, and regression.",
          "zh": "运行正向控制“一个把安全不变量贯穿部署与运行的可信构建”，并执行包含“依赖替换、未评审变更、构建输入污染、安全测试失败、绕过路径、漏洞发布、回滚和回归”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-10.7-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "10.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-10.7-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "10.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-10.7-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "10.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-10.7-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "10.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-10.7-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "10.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever asset inventory, endpoint/workload platforms, cloud-native controls, image and runtime scanners, update services, exclusions, alerts, and response records change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 资产清单、终端/工作负载平台、云原生控制、镜像与运行时扫描、更新服务、排除项、告警和响应记录 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-10.7-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "10.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Use eligible, enforcing, audit-only, failed, bypassed, excepted, rolled-back, and outcome-verified populations to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 适用、已执行、仅审计、失败、被绕过、例外、已回滚和结果已验证总体 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-10.7-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "10.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Use reviewed, unreviewed, reproducible, provenance-bound, vulnerable, test-failed, exception, deployed-unverified, drifted, rolled-back, and regression-protected releases to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已评审、未评审、可复现、来源绑定、存在漏洞、测试失败、例外、已部署未验证、漂移、已回滚和受回归保护发布物 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "11.1",
      "control": 11,
      "title_en": "Establish and Maintain a Data Recovery Process",
      "title_zh": "数据恢复流程",
      "first_ig": 1,
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Documentation",
      "security_function": "Govern",
      "patterns": [
        "recovery",
        "data_lifecycle",
        "governance"
      ],
      "expanded_complexity": true,
      "cas_context": {
        "dependencies": [],
        "variables": [
          "M1",
          "M2",
          "M3"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [
        "annually"
      ],
      "implementation_contract": {
        "en": {
          "scope": "The recovery process covers systems, data, configurations, identities, keys, infrastructure definitions and provider dependencies required to restore business services after deletion, corruption, ransomware, region loss or provider failure.",
          "build": "Assign business, data, platform, security and crisis owners; document recovery order, dependencies, clean-room requirements, backup security, communications, decision authority and validation.",
          "proof": "Tabletop and technically rehearse a representative destructive scenario from declaration through clean restore, dependency startup, integrity/security validation and business acceptance.",
          "boundary": "The current CAS completeness formula divides three process elements by months since review, a dimensional error."
        },
        "zh": {
          "scope": "恢复流程覆盖在误删、损坏、勒索、地域或服务商故障后恢复业务所需的系统、数据、配置、身份、密钥、基础设施定义和外部依赖，并按业务优先级、RTO/RPO 与最小可用服务排序，不能把所有备份一视同仁。",
          "build": "指定业务、数据、平台、安全和危机负责人，写清恢复顺序、依赖、净室、备份安全、通信、决策权和验收；与连续性/事件计划对齐，每年及架构、服务商、业务重大变化时更新。",
          "proof": "桌演并技术演练一个代表破坏场景，从宣告到干净恢复、依赖启动、完整性/安全验证和业务验收；把实测恢复点/时间与目标比较，记录阻塞、人工知识和未测组件。",
          "boundary": "CAS 把三个流程要素除以距复核的月数，量纲错误。"
        }
      },
      "category_counts": {
        "outcome": 9,
        "scope": 9,
        "ownership": 9,
        "data": 9,
        "integration": 9,
        "control": 9,
        "timing": 9,
        "exception": 9,
        "evidence": 9,
        "security": 9,
        "testing": 9,
        "operations": 9
      },
      "requirement_count": 108,
      "requirements": [
        {
          "code": "CIS-11.1-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "11.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Establish and Maintain a Data Recovery Process; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“数据恢复流程”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-11.1-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "11.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 11.1, official Asset Class Documentation, Security Function Govern, and IG1 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 11.1、官方资产类别“文档与治理”、安全功能“治理”和首次出现的 IG1，并保存来源抓取日期。"
        },
        {
          "code": "CIS-11.1-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "11.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “The recovery process covers systems, data, configurations, identities, keys, infrastructure definitions and provider dependencies required to restore business services after deletion, corruption, ransomware, region loss or provider failure.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“恢复流程覆盖在误删、损坏、勒索、地域或服务商故障后恢复业务所需的系统、数据、配置、身份、密钥、基础设施定义和外部依赖，并按业务优先级、RTO/RPO 与最小可用服务排序，不能把所有备份一视同仁。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-11.1-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "11.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-11.1-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "11.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Establish and Maintain a Data Recovery Process to its operating object—protected data and configuration recovery points, copies, keys, isolation, integrity, restore dependencies, and business recovery outcomes—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“数据恢复流程”连接到其运营对象——受保护数据与配置的恢复点、副本、密钥、隔离、完整性、恢复依赖和业务恢复结果——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-11.1-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "11.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original recovery pattern analysis",
          "basis_zh": "SOSEC 原创 recovery 模式分析",
          "en": "For Establish and Maintain a Data Recovery Process, express success as an observable decision over recoverable business service, protected recovery point, trustworthy copy, dependency, recovery objective, and verified restored outcome; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“数据恢复流程”，以 可恢复业务服务、受保护恢复点、可信副本、依赖、恢复目标和经验证的恢复结果 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-11.1-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "11.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "For Establish and Maintain a Data Recovery Process, express success as an observable decision over data identity, sensitivity, owner, purpose, location, flow, access, retention, copy, derivation, and disposal state; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“数据恢复流程”，以 数据身份、敏感度、责任人、目的、位置、流向、访问、保留、副本、派生与销毁状态 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-11.1-OUT-08",
          "local_code": "OUT-08",
          "display_code": "O08",
          "safeguard_id": "11.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "For Establish and Maintain a Data Recovery Process, express success as an observable decision over a documented decision system with policy, process, procedure, accountable owner, approval, and review; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“数据恢复流程”，以 包含策略、流程、程序、责任人、审批和复核的文档化决策系统 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-11.1-OUT-09",
          "local_code": "OUT-09",
          "display_code": "O09",
          "safeguard_id": "11.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "For the expanded Establish and Maintain a Data Recovery Process scope, resolve conflicts among security, safety, privacy, legal, availability, customer, and operational objectives through an explicit risk decision.",
          "zh": "对“数据恢复流程”的扩展范围，通过显式风险决策解决安全、安全生产、隐私、法律、可用性、客户和运营目标冲突。"
        },
        {
          "code": "CIS-11.1-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "11.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-11.1-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "11.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-11.1-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "11.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-11.1-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "11.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-11.1-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "11.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across corrupt source data, silent job failure, ransomware reachability, deleted tenants, missing keys, stale runbooks, region/provider loss, capacity limits, and partial restore; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 源数据损坏、作业静默失败、勒索软件可达、租户删除、密钥缺失、手册陈旧、地域/提供商丢失、容量限制和部分恢复 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-11.1-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "11.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original recovery pattern analysis",
          "basis_zh": "SOSEC 原创 recovery 模式分析",
          "en": "Include silent job failure, corrupt source, ransomware reachability, missing key, provider or region loss, quota, partial restore, stale runbook, and clean-room unavailability in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 作业静默失败、源损坏、勒索软件可达、密钥缺失、提供商或地域丢失、配额、部分恢复、手册陈旧和洁净室不可用 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-11.1-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "11.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Include unstructured and derived data, logs, caches, backups, exports, client-side copies, cross-region processing, AI corpora, holds, and provider residues in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 非结构化与派生数据、日志、缓存、备份、导出、客户端副本、跨地域处理、AI 语料、保全和提供商残留 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-11.1-SCP-08",
          "local_code": "SCP-08",
          "display_code": "P08",
          "safeguard_id": "11.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Include missing policy clauses, conflicting authorities, local deviations, obsolete documentation, and decisions made outside the governed workflow in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 策略条款缺失、权限冲突、本地偏离、文档过期及绕过治理流程的决策 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-11.1-SCP-09",
          "local_code": "SCP-09",
          "display_code": "P09",
          "safeguard_id": "11.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Define nested scope at enterprise, business service, tenant, environment, platform, object, identity, data set, and transaction levels; prohibit a parent result from hiding a failing child.",
          "zh": "按企业、业务服务、租户、环境、平台、对象、身份、数据集和交易定义嵌套范围，禁止父级结果遮蔽失败子级。"
        },
        {
          "code": "CIS-11.1-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "11.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-11.1-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "11.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-11.1-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "11.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-11.1-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "11.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-11.1-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "11.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind data and service owners, backup operators, infrastructure, security, business continuity, legal, and recovery decision makers to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 数据与服务责任人、备份运营、基础设施、安全、业务连续性、法务和恢复决策人 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-11.1-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "11.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original recovery pattern analysis",
          "basis_zh": "SOSEC 原创 recovery 模式分析",
          "en": "Name who may transition protected object identified → copy created → isolated/verified → retained → selected → restored → business-validated → expired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 识别受保护对象 → 创建副本 → 隔离/验证 → 保留 → 选择 → 恢复 → 业务验证 → 到期，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-11.1-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "11.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Name who may transition created/collected → classified → approved use and flow → retained/held → disposed with verification, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-11.1-OWN-08",
          "local_code": "OWN-08",
          "display_code": "W08",
          "safeguard_id": "11.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Name who may transition draft → reviewed → approved → effective → exception/withdrawn → superseded, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-11.1-OWN-09",
          "local_code": "OWN-09",
          "display_code": "W09",
          "safeguard_id": "11.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Model delegated authority, quorum or dual approval where warranted, escalation deadlines, provider handoffs, conflict resolution, and executive risk acceptance.",
          "zh": "建模委派权限、必要时的双人或法定人数审批、升级期限、提供商交接、冲突解决和管理层风险接受。"
        },
        {
          "code": "CIS-11.1-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "11.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-11.1-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "11.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-11.1-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "11.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (M1, M2, M3) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（M1, M2, M3）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-11.1-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "11.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-11.1-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "11.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the recovery inventory, policy, job, vault, and restoration authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把恢复清单、策略、作业、保险库和还原权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-11.1-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "11.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original recovery pattern analysis",
          "basis_zh": "SOSEC 原创 recovery 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle protected object identified → copy created → isolated/verified → retained → selected → restored → business-validated → expired.",
          "zh": "对生命周期“识别受保护对象 → 创建副本 → 隔离/验证 → 保留 → 选择 → 恢复 → 业务验证 → 到期”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-11.1-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "11.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle created/collected → classified → approved use and flow → retained/held → disposed with verification.",
          "zh": "对生命周期“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-11.1-DAT-08",
          "local_code": "DAT-08",
          "display_code": "D08",
          "safeguard_id": "11.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle draft → reviewed → approved → effective → exception/withdrawn → superseded.",
          "zh": "对生命周期“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-11.1-DAT-09",
          "local_code": "DAT-09",
          "display_code": "D09",
          "safeguard_id": "11.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Version schemas and state transitions with migration, backfill, deduplication, lineage, historical denominator, deletion, and rollback semantics.",
          "zh": "对模式和状态转换做版本管理，定义迁移、回填、去重、血缘、历史分母、删除和回滚语义。"
        },
        {
          "code": "CIS-11.1-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "11.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for no explicit predecessor in the pinned CAS page; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 固定 CAS 页面没有列出显式前置项 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-11.1-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "11.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-11.1-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "11.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-11.1-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "11.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-11.1-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "11.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile asset and data inventories, backup platforms, cloud snapshots, SaaS exports, immutable/offline stores, key custody, job logs, restore tests, and continuity plans and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 资产与数据清单、备份平台、云快照、SaaS 导出、不可变/离线存储、密钥保管、作业日志、恢复测试和连续性计划，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-11.1-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "11.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original recovery pattern analysis",
          "basis_zh": "SOSEC 原创 recovery 模式分析",
          "en": "Require every connector carrying recoverable business service, protected recovery point, trustworthy copy, dependency, recovery objective, and verified restored outcome to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 可恢复业务服务、受保护恢复点、可信副本、依赖、恢复目标和经验证的恢复结果 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-11.1-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "11.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Require every connector carrying data identity, sensitivity, owner, purpose, location, flow, access, retention, copy, derivation, and disposal state to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 数据身份、敏感度、责任人、目的、位置、流向、访问、保留、副本、派生与销毁状态 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-11.1-INT-08",
          "local_code": "INT-08",
          "display_code": "I08",
          "safeguard_id": "11.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Require every connector carrying a documented decision system with policy, process, procedure, accountable owner, approval, and review to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 包含策略、流程、程序、责任人、审批和复核的文档化决策系统 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-11.1-INT-09",
          "local_code": "INT-09",
          "display_code": "I09",
          "safeguard_id": "11.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Define consistency rules across disagreeing sources, source precedence, confidence, reconciliation queues, dead-letter handling, reprocessing, and end-to-end trace identity.",
          "zh": "定义冲突来源的一致性、优先级、置信度、对账队列、死信、重处理和端到端追踪身份。"
        },
        {
          "code": "CIS-11.1-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "11.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Assign business, data, platform, security and crisis owners; document recovery order, dependencies, clean-room requirements, backup security, communications, decision authority and validation.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“指定业务、数据、平台、安全和危机负责人，写清恢复顺序、依赖、净室、备份安全、通信、决策权和验收；与连续性/事件计划对齐，每年及架构、服务商、业务重大变化时更新。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-11.1-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "11.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-11.1-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "11.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-11.1-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "11.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-11.1-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "11.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the recovery inventory, policy, job, vault, and restoration authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在恢复清单、策略、作业、保险库和还原权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-11.1-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "11.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original recovery pattern analysis",
          "basis_zh": "SOSEC 原创 recovery 模式分析",
          "en": "Implement the explicit state machine protected object identified → copy created → isolated/verified → retained → selected → restored → business-validated → expired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“识别受保护对象 → 创建副本 → 隔离/验证 → 保留 → 选择 → 恢复 → 业务验证 → 到期”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-11.1-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "11.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Implement the explicit state machine created/collected → classified → approved use and flow → retained/held → disposed with verification; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-11.1-CTL-08",
          "local_code": "CTL-08",
          "display_code": "C08",
          "safeguard_id": "11.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Implement the explicit state machine draft → reviewed → approved → effective → exception/withdrawn → superseded; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-11.1-CTL-09",
          "local_code": "CTL-09",
          "display_code": "C09",
          "safeguard_id": "11.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Specify concurrent decisions, partial success, compensating transactions, repeated requests, stale policy, dependency outage, and recovery from an interrupted state transition.",
          "zh": "定义并发决策、部分成功、补偿事务、重复请求、陈旧策略、依赖中断和中途状态转换恢复。"
        },
        {
          "code": "CIS-11.1-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "11.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (annually); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（annually）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-11.1-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "11.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-11.1-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "11.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-11.1-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "11.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-11.1-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "11.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in protected data and configuration recovery points, copies, keys, isolation, integrity, restore dependencies, and business recovery outcomes; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 受保护数据与配置的恢复点、副本、密钥、隔离、完整性、恢复依赖和业务恢复结果 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-11.1-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "11.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original recovery pattern analysis",
          "basis_zh": "SOSEC 原创 recovery 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for protected object identified → copy created → isolated/verified → retained → selected → restored → business-validated → expired; alert before each deadline becomes overdue.",
          "zh": "为“识别受保护对象 → 创建副本 → 隔离/验证 → 保留 → 选择 → 恢复 → 业务验证 → 到期”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-11.1-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "11.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for created/collected → classified → approved use and flow → retained/held → disposed with verification; alert before each deadline becomes overdue.",
          "zh": "为“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-11.1-TIM-08",
          "local_code": "TIM-08",
          "display_code": "T08",
          "safeguard_id": "11.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for draft → reviewed → approved → effective → exception/withdrawn → superseded; alert before each deadline becomes overdue.",
          "zh": "为“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-11.1-TIM-09",
          "local_code": "TIM-09",
          "display_code": "T09",
          "safeguard_id": "11.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Allocate an end-to-end SLO budget across discovery, collection, processing, approval, enforcement, verification, and closure; prioritize overdue work by consequence and exposure.",
          "zh": "把端到端 SLO 预算分配到发现、采集、处理、审批、执行、验证和关闭，并按后果与暴露排列逾期工作。"
        },
        {
          "code": "CIS-11.1-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "11.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “The current CAS completeness formula divides three process elements by months since review, a dimensional error.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“CAS 把三个流程要素除以距复核的月数，量纲错误。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-11.1-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "11.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-11.1-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "11.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-11.1-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "11.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-11.1-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "11.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat corrupt source data, silent job failure, ransomware reachability, deleted tenants, missing keys, stale runbooks, region/provider loss, capacity limits, and partial restore as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 源数据损坏、作业静默失败、勒索软件可达、租户删除、密钥缺失、手册陈旧、地域/提供商丢失、容量限制和部分恢复 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-11.1-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "11.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original recovery pattern analysis",
          "basis_zh": "SOSEC 原创 recovery 模式分析",
          "en": "Treat silent job failure, corrupt source, ransomware reachability, missing key, provider or region loss, quota, partial restore, stale runbook, and clean-room unavailability as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 作业静默失败、源损坏、勒索软件可达、密钥缺失、提供商或地域丢失、配额、部分恢复、手册陈旧和洁净室不可用 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-11.1-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "11.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Treat unstructured and derived data, logs, caches, backups, exports, client-side copies, cross-region processing, AI corpora, holds, and provider residues as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 非结构化与派生数据、日志、缓存、备份、导出、客户端副本、跨地域处理、AI 语料、保全和提供商残留 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-11.1-EXC-08",
          "local_code": "EXC-08",
          "display_code": "X08",
          "safeguard_id": "11.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Treat missing policy clauses, conflicting authorities, local deviations, obsolete documentation, and decisions made outside the governed workflow as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 策略条款缺失、权限冲突、本地偏离、文档过期及绕过治理流程的决策 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-11.1-EXC-09",
          "local_code": "EXC-09",
          "display_code": "X09",
          "safeguard_id": "11.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Exercise compound failures where an exception, stale source, provider outage, unavailable owner, and degraded control overlap; define one safe command and one accountable decision.",
          "zh": "演练例外、陈旧来源、提供商中断、责任人不可用和控制降级同时出现的复合故障，明确一条安全指令和一个责任决策。"
        },
        {
          "code": "CIS-11.1-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "11.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Tabletop and technically rehearse a representative destructive scenario from declaration through clean restore, dependency startup, integrity/security validation and business acceptance.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“桌演并技术演练一个代表破坏场景，从宣告到干净恢复、依赖启动、完整性/安全验证和业务验收；把实测恢复点/时间与目标比较，记录阻塞、人工知识和未测组件。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-11.1-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "11.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-11.1-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "11.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 3 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、3 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-11.1-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "11.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-11.1-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "11.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the recovery inventory, policy, job, vault, and restoration authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以恢复清单、策略、作业、保险库和还原权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-11.1-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "11.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original recovery pattern analysis",
          "basis_zh": "SOSEC 原创 recovery 模式分析",
          "en": "Publish protected, missed, failed, stale, corrupt, reachable-by-production, keyless, untested, restore-failed, and business-validated recovery objects with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已保护、漏备、失败、陈旧、损坏、生产可达、无密钥、未测试、恢复失败和业务已验证恢复对象，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-11.1-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "11.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Publish known, unknown, classified, ownerless, over-retained, prematurely deleted, unapproved copy, blocked flow, held, and disposal-verified data sets with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已知、未知、已分类、无责任人、超期保留、过早删除、未批准副本、被阻断流、保全及销毁已验证数据集，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-11.1-EVD-08",
          "local_code": "EVD-08",
          "display_code": "E08",
          "safeguard_id": "11.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Publish clause coverage, owner and reviewer completeness, approval age, triggered reviews, deviations, overdue actions, and superseded versions still in use with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 条款覆盖、责任人与复核人完整性、批准年龄、触发式复核、偏离、逾期行动及仍在使用的旧版本，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-11.1-EVD-09",
          "local_code": "EVD-09",
          "display_code": "E09",
          "safeguard_id": "11.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Require an independent party to reconstruct the decision from source receipts and reproduce the population, state transition, calculation, test result, exception, and final closure.",
          "zh": "要求独立人员使用来源回执重建决策，并复现总体、状态转换、计算、测试结果、例外和最终关闭。"
        },
        {
          "code": "CIS-11.1-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "11.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-11.1-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "11.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-11.1-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "11.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-11.1-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "11.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-11.1-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "11.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the recovery inventory, policy, job, vault, and restoration authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护恢复清单、策略、作业、保险库和还原权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-11.1-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "11.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original recovery pattern analysis",
          "basis_zh": "SOSEC 原创 recovery 模式分析",
          "en": "Restrict authority to change protected object identified → copy created → isolated/verified → retained → selected → restored → business-validated → expired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“识别受保护对象 → 创建副本 → 隔离/验证 → 保留 → 选择 → 恢复 → 业务验证 → 到期”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-11.1-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "11.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Restrict authority to change created/collected → classified → approved use and flow → retained/held → disposed with verification; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-11.1-SEC-08",
          "local_code": "SEC-08",
          "display_code": "S08",
          "safeguard_id": "11.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Restrict authority to change draft → reviewed → approved → effective → exception/withdrawn → superseded; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-11.1-SEC-09",
          "local_code": "SEC-09",
          "display_code": "S09",
          "safeguard_id": "11.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Threat-model the implementation system itself: forged evidence, poisoned inventory, privilege abuse, cross-tenant confusion, policy rollback, audit deletion, denial of service, and recovery compromise.",
          "zh": "威胁建模实施系统自身：伪造证据、污染清单、权限滥用、跨租户混淆、策略回滚、审计删除、拒绝服务和恢复失陷。"
        },
        {
          "code": "CIS-11.1-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "11.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-11.1-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "11.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-11.1-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "11.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-11.1-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "11.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-11.1-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "11.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise successful and failed jobs, isolated-copy access, deletion and encryption attempts, point-in-time restore, clean-room rebuild, provider loss, and business transaction validation through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 成功与失败作业、隔离副本访问、删除与加密尝试、时间点恢复、洁净室重建、提供商丢失和业务交易验证，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-11.1-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "11.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original recovery pattern analysis",
          "basis_zh": "SOSEC 原创 recovery 模式分析",
          "en": "Run the positive control a representative point-in-time restoration that passes data and business checks; exercise negative, stale, duplicate, bypass, and outage controls including failed job, corrupt copy, deletion/encryption attempt, lost key, unavailable provider, dependency omission, partial restore, and missed recovery objective.",
          "zh": "运行正向控制“一项通过数据与业务检查的代表性时间点恢复”，并执行包含“作业失败、副本损坏、删除/加密尝试、密钥丢失、提供商不可用、依赖遗漏、部分恢复和未达恢复目标”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-11.1-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "11.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Run the positive control an approved data set following its declared use, access, transfer, retention, and disposal path; exercise negative, stale, duplicate, bypass, and outage controls including an unknown or misclassified copy, forbidden reader or flow, early deletion, expired retention, failed disposal, and provider residue.",
          "zh": "运行正向控制“按声明用途、访问、传输、保留和销毁路径流转的获批数据集”，并执行包含“未知或误分类副本、禁止读取者或流向、过早删除、保留过期、销毁失败和提供商残留”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-11.1-TST-08",
          "local_code": "TST-08",
          "display_code": "V08",
          "safeguard_id": "11.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Run the positive control an approved current process used for a representative decision; exercise negative, stale, duplicate, bypass, and outage controls including an obsolete version, missing approver, undocumented deviation, overdue review, and bypassed workflow.",
          "zh": "运行正向控制“使用当前获批流程完成一项代表性决策”，并执行包含“旧版本、审批人缺失、未记录偏离、逾期复核和绕过流程”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-11.1-TST-09",
          "local_code": "TST-09",
          "display_code": "V09",
          "safeguard_id": "11.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Build a pairwise platform-and-failure matrix, then add high-consequence multi-factor cases, historical regression, source substitution, red-team challenge, and assessor replay.",
          "zh": "建立平台—故障两两组合矩阵，再加入高后果多因素案例、历史回归、来源替换、红队挑战和评估方重放。"
        },
        {
          "code": "CIS-11.1-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "11.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-11.1-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "11.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-11.1-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "11.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-11.1-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "11.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-11.1-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "11.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever asset and data inventories, backup platforms, cloud snapshots, SaaS exports, immutable/offline stores, key custody, job logs, restore tests, and continuity plans change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 资产与数据清单、备份平台、云快照、SaaS 导出、不可变/离线存储、密钥保管、作业日志、恢复测试和连续性计划 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-11.1-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "11.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original recovery pattern analysis",
          "basis_zh": "SOSEC 原创 recovery 模式分析",
          "en": "Use protected, missed, failed, stale, corrupt, reachable-by-production, keyless, untested, restore-failed, and business-validated recovery objects to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已保护、漏备、失败、陈旧、损坏、生产可达、无密钥、未测试、恢复失败和业务已验证恢复对象 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-11.1-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "11.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Use known, unknown, classified, ownerless, over-retained, prematurely deleted, unapproved copy, blocked flow, held, and disposal-verified data sets to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已知、未知、已分类、无责任人、超期保留、过早删除、未批准副本、被阻断流、保全及销毁已验证数据集 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-11.1-OPS-08",
          "local_code": "OPS-08",
          "display_code": "R08",
          "safeguard_id": "11.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Use clause coverage, owner and reviewer completeness, approval age, triggered reviews, deviations, overdue actions, and superseded versions still in use to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 条款覆盖、责任人与复核人完整性、批准年龄、触发式复核、偏离、逾期行动及仍在使用的旧版本 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-11.1-OPS-09",
          "local_code": "OPS-09",
          "display_code": "R09",
          "safeguard_id": "11.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Use canary deployment, kill criteria, rollback, backlog burn-down, exception reduction, source-quality targets, quarterly design review, and a measurable retirement plan.",
          "zh": "采用金丝雀、停止标准、回滚、积压燃尽、例外缩减、来源质量目标、季度设计复核和可量化退役计划。"
        }
      ]
    },
    {
      "id": "11.2",
      "control": 11,
      "title_en": "Perform Automated Backups",
      "title_zh": "自动备份",
      "first_ig": 1,
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Data",
      "security_function": "Recover",
      "patterns": [
        "recovery"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "1.1",
          "2.1",
          "4.1"
        ],
        "variables": [
          "GV1",
          "GV3",
          "GV5",
          "GV33",
          "GV34",
          "M1",
          "M2",
          "M3",
          "M4",
          "M5",
          "M6",
          "M7"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [
        "weekly"
      ],
      "implementation_contract": {
        "en": {
          "scope": "In-scope assets and services are chosen from business/data recovery requirements, including databases, files, SaaS, cloud state, endpoint data not otherwise synchronized, configurations, code/artifacts and critical identity/key material.",
          "build": "Automate backups at least weekly and more frequently to meet RPO, monitor job and object success, capture application-consistent state, encrypt and version data, and inventory destinations and retention.",
          "proof": "Modify a canary file/record, run the job and verify timestamp, scope, application consistency, destination object, immutability and restore.",
          "boundary": "CAS measures configuration but omits its own recent-success M6/M7 from the score."
        },
        "zh": {
          "scope": "范围由业务与数据恢复要求决定，包括数据库、文件、SaaS、云状态、未同步终端数据、配置、代码/制品和关键身份/密钥材料。",
          "build": "至少每周并按 RPO 更频繁地自动备份，监控 Job 与对象成功、应用一致性、加密、版本、目的和保留；新资产自动继承策略，失败生成具名事件而非无限静默重试。",
          "proof": "修改金丝雀文件/记录后跑备份，验证时间、范围、应用一致性、目的对象、不可变和恢复；把近期成功对象与每个范围资产/数据集对账，报告遗漏、部分、陈旧和从未保护。",
          "boundary": "CAS 只计配置，自己定义的近期成功 M6/M7 却未入分数。"
        }
      },
      "category_counts": {
        "outcome": 6,
        "scope": 6,
        "ownership": 6,
        "data": 6,
        "integration": 6,
        "control": 6,
        "timing": 6,
        "exception": 6,
        "evidence": 6,
        "security": 6,
        "testing": 6,
        "operations": 6
      },
      "requirement_count": 72,
      "requirements": [
        {
          "code": "CIS-11.2-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "11.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Perform Automated Backups; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“自动备份”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-11.2-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "11.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 11.2, official Asset Class Data, Security Function Recover, and IG1 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 11.2、官方资产类别“数据”、安全功能“恢复”和首次出现的 IG1，并保存来源抓取日期。"
        },
        {
          "code": "CIS-11.2-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "11.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “In-scope assets and services are chosen from business/data recovery requirements, including databases, files, SaaS, cloud state, endpoint data not otherwise synchronized, configurations, code/artifacts and critical identity/key material.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“范围由业务与数据恢复要求决定，包括数据库、文件、SaaS、云状态、未同步终端数据、配置、代码/制品和关键身份/密钥材料。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-11.2-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "11.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-11.2-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "11.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Perform Automated Backups to its operating object—protected data and configuration recovery points, copies, keys, isolation, integrity, restore dependencies, and business recovery outcomes—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“自动备份”连接到其运营对象——受保护数据与配置的恢复点、副本、密钥、隔离、完整性、恢复依赖和业务恢复结果——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-11.2-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "11.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original recovery pattern analysis",
          "basis_zh": "SOSEC 原创 recovery 模式分析",
          "en": "For Perform Automated Backups, express success as an observable decision over recoverable business service, protected recovery point, trustworthy copy, dependency, recovery objective, and verified restored outcome; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“自动备份”，以 可恢复业务服务、受保护恢复点、可信副本、依赖、恢复目标和经验证的恢复结果 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-11.2-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "11.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-11.2-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "11.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-11.2-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "11.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-11.2-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "11.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-11.2-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "11.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across corrupt source data, silent job failure, ransomware reachability, deleted tenants, missing keys, stale runbooks, region/provider loss, capacity limits, and partial restore; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 源数据损坏、作业静默失败、勒索软件可达、租户删除、密钥缺失、手册陈旧、地域/提供商丢失、容量限制和部分恢复 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-11.2-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "11.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original recovery pattern analysis",
          "basis_zh": "SOSEC 原创 recovery 模式分析",
          "en": "Include silent job failure, corrupt source, ransomware reachability, missing key, provider or region loss, quota, partial restore, stale runbook, and clean-room unavailability in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 作业静默失败、源损坏、勒索软件可达、密钥缺失、提供商或地域丢失、配额、部分恢复、手册陈旧和洁净室不可用 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-11.2-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "11.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-11.2-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "11.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-11.2-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "11.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-11.2-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "11.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-11.2-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "11.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind data and service owners, backup operators, infrastructure, security, business continuity, legal, and recovery decision makers to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 数据与服务责任人、备份运营、基础设施、安全、业务连续性、法务和恢复决策人 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-11.2-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "11.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original recovery pattern analysis",
          "basis_zh": "SOSEC 原创 recovery 模式分析",
          "en": "Name who may transition protected object identified → copy created → isolated/verified → retained → selected → restored → business-validated → expired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 识别受保护对象 → 创建副本 → 隔离/验证 → 保留 → 选择 → 恢复 → 业务验证 → 到期，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-11.2-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "11.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-11.2-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "11.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-11.2-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "11.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV1, GV3, GV5, GV33, GV34, M1, M2, M3, M4, M5, M6, M7) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV1, GV3, GV5, GV33, GV34, M1, M2, M3, M4, M5, M6, M7）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-11.2-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "11.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-11.2-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "11.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the recovery inventory, policy, job, vault, and restoration authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把恢复清单、策略、作业、保险库和还原权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-11.2-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "11.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original recovery pattern analysis",
          "basis_zh": "SOSEC 原创 recovery 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle protected object identified → copy created → isolated/verified → retained → selected → restored → business-validated → expired.",
          "zh": "对生命周期“识别受保护对象 → 创建副本 → 隔离/验证 → 保留 → 选择 → 恢复 → 业务验证 → 到期”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-11.2-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "11.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 1.1, Safeguard 2.1, Safeguard 4.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 1.1、Safeguard 2.1、Safeguard 4.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-11.2-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "11.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-11.2-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "11.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-11.2-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "11.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-11.2-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "11.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile asset and data inventories, backup platforms, cloud snapshots, SaaS exports, immutable/offline stores, key custody, job logs, restore tests, and continuity plans and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 资产与数据清单、备份平台、云快照、SaaS 导出、不可变/离线存储、密钥保管、作业日志、恢复测试和连续性计划，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-11.2-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "11.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original recovery pattern analysis",
          "basis_zh": "SOSEC 原创 recovery 模式分析",
          "en": "Require every connector carrying recoverable business service, protected recovery point, trustworthy copy, dependency, recovery objective, and verified restored outcome to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 可恢复业务服务、受保护恢复点、可信副本、依赖、恢复目标和经验证的恢复结果 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-11.2-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "11.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Automate backups at least weekly and more frequently to meet RPO, monitor job and object success, capture application-consistent state, encrypt and version data, and inventory destinations and retention.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“至少每周并按 RPO 更频繁地自动备份，监控 Job 与对象成功、应用一致性、加密、版本、目的和保留；新资产自动继承策略，失败生成具名事件而非无限静默重试。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-11.2-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "11.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-11.2-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "11.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-11.2-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "11.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-11.2-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "11.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the recovery inventory, policy, job, vault, and restoration authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在恢复清单、策略、作业、保险库和还原权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-11.2-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "11.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original recovery pattern analysis",
          "basis_zh": "SOSEC 原创 recovery 模式分析",
          "en": "Implement the explicit state machine protected object identified → copy created → isolated/verified → retained → selected → restored → business-validated → expired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“识别受保护对象 → 创建副本 → 隔离/验证 → 保留 → 选择 → 恢复 → 业务验证 → 到期”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-11.2-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "11.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (weekly); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（weekly）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-11.2-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "11.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-11.2-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "11.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-11.2-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "11.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-11.2-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "11.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in protected data and configuration recovery points, copies, keys, isolation, integrity, restore dependencies, and business recovery outcomes; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 受保护数据与配置的恢复点、副本、密钥、隔离、完整性、恢复依赖和业务恢复结果 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-11.2-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "11.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original recovery pattern analysis",
          "basis_zh": "SOSEC 原创 recovery 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for protected object identified → copy created → isolated/verified → retained → selected → restored → business-validated → expired; alert before each deadline becomes overdue.",
          "zh": "为“识别受保护对象 → 创建副本 → 隔离/验证 → 保留 → 选择 → 恢复 → 业务验证 → 到期”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-11.2-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "11.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “CAS measures configuration but omits its own recent-success M6/M7 from the score.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“CAS 只计配置，自己定义的近期成功 M6/M7 却未入分数。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-11.2-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "11.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-11.2-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "11.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-11.2-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "11.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-11.2-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "11.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat corrupt source data, silent job failure, ransomware reachability, deleted tenants, missing keys, stale runbooks, region/provider loss, capacity limits, and partial restore as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 源数据损坏、作业静默失败、勒索软件可达、租户删除、密钥缺失、手册陈旧、地域/提供商丢失、容量限制和部分恢复 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-11.2-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "11.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original recovery pattern analysis",
          "basis_zh": "SOSEC 原创 recovery 模式分析",
          "en": "Treat silent job failure, corrupt source, ransomware reachability, missing key, provider or region loss, quota, partial restore, stale runbook, and clean-room unavailability as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 作业静默失败、源损坏、勒索软件可达、密钥缺失、提供商或地域丢失、配额、部分恢复、手册陈旧和洁净室不可用 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-11.2-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "11.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Modify a canary file/record, run the job and verify timestamp, scope, application consistency, destination object, immutability and restore.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“修改金丝雀文件/记录后跑备份，验证时间、范围、应用一致性、目的对象、不可变和恢复；把近期成功对象与每个范围资产/数据集对账，报告遗漏、部分、陈旧和从未保护。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-11.2-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "11.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-11.2-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "11.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 12 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、12 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-11.2-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "11.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-11.2-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "11.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the recovery inventory, policy, job, vault, and restoration authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以恢复清单、策略、作业、保险库和还原权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-11.2-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "11.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original recovery pattern analysis",
          "basis_zh": "SOSEC 原创 recovery 模式分析",
          "en": "Publish protected, missed, failed, stale, corrupt, reachable-by-production, keyless, untested, restore-failed, and business-validated recovery objects with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已保护、漏备、失败、陈旧、损坏、生产可达、无密钥、未测试、恢复失败和业务已验证恢复对象，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-11.2-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "11.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-11.2-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "11.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-11.2-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "11.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-11.2-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "11.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-11.2-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "11.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the recovery inventory, policy, job, vault, and restoration authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护恢复清单、策略、作业、保险库和还原权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-11.2-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "11.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original recovery pattern analysis",
          "basis_zh": "SOSEC 原创 recovery 模式分析",
          "en": "Restrict authority to change protected object identified → copy created → isolated/verified → retained → selected → restored → business-validated → expired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“识别受保护对象 → 创建副本 → 隔离/验证 → 保留 → 选择 → 恢复 → 业务验证 → 到期”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-11.2-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "11.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-11.2-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "11.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-11.2-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "11.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-11.2-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "11.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-11.2-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "11.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise successful and failed jobs, isolated-copy access, deletion and encryption attempts, point-in-time restore, clean-room rebuild, provider loss, and business transaction validation through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 成功与失败作业、隔离副本访问、删除与加密尝试、时间点恢复、洁净室重建、提供商丢失和业务交易验证，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-11.2-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "11.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original recovery pattern analysis",
          "basis_zh": "SOSEC 原创 recovery 模式分析",
          "en": "Run the positive control a representative point-in-time restoration that passes data and business checks; exercise negative, stale, duplicate, bypass, and outage controls including failed job, corrupt copy, deletion/encryption attempt, lost key, unavailable provider, dependency omission, partial restore, and missed recovery objective.",
          "zh": "运行正向控制“一项通过数据与业务检查的代表性时间点恢复”，并执行包含“作业失败、副本损坏、删除/加密尝试、密钥丢失、提供商不可用、依赖遗漏、部分恢复和未达恢复目标”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-11.2-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "11.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-11.2-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "11.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-11.2-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "11.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-11.2-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "11.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-11.2-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "11.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever asset and data inventories, backup platforms, cloud snapshots, SaaS exports, immutable/offline stores, key custody, job logs, restore tests, and continuity plans change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 资产与数据清单、备份平台、云快照、SaaS 导出、不可变/离线存储、密钥保管、作业日志、恢复测试和连续性计划 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-11.2-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "11.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original recovery pattern analysis",
          "basis_zh": "SOSEC 原创 recovery 模式分析",
          "en": "Use protected, missed, failed, stale, corrupt, reachable-by-production, keyless, untested, restore-failed, and business-validated recovery objects to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已保护、漏备、失败、陈旧、损坏、生产可达、无密钥、未测试、恢复失败和业务已验证恢复对象 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "11.3",
      "control": 11,
      "title_en": "Protect Recovery Data",
      "title_zh": "恢复数据保护",
      "first_ig": 1,
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Data",
      "security_function": "Protect",
      "patterns": [
        "recovery",
        "data_lifecycle"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "1.1",
          "2.1",
          "4.1"
        ],
        "variables": [
          "GV3",
          "GV33",
          "GV34",
          "M1",
          "M2",
          "M3"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "Recovery copies inherit at least the confidentiality, integrity and access requirements of the source, plus stronger resistance to destructive administrators and malware.",
          "build": "Encrypt in transit and at rest, separate backup and production identities/administration, enforce MFA and least privilege, make critical copies immutable, monitor access/deletion, protect keys and test integrity.",
          "proof": "Attempt read, alteration and deletion using ordinary production and backup operators, then verify denial/alert or documented authority.",
          "boundary": "CAS reduces this safeguard to encryption, which leaves ransomware and privileged deletion untested."
        },
        "zh": {
          "scope": "恢复副本至少继承源数据的机密、完整和访问要求，并额外抵抗破坏性管理员与恶意软件。",
          "build": "传输/静态加密，分离备份与生产身份/管理，MFA 与最小权限，关键副本不可变，监测访问/删除，保护密钥并验完整性；若威胁模型含生产失陷，使用独立账号/租户。",
          "proof": "用普通生产和备份管理员尝试读、改、删，验证拒绝/告警或明示权力；恢复并哈希/抽样内容，检查密钥和不可变策略，确认日志存活，并逐副本对照源分级要求。",
          "boundary": "CAS 把本项缩成加密，未测勒索和高权删除。"
        }
      },
      "category_counts": {
        "outcome": 7,
        "scope": 7,
        "ownership": 7,
        "data": 7,
        "integration": 7,
        "control": 7,
        "timing": 7,
        "exception": 7,
        "evidence": 7,
        "security": 7,
        "testing": 7,
        "operations": 7
      },
      "requirement_count": 84,
      "requirements": [
        {
          "code": "CIS-11.3-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "11.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Protect Recovery Data; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“恢复数据保护”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-11.3-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "11.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 11.3, official Asset Class Data, Security Function Protect, and IG1 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 11.3、官方资产类别“数据”、安全功能“保护”和首次出现的 IG1，并保存来源抓取日期。"
        },
        {
          "code": "CIS-11.3-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "11.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Recovery copies inherit at least the confidentiality, integrity and access requirements of the source, plus stronger resistance to destructive administrators and malware.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“恢复副本至少继承源数据的机密、完整和访问要求，并额外抵抗破坏性管理员与恶意软件。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-11.3-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "11.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-11.3-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "11.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Protect Recovery Data to its operating object—protected data and configuration recovery points, copies, keys, isolation, integrity, restore dependencies, and business recovery outcomes—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“恢复数据保护”连接到其运营对象——受保护数据与配置的恢复点、副本、密钥、隔离、完整性、恢复依赖和业务恢复结果——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-11.3-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "11.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original recovery pattern analysis",
          "basis_zh": "SOSEC 原创 recovery 模式分析",
          "en": "For Protect Recovery Data, express success as an observable decision over recoverable business service, protected recovery point, trustworthy copy, dependency, recovery objective, and verified restored outcome; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“恢复数据保护”，以 可恢复业务服务、受保护恢复点、可信副本、依赖、恢复目标和经验证的恢复结果 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-11.3-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "11.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "For Protect Recovery Data, express success as an observable decision over data identity, sensitivity, owner, purpose, location, flow, access, retention, copy, derivation, and disposal state; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“恢复数据保护”，以 数据身份、敏感度、责任人、目的、位置、流向、访问、保留、副本、派生与销毁状态 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-11.3-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "11.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-11.3-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "11.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-11.3-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "11.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-11.3-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "11.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-11.3-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "11.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across corrupt source data, silent job failure, ransomware reachability, deleted tenants, missing keys, stale runbooks, region/provider loss, capacity limits, and partial restore; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 源数据损坏、作业静默失败、勒索软件可达、租户删除、密钥缺失、手册陈旧、地域/提供商丢失、容量限制和部分恢复 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-11.3-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "11.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original recovery pattern analysis",
          "basis_zh": "SOSEC 原创 recovery 模式分析",
          "en": "Include silent job failure, corrupt source, ransomware reachability, missing key, provider or region loss, quota, partial restore, stale runbook, and clean-room unavailability in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 作业静默失败、源损坏、勒索软件可达、密钥缺失、提供商或地域丢失、配额、部分恢复、手册陈旧和洁净室不可用 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-11.3-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "11.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Include unstructured and derived data, logs, caches, backups, exports, client-side copies, cross-region processing, AI corpora, holds, and provider residues in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 非结构化与派生数据、日志、缓存、备份、导出、客户端副本、跨地域处理、AI 语料、保全和提供商残留 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-11.3-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "11.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-11.3-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "11.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-11.3-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "11.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-11.3-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "11.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-11.3-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "11.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind data and service owners, backup operators, infrastructure, security, business continuity, legal, and recovery decision makers to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 数据与服务责任人、备份运营、基础设施、安全、业务连续性、法务和恢复决策人 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-11.3-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "11.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original recovery pattern analysis",
          "basis_zh": "SOSEC 原创 recovery 模式分析",
          "en": "Name who may transition protected object identified → copy created → isolated/verified → retained → selected → restored → business-validated → expired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 识别受保护对象 → 创建副本 → 隔离/验证 → 保留 → 选择 → 恢复 → 业务验证 → 到期，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-11.3-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "11.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Name who may transition created/collected → classified → approved use and flow → retained/held → disposed with verification, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-11.3-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "11.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-11.3-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "11.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-11.3-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "11.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV3, GV33, GV34, M1, M2, M3) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV3, GV33, GV34, M1, M2, M3）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-11.3-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "11.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-11.3-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "11.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the recovery inventory, policy, job, vault, and restoration authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把恢复清单、策略、作业、保险库和还原权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-11.3-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "11.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original recovery pattern analysis",
          "basis_zh": "SOSEC 原创 recovery 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle protected object identified → copy created → isolated/verified → retained → selected → restored → business-validated → expired.",
          "zh": "对生命周期“识别受保护对象 → 创建副本 → 隔离/验证 → 保留 → 选择 → 恢复 → 业务验证 → 到期”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-11.3-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "11.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle created/collected → classified → approved use and flow → retained/held → disposed with verification.",
          "zh": "对生命周期“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-11.3-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "11.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 1.1, Safeguard 2.1, Safeguard 4.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 1.1、Safeguard 2.1、Safeguard 4.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-11.3-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "11.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-11.3-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "11.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-11.3-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "11.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-11.3-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "11.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile asset and data inventories, backup platforms, cloud snapshots, SaaS exports, immutable/offline stores, key custody, job logs, restore tests, and continuity plans and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 资产与数据清单、备份平台、云快照、SaaS 导出、不可变/离线存储、密钥保管、作业日志、恢复测试和连续性计划，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-11.3-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "11.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original recovery pattern analysis",
          "basis_zh": "SOSEC 原创 recovery 模式分析",
          "en": "Require every connector carrying recoverable business service, protected recovery point, trustworthy copy, dependency, recovery objective, and verified restored outcome to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 可恢复业务服务、受保护恢复点、可信副本、依赖、恢复目标和经验证的恢复结果 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-11.3-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "11.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Require every connector carrying data identity, sensitivity, owner, purpose, location, flow, access, retention, copy, derivation, and disposal state to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 数据身份、敏感度、责任人、目的、位置、流向、访问、保留、副本、派生与销毁状态 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-11.3-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "11.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Encrypt in transit and at rest, separate backup and production identities/administration, enforce MFA and least privilege, make critical copies immutable, monitor access/deletion, protect keys and test integrity.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“传输/静态加密，分离备份与生产身份/管理，MFA 与最小权限，关键副本不可变，监测访问/删除，保护密钥并验完整性；若威胁模型含生产失陷，使用独立账号/租户。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-11.3-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "11.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-11.3-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "11.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-11.3-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "11.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-11.3-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "11.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the recovery inventory, policy, job, vault, and restoration authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在恢复清单、策略、作业、保险库和还原权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-11.3-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "11.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original recovery pattern analysis",
          "basis_zh": "SOSEC 原创 recovery 模式分析",
          "en": "Implement the explicit state machine protected object identified → copy created → isolated/verified → retained → selected → restored → business-validated → expired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“识别受保护对象 → 创建副本 → 隔离/验证 → 保留 → 选择 → 恢复 → 业务验证 → 到期”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-11.3-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "11.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Implement the explicit state machine created/collected → classified → approved use and flow → retained/held → disposed with verification; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-11.3-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "11.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-11.3-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "11.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-11.3-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "11.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-11.3-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "11.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-11.3-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "11.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in protected data and configuration recovery points, copies, keys, isolation, integrity, restore dependencies, and business recovery outcomes; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 受保护数据与配置的恢复点、副本、密钥、隔离、完整性、恢复依赖和业务恢复结果 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-11.3-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "11.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original recovery pattern analysis",
          "basis_zh": "SOSEC 原创 recovery 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for protected object identified → copy created → isolated/verified → retained → selected → restored → business-validated → expired; alert before each deadline becomes overdue.",
          "zh": "为“识别受保护对象 → 创建副本 → 隔离/验证 → 保留 → 选择 → 恢复 → 业务验证 → 到期”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-11.3-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "11.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for created/collected → classified → approved use and flow → retained/held → disposed with verification; alert before each deadline becomes overdue.",
          "zh": "为“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-11.3-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "11.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “CAS reduces this safeguard to encryption, which leaves ransomware and privileged deletion untested.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“CAS 把本项缩成加密，未测勒索和高权删除。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-11.3-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "11.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-11.3-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "11.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-11.3-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "11.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-11.3-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "11.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat corrupt source data, silent job failure, ransomware reachability, deleted tenants, missing keys, stale runbooks, region/provider loss, capacity limits, and partial restore as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 源数据损坏、作业静默失败、勒索软件可达、租户删除、密钥缺失、手册陈旧、地域/提供商丢失、容量限制和部分恢复 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-11.3-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "11.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original recovery pattern analysis",
          "basis_zh": "SOSEC 原创 recovery 模式分析",
          "en": "Treat silent job failure, corrupt source, ransomware reachability, missing key, provider or region loss, quota, partial restore, stale runbook, and clean-room unavailability as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 作业静默失败、源损坏、勒索软件可达、密钥缺失、提供商或地域丢失、配额、部分恢复、手册陈旧和洁净室不可用 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-11.3-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "11.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Treat unstructured and derived data, logs, caches, backups, exports, client-side copies, cross-region processing, AI corpora, holds, and provider residues as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 非结构化与派生数据、日志、缓存、备份、导出、客户端副本、跨地域处理、AI 语料、保全和提供商残留 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-11.3-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "11.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Attempt read, alteration and deletion using ordinary production and backup operators, then verify denial/alert or documented authority.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“用普通生产和备份管理员尝试读、改、删，验证拒绝/告警或明示权力；恢复并哈希/抽样内容，检查密钥和不可变策略，确认日志存活，并逐副本对照源分级要求。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-11.3-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "11.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-11.3-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "11.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 6 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、6 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-11.3-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "11.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-11.3-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "11.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the recovery inventory, policy, job, vault, and restoration authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以恢复清单、策略、作业、保险库和还原权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-11.3-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "11.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original recovery pattern analysis",
          "basis_zh": "SOSEC 原创 recovery 模式分析",
          "en": "Publish protected, missed, failed, stale, corrupt, reachable-by-production, keyless, untested, restore-failed, and business-validated recovery objects with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已保护、漏备、失败、陈旧、损坏、生产可达、无密钥、未测试、恢复失败和业务已验证恢复对象，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-11.3-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "11.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Publish known, unknown, classified, ownerless, over-retained, prematurely deleted, unapproved copy, blocked flow, held, and disposal-verified data sets with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已知、未知、已分类、无责任人、超期保留、过早删除、未批准副本、被阻断流、保全及销毁已验证数据集，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-11.3-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "11.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-11.3-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "11.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-11.3-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "11.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-11.3-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "11.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-11.3-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "11.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the recovery inventory, policy, job, vault, and restoration authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护恢复清单、策略、作业、保险库和还原权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-11.3-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "11.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original recovery pattern analysis",
          "basis_zh": "SOSEC 原创 recovery 模式分析",
          "en": "Restrict authority to change protected object identified → copy created → isolated/verified → retained → selected → restored → business-validated → expired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“识别受保护对象 → 创建副本 → 隔离/验证 → 保留 → 选择 → 恢复 → 业务验证 → 到期”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-11.3-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "11.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Restrict authority to change created/collected → classified → approved use and flow → retained/held → disposed with verification; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-11.3-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "11.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-11.3-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "11.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-11.3-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "11.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-11.3-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "11.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-11.3-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "11.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise successful and failed jobs, isolated-copy access, deletion and encryption attempts, point-in-time restore, clean-room rebuild, provider loss, and business transaction validation through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 成功与失败作业、隔离副本访问、删除与加密尝试、时间点恢复、洁净室重建、提供商丢失和业务交易验证，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-11.3-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "11.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original recovery pattern analysis",
          "basis_zh": "SOSEC 原创 recovery 模式分析",
          "en": "Run the positive control a representative point-in-time restoration that passes data and business checks; exercise negative, stale, duplicate, bypass, and outage controls including failed job, corrupt copy, deletion/encryption attempt, lost key, unavailable provider, dependency omission, partial restore, and missed recovery objective.",
          "zh": "运行正向控制“一项通过数据与业务检查的代表性时间点恢复”，并执行包含“作业失败、副本损坏、删除/加密尝试、密钥丢失、提供商不可用、依赖遗漏、部分恢复和未达恢复目标”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-11.3-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "11.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Run the positive control an approved data set following its declared use, access, transfer, retention, and disposal path; exercise negative, stale, duplicate, bypass, and outage controls including an unknown or misclassified copy, forbidden reader or flow, early deletion, expired retention, failed disposal, and provider residue.",
          "zh": "运行正向控制“按声明用途、访问、传输、保留和销毁路径流转的获批数据集”，并执行包含“未知或误分类副本、禁止读取者或流向、过早删除、保留过期、销毁失败和提供商残留”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-11.3-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "11.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-11.3-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "11.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-11.3-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "11.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-11.3-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "11.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-11.3-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "11.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever asset and data inventories, backup platforms, cloud snapshots, SaaS exports, immutable/offline stores, key custody, job logs, restore tests, and continuity plans change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 资产与数据清单、备份平台、云快照、SaaS 导出、不可变/离线存储、密钥保管、作业日志、恢复测试和连续性计划 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-11.3-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "11.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original recovery pattern analysis",
          "basis_zh": "SOSEC 原创 recovery 模式分析",
          "en": "Use protected, missed, failed, stale, corrupt, reachable-by-production, keyless, untested, restore-failed, and business-validated recovery objects to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已保护、漏备、失败、陈旧、损坏、生产可达、无密钥、未测试、恢复失败和业务已验证恢复对象 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-11.3-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "11.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Use known, unknown, classified, ownerless, over-retained, prematurely deleted, unapproved copy, blocked flow, held, and disposal-verified data sets to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已知、未知、已分类、无责任人、超期保留、过早删除、未批准副本、被阻断流、保全及销毁已验证数据集 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "11.4",
      "control": 11,
      "title_en": "Establish and Maintain an Isolated Instance of Recovery Data",
      "title_zh": "隔离恢复副本",
      "first_ig": 1,
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Data",
      "security_function": "Recover",
      "patterns": [
        "recovery",
        "data_lifecycle"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "1.1",
          "4.1"
        ],
        "variables": [
          "GV3",
          "GV33",
          "GV34",
          "M1",
          "M2",
          "M3"
        ],
        "metric_branches": 1,
        "has_assumptions": true,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "At least one recovery instance must be isolated from the failure and authority domain that can destroy production and primary backups.",
          "build": "Design a distinct trust path with separate credentials, write-once or delayed deletion, protected catalog/keys and controlled restore channel.",
          "proof": "Compromise or disable a test production administrator and attempt to enumerate/delete the isolated copy.",
          "boundary": "A cloud bucket in another region under the same compromised root is not isolated."
        },
        "zh": {
          "scope": "至少一份恢复数据要与能破坏生产及主备份的故障/权限域隔离。",
          "build": "设计不同信任路径，独立凭据、只写或延迟删除、受保护目录/密钥和受控恢复通道；保留早于可能攻击驻留期的版本，监控桥接，并说明每份副本能抵抗哪些故障及如何重新连接。",
          "proof": "禁用或“攻陷”测试生产管理员，尝试枚举/删除隔离副本；模拟主地域/账号和备份 Console 故障后走独立路径恢复，验证删除延迟、凭据分离、净室访问和最后良好点。",
          "boundary": "同一 Root 管理的跨地域 Bucket 不是隔离。"
        }
      },
      "category_counts": {
        "outcome": 7,
        "scope": 7,
        "ownership": 7,
        "data": 7,
        "integration": 7,
        "control": 7,
        "timing": 7,
        "exception": 7,
        "evidence": 7,
        "security": 7,
        "testing": 7,
        "operations": 7
      },
      "requirement_count": 84,
      "requirements": [
        {
          "code": "CIS-11.4-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "11.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Establish and Maintain an Isolated Instance of Recovery Data; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“隔离恢复副本”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-11.4-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "11.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 11.4, official Asset Class Data, Security Function Recover, and IG1 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 11.4、官方资产类别“数据”、安全功能“恢复”和首次出现的 IG1，并保存来源抓取日期。"
        },
        {
          "code": "CIS-11.4-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "11.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “At least one recovery instance must be isolated from the failure and authority domain that can destroy production and primary backups.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“至少一份恢复数据要与能破坏生产及主备份的故障/权限域隔离。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-11.4-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "11.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-11.4-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "11.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Establish and Maintain an Isolated Instance of Recovery Data to its operating object—protected data and configuration recovery points, copies, keys, isolation, integrity, restore dependencies, and business recovery outcomes—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“隔离恢复副本”连接到其运营对象——受保护数据与配置的恢复点、副本、密钥、隔离、完整性、恢复依赖和业务恢复结果——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-11.4-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "11.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original recovery pattern analysis",
          "basis_zh": "SOSEC 原创 recovery 模式分析",
          "en": "For Establish and Maintain an Isolated Instance of Recovery Data, express success as an observable decision over recoverable business service, protected recovery point, trustworthy copy, dependency, recovery objective, and verified restored outcome; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“隔离恢复副本”，以 可恢复业务服务、受保护恢复点、可信副本、依赖、恢复目标和经验证的恢复结果 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-11.4-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "11.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "For Establish and Maintain an Isolated Instance of Recovery Data, express success as an observable decision over data identity, sensitivity, owner, purpose, location, flow, access, retention, copy, derivation, and disposal state; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“隔离恢复副本”，以 数据身份、敏感度、责任人、目的、位置、流向、访问、保留、副本、派生与销毁状态 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-11.4-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "11.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-11.4-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "11.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-11.4-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "11.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-11.4-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "11.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-11.4-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "11.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across corrupt source data, silent job failure, ransomware reachability, deleted tenants, missing keys, stale runbooks, region/provider loss, capacity limits, and partial restore; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 源数据损坏、作业静默失败、勒索软件可达、租户删除、密钥缺失、手册陈旧、地域/提供商丢失、容量限制和部分恢复 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-11.4-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "11.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original recovery pattern analysis",
          "basis_zh": "SOSEC 原创 recovery 模式分析",
          "en": "Include silent job failure, corrupt source, ransomware reachability, missing key, provider or region loss, quota, partial restore, stale runbook, and clean-room unavailability in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 作业静默失败、源损坏、勒索软件可达、密钥缺失、提供商或地域丢失、配额、部分恢复、手册陈旧和洁净室不可用 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-11.4-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "11.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Include unstructured and derived data, logs, caches, backups, exports, client-side copies, cross-region processing, AI corpora, holds, and provider residues in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 非结构化与派生数据、日志、缓存、备份、导出、客户端副本、跨地域处理、AI 语料、保全和提供商残留 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-11.4-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "11.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-11.4-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "11.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-11.4-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "11.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-11.4-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "11.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-11.4-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "11.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind data and service owners, backup operators, infrastructure, security, business continuity, legal, and recovery decision makers to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 数据与服务责任人、备份运营、基础设施、安全、业务连续性、法务和恢复决策人 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-11.4-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "11.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original recovery pattern analysis",
          "basis_zh": "SOSEC 原创 recovery 模式分析",
          "en": "Name who may transition protected object identified → copy created → isolated/verified → retained → selected → restored → business-validated → expired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 识别受保护对象 → 创建副本 → 隔离/验证 → 保留 → 选择 → 恢复 → 业务验证 → 到期，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-11.4-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "11.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Name who may transition created/collected → classified → approved use and flow → retained/held → disposed with verification, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-11.4-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "11.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-11.4-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "11.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-11.4-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "11.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV3, GV33, GV34, M1, M2, M3) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV3, GV33, GV34, M1, M2, M3）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-11.4-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "11.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-11.4-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "11.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the recovery inventory, policy, job, vault, and restoration authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把恢复清单、策略、作业、保险库和还原权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-11.4-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "11.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original recovery pattern analysis",
          "basis_zh": "SOSEC 原创 recovery 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle protected object identified → copy created → isolated/verified → retained → selected → restored → business-validated → expired.",
          "zh": "对生命周期“识别受保护对象 → 创建副本 → 隔离/验证 → 保留 → 选择 → 恢复 → 业务验证 → 到期”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-11.4-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "11.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle created/collected → classified → approved use and flow → retained/held → disposed with verification.",
          "zh": "对生命周期“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-11.4-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "11.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 1.1, Safeguard 4.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 1.1、Safeguard 4.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-11.4-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "11.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-11.4-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "11.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-11.4-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "11.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-11.4-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "11.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile asset and data inventories, backup platforms, cloud snapshots, SaaS exports, immutable/offline stores, key custody, job logs, restore tests, and continuity plans and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 资产与数据清单、备份平台、云快照、SaaS 导出、不可变/离线存储、密钥保管、作业日志、恢复测试和连续性计划，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-11.4-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "11.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original recovery pattern analysis",
          "basis_zh": "SOSEC 原创 recovery 模式分析",
          "en": "Require every connector carrying recoverable business service, protected recovery point, trustworthy copy, dependency, recovery objective, and verified restored outcome to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 可恢复业务服务、受保护恢复点、可信副本、依赖、恢复目标和经验证的恢复结果 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-11.4-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "11.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Require every connector carrying data identity, sensitivity, owner, purpose, location, flow, access, retention, copy, derivation, and disposal state to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 数据身份、敏感度、责任人、目的、位置、流向、访问、保留、副本、派生与销毁状态 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-11.4-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "11.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Design a distinct trust path with separate credentials, write-once or delayed deletion, protected catalog/keys and controlled restore channel.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“设计不同信任路径，独立凭据、只写或延迟删除、受保护目录/密钥和受控恢复通道；保留早于可能攻击驻留期的版本，监控桥接，并说明每份副本能抵抗哪些故障及如何重新连接。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-11.4-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "11.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-11.4-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "11.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-11.4-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "11.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-11.4-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "11.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the recovery inventory, policy, job, vault, and restoration authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在恢复清单、策略、作业、保险库和还原权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-11.4-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "11.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original recovery pattern analysis",
          "basis_zh": "SOSEC 原创 recovery 模式分析",
          "en": "Implement the explicit state machine protected object identified → copy created → isolated/verified → retained → selected → restored → business-validated → expired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“识别受保护对象 → 创建副本 → 隔离/验证 → 保留 → 选择 → 恢复 → 业务验证 → 到期”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-11.4-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "11.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Implement the explicit state machine created/collected → classified → approved use and flow → retained/held → disposed with verification; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-11.4-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "11.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-11.4-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "11.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-11.4-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "11.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-11.4-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "11.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-11.4-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "11.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in protected data and configuration recovery points, copies, keys, isolation, integrity, restore dependencies, and business recovery outcomes; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 受保护数据与配置的恢复点、副本、密钥、隔离、完整性、恢复依赖和业务恢复结果 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-11.4-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "11.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original recovery pattern analysis",
          "basis_zh": "SOSEC 原创 recovery 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for protected object identified → copy created → isolated/verified → retained → selected → restored → business-validated → expired; alert before each deadline becomes overdue.",
          "zh": "为“识别受保护对象 → 创建副本 → 隔离/验证 → 保留 → 选择 → 恢复 → 业务验证 → 到期”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-11.4-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "11.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for created/collected → classified → approved use and flow → retained/held → disposed with verification; alert before each deadline becomes overdue.",
          "zh": "为“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-11.4-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "11.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “A cloud bucket in another region under the same compromised root is not isolated.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“同一 Root 管理的跨地域 Bucket 不是隔离。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-11.4-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "11.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-11.4-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "11.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-11.4-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "11.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-11.4-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "11.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat corrupt source data, silent job failure, ransomware reachability, deleted tenants, missing keys, stale runbooks, region/provider loss, capacity limits, and partial restore as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 源数据损坏、作业静默失败、勒索软件可达、租户删除、密钥缺失、手册陈旧、地域/提供商丢失、容量限制和部分恢复 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-11.4-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "11.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original recovery pattern analysis",
          "basis_zh": "SOSEC 原创 recovery 模式分析",
          "en": "Treat silent job failure, corrupt source, ransomware reachability, missing key, provider or region loss, quota, partial restore, stale runbook, and clean-room unavailability as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 作业静默失败、源损坏、勒索软件可达、密钥缺失、提供商或地域丢失、配额、部分恢复、手册陈旧和洁净室不可用 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-11.4-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "11.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Treat unstructured and derived data, logs, caches, backups, exports, client-side copies, cross-region processing, AI corpora, holds, and provider residues as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 非结构化与派生数据、日志、缓存、备份、导出、客户端副本、跨地域处理、AI 语料、保全和提供商残留 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-11.4-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "11.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Compromise or disable a test production administrator and attempt to enumerate/delete the isolated copy.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“禁用或“攻陷”测试生产管理员，尝试枚举/删除隔离副本；模拟主地域/账号和备份 Console 故障后走独立路径恢复，验证删除延迟、凭据分离、净室访问和最后良好点。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-11.4-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "11.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-11.4-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "11.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 6 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、6 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-11.4-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "11.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-11.4-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "11.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the recovery inventory, policy, job, vault, and restoration authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以恢复清单、策略、作业、保险库和还原权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-11.4-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "11.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original recovery pattern analysis",
          "basis_zh": "SOSEC 原创 recovery 模式分析",
          "en": "Publish protected, missed, failed, stale, corrupt, reachable-by-production, keyless, untested, restore-failed, and business-validated recovery objects with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已保护、漏备、失败、陈旧、损坏、生产可达、无密钥、未测试、恢复失败和业务已验证恢复对象，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-11.4-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "11.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Publish known, unknown, classified, ownerless, over-retained, prematurely deleted, unapproved copy, blocked flow, held, and disposal-verified data sets with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已知、未知、已分类、无责任人、超期保留、过早删除、未批准副本、被阻断流、保全及销毁已验证数据集，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-11.4-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "11.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-11.4-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "11.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-11.4-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "11.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-11.4-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "11.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-11.4-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "11.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the recovery inventory, policy, job, vault, and restoration authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护恢复清单、策略、作业、保险库和还原权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-11.4-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "11.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original recovery pattern analysis",
          "basis_zh": "SOSEC 原创 recovery 模式分析",
          "en": "Restrict authority to change protected object identified → copy created → isolated/verified → retained → selected → restored → business-validated → expired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“识别受保护对象 → 创建副本 → 隔离/验证 → 保留 → 选择 → 恢复 → 业务验证 → 到期”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-11.4-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "11.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Restrict authority to change created/collected → classified → approved use and flow → retained/held → disposed with verification; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-11.4-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "11.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-11.4-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "11.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-11.4-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "11.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-11.4-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "11.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-11.4-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "11.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise successful and failed jobs, isolated-copy access, deletion and encryption attempts, point-in-time restore, clean-room rebuild, provider loss, and business transaction validation through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 成功与失败作业、隔离副本访问、删除与加密尝试、时间点恢复、洁净室重建、提供商丢失和业务交易验证，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-11.4-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "11.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original recovery pattern analysis",
          "basis_zh": "SOSEC 原创 recovery 模式分析",
          "en": "Run the positive control a representative point-in-time restoration that passes data and business checks; exercise negative, stale, duplicate, bypass, and outage controls including failed job, corrupt copy, deletion/encryption attempt, lost key, unavailable provider, dependency omission, partial restore, and missed recovery objective.",
          "zh": "运行正向控制“一项通过数据与业务检查的代表性时间点恢复”，并执行包含“作业失败、副本损坏、删除/加密尝试、密钥丢失、提供商不可用、依赖遗漏、部分恢复和未达恢复目标”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-11.4-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "11.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Run the positive control an approved data set following its declared use, access, transfer, retention, and disposal path; exercise negative, stale, duplicate, bypass, and outage controls including an unknown or misclassified copy, forbidden reader or flow, early deletion, expired retention, failed disposal, and provider residue.",
          "zh": "运行正向控制“按声明用途、访问、传输、保留和销毁路径流转的获批数据集”，并执行包含“未知或误分类副本、禁止读取者或流向、过早删除、保留过期、销毁失败和提供商残留”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-11.4-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "11.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-11.4-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "11.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-11.4-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "11.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-11.4-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "11.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-11.4-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "11.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever asset and data inventories, backup platforms, cloud snapshots, SaaS exports, immutable/offline stores, key custody, job logs, restore tests, and continuity plans change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 资产与数据清单、备份平台、云快照、SaaS 导出、不可变/离线存储、密钥保管、作业日志、恢复测试和连续性计划 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-11.4-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "11.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original recovery pattern analysis",
          "basis_zh": "SOSEC 原创 recovery 模式分析",
          "en": "Use protected, missed, failed, stale, corrupt, reachable-by-production, keyless, untested, restore-failed, and business-validated recovery objects to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已保护、漏备、失败、陈旧、损坏、生产可达、无密钥、未测试、恢复失败和业务已验证恢复对象 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-11.4-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "11.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Use known, unknown, classified, ownerless, over-retained, prematurely deleted, unapproved copy, blocked flow, held, and disposal-verified data sets to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已知、未知、已分类、无责任人、超期保留、过早删除、未批准副本、被阻断流、保全及销毁已验证数据集 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "11.5",
      "control": 11,
      "title_en": "Test Data Recovery",
      "title_zh": "恢复演练",
      "first_ig": 2,
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Data",
      "security_function": "Recover",
      "patterns": [
        "recovery",
        "data_lifecycle"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "1.1"
        ],
        "variables": [
          "M1",
          "M2",
          "M3",
          "M4"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [
        "quarterly"
      ],
      "implementation_contract": {
        "en": {
          "scope": "The quarterly sample must represent business criticality, technology, size, encryption, provider and recovery path; its selection method prevents an easiest-small-files bias.",
          "build": "Maintain a risk-based rotation, isolated test environment, success criteria for RTO/RPO, integrity, security and business function, and remediation owners.",
          "proof": "Restore from selected points without using production shortcuts, validate data/application semantics, authentication, network dependencies, security baseline and user acceptance, then securely dispose of test copies.",
          "boundary": "A tool reporting “restore successful” may deliver corrupt, stale or unusable data."
        },
        "zh": {
          "scope": "季度抽样必须代表业务关键度、技术、规模、加密、服务商和恢复路径，不能只挑最好恢复的小文件；长期轮转应覆盖每个关键服务和依赖，包括全服务重建而非只解压文件。",
          "build": "维护风险化轮转、隔离测试环境，以及 RTO/RPO、完整性、安全和业务功能成功标准；保留命令、版本、密钥和人工步骤，给修复指定责任人，并把重复人工过程自动化。",
          "proof": "不借生产捷径从选定点恢复，验证数据/应用语义、认证、网络依赖、安全基线和用户验收，随后安全销毁测试副本；记录实测时间、数据损失、失败和复测关闭。",
          "boundary": "工具显示“恢复成功”可能只得到损坏、陈旧或不可用数据；隔离副本也要周期测试。"
        }
      },
      "category_counts": {
        "outcome": 7,
        "scope": 7,
        "ownership": 7,
        "data": 7,
        "integration": 7,
        "control": 7,
        "timing": 7,
        "exception": 7,
        "evidence": 7,
        "security": 7,
        "testing": 7,
        "operations": 7
      },
      "requirement_count": 84,
      "requirements": [
        {
          "code": "CIS-11.5-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "11.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Test Data Recovery; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“恢复演练”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-11.5-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "11.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 11.5, official Asset Class Data, Security Function Recover, and IG2 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 11.5、官方资产类别“数据”、安全功能“恢复”和首次出现的 IG2，并保存来源抓取日期。"
        },
        {
          "code": "CIS-11.5-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "11.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “The quarterly sample must represent business criticality, technology, size, encryption, provider and recovery path; its selection method prevents an easiest-small-files bias.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“季度抽样必须代表业务关键度、技术、规模、加密、服务商和恢复路径，不能只挑最好恢复的小文件；长期轮转应覆盖每个关键服务和依赖，包括全服务重建而非只解压文件。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-11.5-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "11.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-11.5-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "11.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Test Data Recovery to its operating object—protected data and configuration recovery points, copies, keys, isolation, integrity, restore dependencies, and business recovery outcomes—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“恢复演练”连接到其运营对象——受保护数据与配置的恢复点、副本、密钥、隔离、完整性、恢复依赖和业务恢复结果——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-11.5-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "11.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original recovery pattern analysis",
          "basis_zh": "SOSEC 原创 recovery 模式分析",
          "en": "For Test Data Recovery, express success as an observable decision over recoverable business service, protected recovery point, trustworthy copy, dependency, recovery objective, and verified restored outcome; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“恢复演练”，以 可恢复业务服务、受保护恢复点、可信副本、依赖、恢复目标和经验证的恢复结果 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-11.5-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "11.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "For Test Data Recovery, express success as an observable decision over data identity, sensitivity, owner, purpose, location, flow, access, retention, copy, derivation, and disposal state; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“恢复演练”，以 数据身份、敏感度、责任人、目的、位置、流向、访问、保留、副本、派生与销毁状态 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-11.5-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "11.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-11.5-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "11.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-11.5-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "11.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-11.5-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "11.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-11.5-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "11.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across corrupt source data, silent job failure, ransomware reachability, deleted tenants, missing keys, stale runbooks, region/provider loss, capacity limits, and partial restore; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 源数据损坏、作业静默失败、勒索软件可达、租户删除、密钥缺失、手册陈旧、地域/提供商丢失、容量限制和部分恢复 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-11.5-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "11.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original recovery pattern analysis",
          "basis_zh": "SOSEC 原创 recovery 模式分析",
          "en": "Include silent job failure, corrupt source, ransomware reachability, missing key, provider or region loss, quota, partial restore, stale runbook, and clean-room unavailability in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 作业静默失败、源损坏、勒索软件可达、密钥缺失、提供商或地域丢失、配额、部分恢复、手册陈旧和洁净室不可用 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-11.5-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "11.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Include unstructured and derived data, logs, caches, backups, exports, client-side copies, cross-region processing, AI corpora, holds, and provider residues in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 非结构化与派生数据、日志、缓存、备份、导出、客户端副本、跨地域处理、AI 语料、保全和提供商残留 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-11.5-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "11.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-11.5-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "11.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-11.5-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "11.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-11.5-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "11.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-11.5-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "11.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind data and service owners, backup operators, infrastructure, security, business continuity, legal, and recovery decision makers to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 数据与服务责任人、备份运营、基础设施、安全、业务连续性、法务和恢复决策人 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-11.5-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "11.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original recovery pattern analysis",
          "basis_zh": "SOSEC 原创 recovery 模式分析",
          "en": "Name who may transition protected object identified → copy created → isolated/verified → retained → selected → restored → business-validated → expired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 识别受保护对象 → 创建副本 → 隔离/验证 → 保留 → 选择 → 恢复 → 业务验证 → 到期，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-11.5-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "11.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Name who may transition created/collected → classified → approved use and flow → retained/held → disposed with verification, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-11.5-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "11.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-11.5-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "11.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-11.5-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "11.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (M1, M2, M3, M4) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（M1, M2, M3, M4）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-11.5-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "11.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-11.5-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "11.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the recovery inventory, policy, job, vault, and restoration authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把恢复清单、策略、作业、保险库和还原权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-11.5-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "11.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original recovery pattern analysis",
          "basis_zh": "SOSEC 原创 recovery 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle protected object identified → copy created → isolated/verified → retained → selected → restored → business-validated → expired.",
          "zh": "对生命周期“识别受保护对象 → 创建副本 → 隔离/验证 → 保留 → 选择 → 恢复 → 业务验证 → 到期”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-11.5-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "11.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle created/collected → classified → approved use and flow → retained/held → disposed with verification.",
          "zh": "对生命周期“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-11.5-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "11.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 1.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 1.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-11.5-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "11.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-11.5-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "11.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-11.5-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "11.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-11.5-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "11.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile asset and data inventories, backup platforms, cloud snapshots, SaaS exports, immutable/offline stores, key custody, job logs, restore tests, and continuity plans and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 资产与数据清单、备份平台、云快照、SaaS 导出、不可变/离线存储、密钥保管、作业日志、恢复测试和连续性计划，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-11.5-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "11.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original recovery pattern analysis",
          "basis_zh": "SOSEC 原创 recovery 模式分析",
          "en": "Require every connector carrying recoverable business service, protected recovery point, trustworthy copy, dependency, recovery objective, and verified restored outcome to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 可恢复业务服务、受保护恢复点、可信副本、依赖、恢复目标和经验证的恢复结果 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-11.5-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "11.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Require every connector carrying data identity, sensitivity, owner, purpose, location, flow, access, retention, copy, derivation, and disposal state to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 数据身份、敏感度、责任人、目的、位置、流向、访问、保留、副本、派生与销毁状态 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-11.5-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "11.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Maintain a risk-based rotation, isolated test environment, success criteria for RTO/RPO, integrity, security and business function, and remediation owners.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“维护风险化轮转、隔离测试环境，以及 RTO/RPO、完整性、安全和业务功能成功标准；保留命令、版本、密钥和人工步骤，给修复指定责任人，并把重复人工过程自动化。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-11.5-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "11.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-11.5-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "11.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-11.5-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "11.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-11.5-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "11.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the recovery inventory, policy, job, vault, and restoration authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在恢复清单、策略、作业、保险库和还原权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-11.5-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "11.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original recovery pattern analysis",
          "basis_zh": "SOSEC 原创 recovery 模式分析",
          "en": "Implement the explicit state machine protected object identified → copy created → isolated/verified → retained → selected → restored → business-validated → expired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“识别受保护对象 → 创建副本 → 隔离/验证 → 保留 → 选择 → 恢复 → 业务验证 → 到期”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-11.5-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "11.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Implement the explicit state machine created/collected → classified → approved use and flow → retained/held → disposed with verification; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-11.5-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "11.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (quarterly); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（quarterly）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-11.5-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "11.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-11.5-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "11.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-11.5-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "11.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-11.5-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "11.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in protected data and configuration recovery points, copies, keys, isolation, integrity, restore dependencies, and business recovery outcomes; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 受保护数据与配置的恢复点、副本、密钥、隔离、完整性、恢复依赖和业务恢复结果 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-11.5-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "11.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original recovery pattern analysis",
          "basis_zh": "SOSEC 原创 recovery 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for protected object identified → copy created → isolated/verified → retained → selected → restored → business-validated → expired; alert before each deadline becomes overdue.",
          "zh": "为“识别受保护对象 → 创建副本 → 隔离/验证 → 保留 → 选择 → 恢复 → 业务验证 → 到期”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-11.5-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "11.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for created/collected → classified → approved use and flow → retained/held → disposed with verification; alert before each deadline becomes overdue.",
          "zh": "为“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-11.5-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "11.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “A tool reporting “restore successful” may deliver corrupt, stale or unusable data.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“工具显示“恢复成功”可能只得到损坏、陈旧或不可用数据；隔离副本也要周期测试。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-11.5-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "11.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-11.5-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "11.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-11.5-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "11.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-11.5-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "11.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat corrupt source data, silent job failure, ransomware reachability, deleted tenants, missing keys, stale runbooks, region/provider loss, capacity limits, and partial restore as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 源数据损坏、作业静默失败、勒索软件可达、租户删除、密钥缺失、手册陈旧、地域/提供商丢失、容量限制和部分恢复 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-11.5-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "11.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original recovery pattern analysis",
          "basis_zh": "SOSEC 原创 recovery 模式分析",
          "en": "Treat silent job failure, corrupt source, ransomware reachability, missing key, provider or region loss, quota, partial restore, stale runbook, and clean-room unavailability as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 作业静默失败、源损坏、勒索软件可达、密钥缺失、提供商或地域丢失、配额、部分恢复、手册陈旧和洁净室不可用 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-11.5-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "11.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Treat unstructured and derived data, logs, caches, backups, exports, client-side copies, cross-region processing, AI corpora, holds, and provider residues as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 非结构化与派生数据、日志、缓存、备份、导出、客户端副本、跨地域处理、AI 语料、保全和提供商残留 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-11.5-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "11.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Restore from selected points without using production shortcuts, validate data/application semantics, authentication, network dependencies, security baseline and user acceptance, then securely dispose of test copies.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“不借生产捷径从选定点恢复，验证数据/应用语义、认证、网络依赖、安全基线和用户验收，随后安全销毁测试副本；记录实测时间、数据损失、失败和复测关闭。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-11.5-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "11.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-11.5-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "11.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 4 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、4 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-11.5-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "11.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-11.5-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "11.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the recovery inventory, policy, job, vault, and restoration authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以恢复清单、策略、作业、保险库和还原权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-11.5-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "11.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original recovery pattern analysis",
          "basis_zh": "SOSEC 原创 recovery 模式分析",
          "en": "Publish protected, missed, failed, stale, corrupt, reachable-by-production, keyless, untested, restore-failed, and business-validated recovery objects with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已保护、漏备、失败、陈旧、损坏、生产可达、无密钥、未测试、恢复失败和业务已验证恢复对象，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-11.5-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "11.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Publish known, unknown, classified, ownerless, over-retained, prematurely deleted, unapproved copy, blocked flow, held, and disposal-verified data sets with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已知、未知、已分类、无责任人、超期保留、过早删除、未批准副本、被阻断流、保全及销毁已验证数据集，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-11.5-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "11.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-11.5-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "11.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-11.5-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "11.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-11.5-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "11.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-11.5-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "11.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the recovery inventory, policy, job, vault, and restoration authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护恢复清单、策略、作业、保险库和还原权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-11.5-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "11.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original recovery pattern analysis",
          "basis_zh": "SOSEC 原创 recovery 模式分析",
          "en": "Restrict authority to change protected object identified → copy created → isolated/verified → retained → selected → restored → business-validated → expired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“识别受保护对象 → 创建副本 → 隔离/验证 → 保留 → 选择 → 恢复 → 业务验证 → 到期”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-11.5-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "11.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Restrict authority to change created/collected → classified → approved use and flow → retained/held → disposed with verification; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-11.5-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "11.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-11.5-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "11.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-11.5-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "11.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-11.5-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "11.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-11.5-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "11.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise successful and failed jobs, isolated-copy access, deletion and encryption attempts, point-in-time restore, clean-room rebuild, provider loss, and business transaction validation through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 成功与失败作业、隔离副本访问、删除与加密尝试、时间点恢复、洁净室重建、提供商丢失和业务交易验证，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-11.5-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "11.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original recovery pattern analysis",
          "basis_zh": "SOSEC 原创 recovery 模式分析",
          "en": "Run the positive control a representative point-in-time restoration that passes data and business checks; exercise negative, stale, duplicate, bypass, and outage controls including failed job, corrupt copy, deletion/encryption attempt, lost key, unavailable provider, dependency omission, partial restore, and missed recovery objective.",
          "zh": "运行正向控制“一项通过数据与业务检查的代表性时间点恢复”，并执行包含“作业失败、副本损坏、删除/加密尝试、密钥丢失、提供商不可用、依赖遗漏、部分恢复和未达恢复目标”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-11.5-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "11.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Run the positive control an approved data set following its declared use, access, transfer, retention, and disposal path; exercise negative, stale, duplicate, bypass, and outage controls including an unknown or misclassified copy, forbidden reader or flow, early deletion, expired retention, failed disposal, and provider residue.",
          "zh": "运行正向控制“按声明用途、访问、传输、保留和销毁路径流转的获批数据集”，并执行包含“未知或误分类副本、禁止读取者或流向、过早删除、保留过期、销毁失败和提供商残留”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-11.5-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "11.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-11.5-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "11.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-11.5-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "11.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-11.5-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "11.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-11.5-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "11.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever asset and data inventories, backup platforms, cloud snapshots, SaaS exports, immutable/offline stores, key custody, job logs, restore tests, and continuity plans change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 资产与数据清单、备份平台、云快照、SaaS 导出、不可变/离线存储、密钥保管、作业日志、恢复测试和连续性计划 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-11.5-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "11.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original recovery pattern analysis",
          "basis_zh": "SOSEC 原创 recovery 模式分析",
          "en": "Use protected, missed, failed, stale, corrupt, reachable-by-production, keyless, untested, restore-failed, and business-validated recovery objects to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已保护、漏备、失败、陈旧、损坏、生产可达、无密钥、未测试、恢复失败和业务已验证恢复对象 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-11.5-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "11.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Use known, unknown, classified, ownerless, over-retained, prematurely deleted, unapproved copy, blocked flow, held, and disposal-verified data sets to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已知、未知、已分类、无责任人、超期保留、过早删除、未批准副本、被阻断流、保全及销毁已验证数据集 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "12.1",
      "control": 12,
      "title_en": "Ensure Network Infrastructure is Up-to-Date",
      "title_zh": "网络基础设施生命周期",
      "first_ig": 1,
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Network",
      "security_function": "Protect",
      "patterns": [
        "network",
        "vulnerability"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "1.1"
        ],
        "variables": [
          "GV1",
          "GV35",
          "M1",
          "M2",
          "M3",
          "M4"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [
        "monthly"
      ],
      "implementation_contract": {
        "en": {
          "scope": "Include physical/virtual routers, switches, firewalls, wireless, controllers, VPN, load balancers, DNS/DHCP, SD-WAN, cloud networking and NaaS features with software/firmware and support state.",
          "build": "Review versions at least monthly, subscribe to vendor security/lifecycle notices, qualify stable targets, stage and roll out with redundant paths and rollback, and replace unsupported products.",
          "proof": "Reconcile every network asset/control plane to current and supported authoritative versions, sample running state, and deploy a lab/canary update including failover/rollback.",
          "boundary": "A newer release can introduce severe defects, so controlled deferral is valid with evidence and deadline."
        },
        "zh": {
          "scope": "包括物理/虚拟路由、交换、防火墙、无线、控制器、VPN、负载均衡、DNS/DHCP、SD-WAN、云网络和 NaaS 的软件/固件与支持状态。",
          "build": "至少每月查版本，订阅厂商安全/生命周期通知，验证稳定目标，带冗余路径和回滚分批升级，并替换不受支持产品；托管服务记录发布证据和租户仍需动作。",
          "proof": "把每个网络资产/控制面与权威当前/支持版本对账，抽查运行状态，并在实验室/金丝雀部署含故障转移/回滚的更新；不支持、易受害、延期、不可达和服务商不透明分别报告。",
          "boundary": "新版本也会有严重缺陷，有证据与截止日的受控延期可合理。"
        }
      },
      "category_counts": {
        "outcome": 7,
        "scope": 7,
        "ownership": 7,
        "data": 7,
        "integration": 7,
        "control": 7,
        "timing": 7,
        "exception": 7,
        "evidence": 7,
        "security": 7,
        "testing": 7,
        "operations": 7
      },
      "requirement_count": 84,
      "requirements": [
        {
          "code": "CIS-12.1-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "12.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Ensure Network Infrastructure is Up-to-Date; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“网络基础设施生命周期”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-12.1-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "12.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 12.1, official Asset Class Network, Security Function Protect, and IG1 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 12.1、官方资产类别“网络”、安全功能“保护”和首次出现的 IG1，并保存来源抓取日期。"
        },
        {
          "code": "CIS-12.1-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "12.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Include physical/virtual routers, switches, firewalls, wireless, controllers, VPN, load balancers, DNS/DHCP, SD-WAN, cloud networking and NaaS features with software/firmware and support state.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“包括物理/虚拟路由、交换、防火墙、无线、控制器、VPN、负载均衡、DNS/DHCP、SD-WAN、云网络和 NaaS 的软件/固件与支持状态。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-12.1-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "12.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-12.1-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "12.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Ensure Network Infrastructure is Up-to-Date to its operating object—network devices, virtual and cloud networking, topology, trust zones, routes, management planes, remote access, AAA, and administrative workstations—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“网络基础设施生命周期”连接到其运营对象——网络设备、虚拟与云网络、拓扑、信任区、路由、管理平面、远程访问、AAA 和管理工作站——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-12.1-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "12.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "For Ensure Network Infrastructure is Up-to-Date, express success as an observable decision over intended connectivity, trust zone, route, protocol, identity, management path, traffic decision, and observed outcome; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“网络基础设施生命周期”，以 预期连接、信任区、路由、协议、身份、管理路径、流量决策和观察结果 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-12.1-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "12.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "For Ensure Network Infrastructure is Up-to-Date, express success as an observable decision over affected artifact identity, exploitability, business consequence, remediation choice, deployed fix, compensating control, and residual exposure; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“网络基础设施生命周期”，以 受影响制品身份、可利用性、业务后果、修复选择、已部署修复、补偿控制和残余暴露 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-12.1-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "12.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-12.1-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "12.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-12.1-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "12.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-12.1-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "12.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-12.1-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "12.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across shadow links, overlapping address space, overlays, provider abstractions, unsupported protocols, emergency consoles, remote devices, stale diagrams, and asymmetric routes; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 影子链路、重叠地址、覆盖网络、提供商抽象、不支持协议、紧急控制台、远程设备、陈旧架构图和非对称路由 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-12.1-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "12.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Include IPv6, overlays, east-west paths, remote and roaming devices, direct egress, alternate resolvers, QUIC, asymmetric routes, provider abstraction, and emergency consoles in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 IPv6、覆盖网络、东西向路径、远程与漫游设备、直接出口、替代解析器、QUIC、非对称路由、提供商抽象和紧急控制台 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-12.1-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "12.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Include unknown versions, false positives, unavailable fixes, vendor lag, ephemeral workloads, unscannable platforms, inherited dependencies, mitigation-only states, and recurrence in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 未知版本、误报、无可用修复、厂商滞后、短生工作负载、不可扫描平台、继承依赖、仅缓解状态和复发 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-12.1-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "12.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-12.1-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "12.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-12.1-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "12.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-12.1-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "12.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-12.1-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "12.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind network and cloud engineering, security architecture, identity, service owners, operations, and change management to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 网络与云工程、安全架构、身份、服务责任人、运营和变更管理 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-12.1-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "12.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Name who may transition requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-12.1-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "12.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Name who may transition discovered → validated → prioritized → assigned → fixed/mitigated/excepted → deployed → retested → closed/reopened, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 发现 → 验证 → 定级 → 分派 → 修复/缓解/例外 → 部署 → 复测 → 关闭/重开，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-12.1-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "12.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-12.1-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "12.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-12.1-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "12.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV1, GV35, M1, M2, M3, M4) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV1, GV35, M1, M2, M3, M4）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-12.1-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "12.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-12.1-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "12.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the network inventory, architecture, configuration, and policy authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把网络清单、架构、配置与策略权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-12.1-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "12.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired.",
          "zh": "对生命周期“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-12.1-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "12.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle discovered → validated → prioritized → assigned → fixed/mitigated/excepted → deployed → retested → closed/reopened.",
          "zh": "对生命周期“发现 → 验证 → 定级 → 分派 → 修复/缓解/例外 → 部署 → 复测 → 关闭/重开”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-12.1-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "12.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 1.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 1.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-12.1-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "12.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-12.1-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "12.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-12.1-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "12.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-12.1-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "12.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile device and cloud inventories, controllers, configuration backups, IaC, diagrams, routing and firewall state, AAA, VPN, flow data, and change records and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 设备与云清单、控制器、配置备份、IaC、架构图、路由与防火墙状态、AAA、VPN、流量数据和变更记录，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-12.1-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "12.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Require every connector carrying intended connectivity, trust zone, route, protocol, identity, management path, traffic decision, and observed outcome to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 预期连接、信任区、路由、协议、身份、管理路径、流量决策和观察结果 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-12.1-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "12.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Require every connector carrying affected artifact identity, exploitability, business consequence, remediation choice, deployed fix, compensating control, and residual exposure to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 受影响制品身份、可利用性、业务后果、修复选择、已部署修复、补偿控制和残余暴露 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-12.1-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "12.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Review versions at least monthly, subscribe to vendor security/lifecycle notices, qualify stable targets, stage and roll out with redundant paths and rollback, and replace unsupported products.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“至少每月查版本，订阅厂商安全/生命周期通知，验证稳定目标，带冗余路径和回滚分批升级，并替换不受支持产品；托管服务记录发布证据和租户仍需动作。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-12.1-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "12.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-12.1-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "12.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-12.1-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "12.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-12.1-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "12.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the network inventory, architecture, configuration, and policy authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在网络清单、架构、配置与策略权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-12.1-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "12.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Implement the explicit state machine requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-12.1-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "12.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Implement the explicit state machine discovered → validated → prioritized → assigned → fixed/mitigated/excepted → deployed → retested → closed/reopened; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“发现 → 验证 → 定级 → 分派 → 修复/缓解/例外 → 部署 → 复测 → 关闭/重开”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-12.1-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "12.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (monthly); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（monthly）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-12.1-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "12.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-12.1-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "12.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-12.1-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "12.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-12.1-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "12.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in network devices, virtual and cloud networking, topology, trust zones, routes, management planes, remote access, AAA, and administrative workstations; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 网络设备、虚拟与云网络、拓扑、信任区、路由、管理平面、远程访问、AAA 和管理工作站 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-12.1-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "12.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; alert before each deadline becomes overdue.",
          "zh": "为“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-12.1-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "12.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for discovered → validated → prioritized → assigned → fixed/mitigated/excepted → deployed → retested → closed/reopened; alert before each deadline becomes overdue.",
          "zh": "为“发现 → 验证 → 定级 → 分派 → 修复/缓解/例外 → 部署 → 复测 → 关闭/重开”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-12.1-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "12.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “A newer release can introduce severe defects, so controlled deferral is valid with evidence and deadline.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“新版本也会有严重缺陷，有证据与截止日的受控延期可合理。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-12.1-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "12.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-12.1-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "12.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-12.1-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "12.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-12.1-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "12.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat shadow links, overlapping address space, overlays, provider abstractions, unsupported protocols, emergency consoles, remote devices, stale diagrams, and asymmetric routes as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 影子链路、重叠地址、覆盖网络、提供商抽象、不支持协议、紧急控制台、远程设备、陈旧架构图和非对称路由 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-12.1-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "12.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Treat IPv6, overlays, east-west paths, remote and roaming devices, direct egress, alternate resolvers, QUIC, asymmetric routes, provider abstraction, and emergency consoles as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 IPv6、覆盖网络、东西向路径、远程与漫游设备、直接出口、替代解析器、QUIC、非对称路由、提供商抽象和紧急控制台 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-12.1-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "12.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Treat unknown versions, false positives, unavailable fixes, vendor lag, ephemeral workloads, unscannable platforms, inherited dependencies, mitigation-only states, and recurrence as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 未知版本、误报、无可用修复、厂商滞后、短生工作负载、不可扫描平台、继承依赖、仅缓解状态和复发 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-12.1-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "12.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Reconcile every network asset/control plane to current and supported authoritative versions, sample running state, and deploy a lab/canary update including failover/rollback.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“把每个网络资产/控制面与权威当前/支持版本对账，抽查运行状态，并在实验室/金丝雀部署含故障转移/回滚的更新；不支持、易受害、延期、不可达和服务商不透明分别报告。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-12.1-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "12.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-12.1-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "12.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 6 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、6 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-12.1-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "12.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-12.1-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "12.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the network inventory, architecture, configuration, and policy authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以网络清单、架构、配置与策略权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-12.1-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "12.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Publish known, unknown, allowed, denied, shadow, bypassed, asymmetric, stale-rule, exception, and unobserved paths with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已知、未知、允许、拒绝、影子、绕过、非对称、陈旧规则、例外和未观测路径，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-12.1-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "12.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Publish open, validated, false-positive, overdue, mitigated, excepted, deployed-unverified, retest-failed, reopened, and exposure-weighted findings with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 开放、已验证、误报、逾期、已缓解、例外、已部署未验证、复测失败、重开和暴露加权发现，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-12.1-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "12.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-12.1-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "12.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-12.1-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "12.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-12.1-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "12.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-12.1-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "12.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the network inventory, architecture, configuration, and policy authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护网络清单、架构、配置与策略权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-12.1-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "12.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Restrict authority to change requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-12.1-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "12.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Restrict authority to change discovered → validated → prioritized → assigned → fixed/mitigated/excepted → deployed → retested → closed/reopened; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“发现 → 验证 → 定级 → 分派 → 修复/缓解/例外 → 部署 → 复测 → 关闭/重开”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-12.1-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "12.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-12.1-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "12.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-12.1-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "12.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-12.1-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "12.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-12.1-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "12.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise approved and rogue paths, management protocol downgrade, AAA loss, VPN split paths, route and firewall rollback, provider change, and dedicated admin workstation compromise through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 获批与异常路径、管理协议降级、AAA 丢失、VPN 分流、路由与防火墙回滚、提供商变化和专用管理工作站失陷，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-12.1-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "12.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Run the positive control an approved flow over the required secure management or business path; exercise negative, stale, duplicate, bypass, and outage controls including an unapproved route, protocol downgrade, direct egress, alternate DNS/QUIC path, segmentation bypass, AAA loss, stale rule, and rollback failure.",
          "zh": "运行正向控制“通过规定安全管理或业务路径的一项获批流量”，并执行包含“未批准路由、协议降级、直接出口、替代 DNS/QUIC 路径、分段绕过、AAA 丢失、陈旧规则和回滚失败”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-12.1-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "12.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Run the positive control a known vulnerable artifact repaired and independently retested; exercise negative, stale, duplicate, bypass, and outage controls including credential failure, wrong version match, unavailable fix, mitigation bypass, failed deployment, rollback, recurring finding, and exposed unowned asset.",
          "zh": "运行正向控制“一项已知漏洞制品完成修复并独立复测”，并执行包含“凭据失败、版本误配、无可用修复、缓解绕过、部署失败、回滚、问题复发和外露无主资产”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-12.1-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "12.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-12.1-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "12.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-12.1-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "12.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-12.1-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "12.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-12.1-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "12.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever device and cloud inventories, controllers, configuration backups, IaC, diagrams, routing and firewall state, AAA, VPN, flow data, and change records change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 设备与云清单、控制器、配置备份、IaC、架构图、路由与防火墙状态、AAA、VPN、流量数据和变更记录 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-12.1-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "12.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Use known, unknown, allowed, denied, shadow, bypassed, asymmetric, stale-rule, exception, and unobserved paths to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已知、未知、允许、拒绝、影子、绕过、非对称、陈旧规则、例外和未观测路径 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-12.1-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "12.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Use open, validated, false-positive, overdue, mitigated, excepted, deployed-unverified, retest-failed, reopened, and exposure-weighted findings to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 开放、已验证、误报、逾期、已缓解、例外、已部署未验证、复测失败、重开和暴露加权发现 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "12.2",
      "control": 12,
      "title_en": "Establish and Maintain a Secure Network Architecture",
      "title_zh": "安全网络架构",
      "first_ig": 2,
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Network",
      "security_function": "Protect",
      "patterns": [
        "network",
        "governance"
      ],
      "expanded_complexity": true,
      "cas_context": {
        "dependencies": [
          "2.1",
          "12.4"
        ],
        "variables": [
          "GV4",
          "GV5",
          "GV36",
          "M1",
          "M2",
          "M3",
          "M4",
          "M5"
        ],
        "metric_branches": 3,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "The architecture covers segmentation, least privilege and availability across user, server, management, cloud, remote, partner, OT/IoT, Internet and service/control planes.",
          "build": "Derive zones and allowed flows from services/data, minimize transitive reachability, separate management, add resilient paths and capacity, and enforce through firewalls, security groups, proxies, identity-aware gateways and routing.",
          "proof": "Test allowed business flows and denied lateral/management paths from representative identities/assets, then fail a link/control component and observe availability and policy consistency.",
          "boundary": "The CAS segment test says one segment both fails and passes due overlapping conditions and treats an unauthorized device as the sole least-privilege test."
        },
        "zh": {
          "scope": "覆盖用户、服务器、管理、云、远程、伙伴、OT/IoT、互联网和服务/控制面，至少处理分段、最小权限与可用性。",
          "build": "从服务和数据流推导区域与允许流，减少传递可达，隔离管理面，增加冗余/容量；用防火墙、安全组、代理、身份网关和路由执行，并通过变更控制和威胁场景审查设计/实效。",
          "proof": "从代表身份/资产测试允许业务流和拒绝横向/管理路径，再故障链路/控制组件观察可用与政策一致；计算有效可达与批准流的偏差，发现未记录路径。",
          "boundary": "CAS 在一个 Segment 时既写 Fail 又写 Pass，并用“未授权设备能否接入”代替全部最小权限。"
        }
      },
      "category_counts": {
        "outcome": 8,
        "scope": 8,
        "ownership": 8,
        "data": 8,
        "integration": 8,
        "control": 8,
        "timing": 8,
        "exception": 8,
        "evidence": 8,
        "security": 8,
        "testing": 8,
        "operations": 8
      },
      "requirement_count": 96,
      "requirements": [
        {
          "code": "CIS-12.2-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "12.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Establish and Maintain a Secure Network Architecture; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“安全网络架构”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-12.2-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "12.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 12.2, official Asset Class Network, Security Function Protect, and IG2 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 12.2、官方资产类别“网络”、安全功能“保护”和首次出现的 IG2，并保存来源抓取日期。"
        },
        {
          "code": "CIS-12.2-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "12.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “The architecture covers segmentation, least privilege and availability across user, server, management, cloud, remote, partner, OT/IoT, Internet and service/control planes.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“覆盖用户、服务器、管理、云、远程、伙伴、OT/IoT、互联网和服务/控制面，至少处理分段、最小权限与可用性。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-12.2-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "12.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-12.2-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "12.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Establish and Maintain a Secure Network Architecture to its operating object—network devices, virtual and cloud networking, topology, trust zones, routes, management planes, remote access, AAA, and administrative workstations—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“安全网络架构”连接到其运营对象——网络设备、虚拟与云网络、拓扑、信任区、路由、管理平面、远程访问、AAA 和管理工作站——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-12.2-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "12.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "For Establish and Maintain a Secure Network Architecture, express success as an observable decision over intended connectivity, trust zone, route, protocol, identity, management path, traffic decision, and observed outcome; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“安全网络架构”，以 预期连接、信任区、路由、协议、身份、管理路径、流量决策和观察结果 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-12.2-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "12.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "For Establish and Maintain a Secure Network Architecture, express success as an observable decision over a documented decision system with policy, process, procedure, accountable owner, approval, and review; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“安全网络架构”，以 包含策略、流程、程序、责任人、审批和复核的文档化决策系统 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-12.2-OUT-08",
          "local_code": "OUT-08",
          "display_code": "O08",
          "safeguard_id": "12.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "For the expanded Establish and Maintain a Secure Network Architecture scope, resolve conflicts among security, safety, privacy, legal, availability, customer, and operational objectives through an explicit risk decision.",
          "zh": "对“安全网络架构”的扩展范围，通过显式风险决策解决安全、安全生产、隐私、法律、可用性、客户和运营目标冲突。"
        },
        {
          "code": "CIS-12.2-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "12.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-12.2-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "12.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-12.2-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "12.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-12.2-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "12.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-12.2-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "12.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across shadow links, overlapping address space, overlays, provider abstractions, unsupported protocols, emergency consoles, remote devices, stale diagrams, and asymmetric routes; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 影子链路、重叠地址、覆盖网络、提供商抽象、不支持协议、紧急控制台、远程设备、陈旧架构图和非对称路由 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-12.2-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "12.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Include IPv6, overlays, east-west paths, remote and roaming devices, direct egress, alternate resolvers, QUIC, asymmetric routes, provider abstraction, and emergency consoles in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 IPv6、覆盖网络、东西向路径、远程与漫游设备、直接出口、替代解析器、QUIC、非对称路由、提供商抽象和紧急控制台 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-12.2-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "12.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Include missing policy clauses, conflicting authorities, local deviations, obsolete documentation, and decisions made outside the governed workflow in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 策略条款缺失、权限冲突、本地偏离、文档过期及绕过治理流程的决策 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-12.2-SCP-08",
          "local_code": "SCP-08",
          "display_code": "P08",
          "safeguard_id": "12.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Define nested scope at enterprise, business service, tenant, environment, platform, object, identity, data set, and transaction levels; prohibit a parent result from hiding a failing child.",
          "zh": "按企业、业务服务、租户、环境、平台、对象、身份、数据集和交易定义嵌套范围，禁止父级结果遮蔽失败子级。"
        },
        {
          "code": "CIS-12.2-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "12.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-12.2-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "12.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-12.2-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "12.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-12.2-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "12.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-12.2-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "12.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind network and cloud engineering, security architecture, identity, service owners, operations, and change management to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 网络与云工程、安全架构、身份、服务责任人、运营和变更管理 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-12.2-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "12.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Name who may transition requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-12.2-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "12.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Name who may transition draft → reviewed → approved → effective → exception/withdrawn → superseded, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-12.2-OWN-08",
          "local_code": "OWN-08",
          "display_code": "W08",
          "safeguard_id": "12.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Model delegated authority, quorum or dual approval where warranted, escalation deadlines, provider handoffs, conflict resolution, and executive risk acceptance.",
          "zh": "建模委派权限、必要时的双人或法定人数审批、升级期限、提供商交接、冲突解决和管理层风险接受。"
        },
        {
          "code": "CIS-12.2-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "12.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-12.2-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "12.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-12.2-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "12.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV4, GV5, GV36, M1, M2, M3, M4, M5) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV4, GV5, GV36, M1, M2, M3, M4, M5）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-12.2-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "12.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-12.2-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "12.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the network inventory, architecture, configuration, and policy authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把网络清单、架构、配置与策略权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-12.2-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "12.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired.",
          "zh": "对生命周期“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-12.2-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "12.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle draft → reviewed → approved → effective → exception/withdrawn → superseded.",
          "zh": "对生命周期“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-12.2-DAT-08",
          "local_code": "DAT-08",
          "display_code": "D08",
          "safeguard_id": "12.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Version schemas and state transitions with migration, backfill, deduplication, lineage, historical denominator, deletion, and rollback semantics.",
          "zh": "对模式和状态转换做版本管理，定义迁移、回填、去重、血缘、历史分母、删除和回滚语义。"
        },
        {
          "code": "CIS-12.2-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "12.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 2.1, Safeguard 12.4; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 2.1、Safeguard 12.4 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-12.2-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "12.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-12.2-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "12.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-12.2-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "12.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-12.2-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "12.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile device and cloud inventories, controllers, configuration backups, IaC, diagrams, routing and firewall state, AAA, VPN, flow data, and change records and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 设备与云清单、控制器、配置备份、IaC、架构图、路由与防火墙状态、AAA、VPN、流量数据和变更记录，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-12.2-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "12.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Require every connector carrying intended connectivity, trust zone, route, protocol, identity, management path, traffic decision, and observed outcome to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 预期连接、信任区、路由、协议、身份、管理路径、流量决策和观察结果 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-12.2-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "12.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Require every connector carrying a documented decision system with policy, process, procedure, accountable owner, approval, and review to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 包含策略、流程、程序、责任人、审批和复核的文档化决策系统 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-12.2-INT-08",
          "local_code": "INT-08",
          "display_code": "I08",
          "safeguard_id": "12.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Define consistency rules across disagreeing sources, source precedence, confidence, reconciliation queues, dead-letter handling, reprocessing, and end-to-end trace identity.",
          "zh": "定义冲突来源的一致性、优先级、置信度、对账队列、死信、重处理和端到端追踪身份。"
        },
        {
          "code": "CIS-12.2-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "12.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Derive zones and allowed flows from services/data, minimize transitive reachability, separate management, add resilient paths and capacity, and enforce through firewalls, security groups, proxies, identity-aware gateways and routing.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“从服务和数据流推导区域与允许流，减少传递可达，隔离管理面，增加冗余/容量；用防火墙、安全组、代理、身份网关和路由执行，并通过变更控制和威胁场景审查设计/实效。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-12.2-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "12.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-12.2-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "12.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-12.2-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "12.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-12.2-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "12.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the network inventory, architecture, configuration, and policy authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在网络清单、架构、配置与策略权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-12.2-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "12.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Implement the explicit state machine requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-12.2-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "12.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Implement the explicit state machine draft → reviewed → approved → effective → exception/withdrawn → superseded; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-12.2-CTL-08",
          "local_code": "CTL-08",
          "display_code": "C08",
          "safeguard_id": "12.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Specify concurrent decisions, partial success, compensating transactions, repeated requests, stale policy, dependency outage, and recovery from an interrupted state transition.",
          "zh": "定义并发决策、部分成功、补偿事务、重复请求、陈旧策略、依赖中断和中途状态转换恢复。"
        },
        {
          "code": "CIS-12.2-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "12.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-12.2-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "12.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-12.2-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "12.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-12.2-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "12.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-12.2-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "12.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in network devices, virtual and cloud networking, topology, trust zones, routes, management planes, remote access, AAA, and administrative workstations; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 网络设备、虚拟与云网络、拓扑、信任区、路由、管理平面、远程访问、AAA 和管理工作站 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-12.2-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "12.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; alert before each deadline becomes overdue.",
          "zh": "为“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-12.2-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "12.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for draft → reviewed → approved → effective → exception/withdrawn → superseded; alert before each deadline becomes overdue.",
          "zh": "为“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-12.2-TIM-08",
          "local_code": "TIM-08",
          "display_code": "T08",
          "safeguard_id": "12.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Allocate an end-to-end SLO budget across discovery, collection, processing, approval, enforcement, verification, and closure; prioritize overdue work by consequence and exposure.",
          "zh": "把端到端 SLO 预算分配到发现、采集、处理、审批、执行、验证和关闭，并按后果与暴露排列逾期工作。"
        },
        {
          "code": "CIS-12.2-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "12.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “The CAS segment test says one segment both fails and passes due overlapping conditions and treats an unauthorized device as the sole least-privilege test.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“CAS 在一个 Segment 时既写 Fail 又写 Pass，并用“未授权设备能否接入”代替全部最小权限。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-12.2-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "12.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-12.2-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "12.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-12.2-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "12.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-12.2-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "12.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat shadow links, overlapping address space, overlays, provider abstractions, unsupported protocols, emergency consoles, remote devices, stale diagrams, and asymmetric routes as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 影子链路、重叠地址、覆盖网络、提供商抽象、不支持协议、紧急控制台、远程设备、陈旧架构图和非对称路由 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-12.2-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "12.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Treat IPv6, overlays, east-west paths, remote and roaming devices, direct egress, alternate resolvers, QUIC, asymmetric routes, provider abstraction, and emergency consoles as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 IPv6、覆盖网络、东西向路径、远程与漫游设备、直接出口、替代解析器、QUIC、非对称路由、提供商抽象和紧急控制台 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-12.2-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "12.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Treat missing policy clauses, conflicting authorities, local deviations, obsolete documentation, and decisions made outside the governed workflow as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 策略条款缺失、权限冲突、本地偏离、文档过期及绕过治理流程的决策 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-12.2-EXC-08",
          "local_code": "EXC-08",
          "display_code": "X08",
          "safeguard_id": "12.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Exercise compound failures where an exception, stale source, provider outage, unavailable owner, and degraded control overlap; define one safe command and one accountable decision.",
          "zh": "演练例外、陈旧来源、提供商中断、责任人不可用和控制降级同时出现的复合故障，明确一条安全指令和一个责任决策。"
        },
        {
          "code": "CIS-12.2-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "12.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Test allowed business flows and denied lateral/management paths from representative identities/assets, then fail a link/control component and observe availability and policy consistency.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“从代表身份/资产测试允许业务流和拒绝横向/管理路径，再故障链路/控制组件观察可用与政策一致；计算有效可达与批准流的偏差，发现未记录路径。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-12.2-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "12.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-12.2-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "12.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 3 pinned CAS metric branch(es), 8 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 3 个指标分支、8 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-12.2-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "12.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-12.2-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "12.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the network inventory, architecture, configuration, and policy authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以网络清单、架构、配置与策略权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-12.2-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "12.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Publish known, unknown, allowed, denied, shadow, bypassed, asymmetric, stale-rule, exception, and unobserved paths with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已知、未知、允许、拒绝、影子、绕过、非对称、陈旧规则、例外和未观测路径，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-12.2-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "12.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Publish clause coverage, owner and reviewer completeness, approval age, triggered reviews, deviations, overdue actions, and superseded versions still in use with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 条款覆盖、责任人与复核人完整性、批准年龄、触发式复核、偏离、逾期行动及仍在使用的旧版本，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-12.2-EVD-08",
          "local_code": "EVD-08",
          "display_code": "E08",
          "safeguard_id": "12.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Require an independent party to reconstruct the decision from source receipts and reproduce the population, state transition, calculation, test result, exception, and final closure.",
          "zh": "要求独立人员使用来源回执重建决策，并复现总体、状态转换、计算、测试结果、例外和最终关闭。"
        },
        {
          "code": "CIS-12.2-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "12.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-12.2-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "12.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-12.2-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "12.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-12.2-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "12.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-12.2-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "12.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the network inventory, architecture, configuration, and policy authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护网络清单、架构、配置与策略权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-12.2-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "12.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Restrict authority to change requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-12.2-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "12.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Restrict authority to change draft → reviewed → approved → effective → exception/withdrawn → superseded; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-12.2-SEC-08",
          "local_code": "SEC-08",
          "display_code": "S08",
          "safeguard_id": "12.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Threat-model the implementation system itself: forged evidence, poisoned inventory, privilege abuse, cross-tenant confusion, policy rollback, audit deletion, denial of service, and recovery compromise.",
          "zh": "威胁建模实施系统自身：伪造证据、污染清单、权限滥用、跨租户混淆、策略回滚、审计删除、拒绝服务和恢复失陷。"
        },
        {
          "code": "CIS-12.2-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "12.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-12.2-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "12.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-12.2-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "12.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-12.2-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "12.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-12.2-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "12.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise approved and rogue paths, management protocol downgrade, AAA loss, VPN split paths, route and firewall rollback, provider change, and dedicated admin workstation compromise through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 获批与异常路径、管理协议降级、AAA 丢失、VPN 分流、路由与防火墙回滚、提供商变化和专用管理工作站失陷，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-12.2-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "12.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Run the positive control an approved flow over the required secure management or business path; exercise negative, stale, duplicate, bypass, and outage controls including an unapproved route, protocol downgrade, direct egress, alternate DNS/QUIC path, segmentation bypass, AAA loss, stale rule, and rollback failure.",
          "zh": "运行正向控制“通过规定安全管理或业务路径的一项获批流量”，并执行包含“未批准路由、协议降级、直接出口、替代 DNS/QUIC 路径、分段绕过、AAA 丢失、陈旧规则和回滚失败”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-12.2-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "12.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Run the positive control an approved current process used for a representative decision; exercise negative, stale, duplicate, bypass, and outage controls including an obsolete version, missing approver, undocumented deviation, overdue review, and bypassed workflow.",
          "zh": "运行正向控制“使用当前获批流程完成一项代表性决策”，并执行包含“旧版本、审批人缺失、未记录偏离、逾期复核和绕过流程”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-12.2-TST-08",
          "local_code": "TST-08",
          "display_code": "V08",
          "safeguard_id": "12.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Build a pairwise platform-and-failure matrix, then add high-consequence multi-factor cases, historical regression, source substitution, red-team challenge, and assessor replay.",
          "zh": "建立平台—故障两两组合矩阵，再加入高后果多因素案例、历史回归、来源替换、红队挑战和评估方重放。"
        },
        {
          "code": "CIS-12.2-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "12.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-12.2-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "12.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-12.2-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "12.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-12.2-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "12.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-12.2-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "12.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever device and cloud inventories, controllers, configuration backups, IaC, diagrams, routing and firewall state, AAA, VPN, flow data, and change records change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 设备与云清单、控制器、配置备份、IaC、架构图、路由与防火墙状态、AAA、VPN、流量数据和变更记录 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-12.2-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "12.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Use known, unknown, allowed, denied, shadow, bypassed, asymmetric, stale-rule, exception, and unobserved paths to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已知、未知、允许、拒绝、影子、绕过、非对称、陈旧规则、例外和未观测路径 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-12.2-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "12.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Use clause coverage, owner and reviewer completeness, approval age, triggered reviews, deviations, overdue actions, and superseded versions still in use to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 条款覆盖、责任人与复核人完整性、批准年龄、触发式复核、偏离、逾期行动及仍在使用的旧版本 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-12.2-OPS-08",
          "local_code": "OPS-08",
          "display_code": "R08",
          "safeguard_id": "12.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Use canary deployment, kill criteria, rollback, backlog burn-down, exception reduction, source-quality targets, quarterly design review, and a measurable retirement plan.",
          "zh": "采用金丝雀、停止标准、回滚、积压燃尽、例外缩减、来源质量目标、季度设计复核和可量化退役计划。"
        }
      ]
    },
    {
      "id": "12.3",
      "control": 12,
      "title_en": "Securely Manage Network Infrastructure",
      "title_zh": "安全管理网络基础设施",
      "first_ig": 2,
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Network",
      "security_function": "Protect",
      "patterns": [
        "network"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "1.1",
          "4.2",
          "12.4"
        ],
        "variables": [
          "GV35",
          "GV36",
          "GV37",
          "M1",
          "M2",
          "M3",
          "M4",
          "M5",
          "M6",
          "M7",
          "M8"
        ],
        "metric_branches": 2,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "Management includes interactive, API and automated changes to all network devices and cloud/service controls, from administrator workstation through bastion/controller to target.",
          "build": "Use dedicated management networks/resources, central AAA/MFA, encrypted protocols, version-controlled templates/IaC, reviewed deployment and protected out-of-band recovery.",
          "proof": "Attempt management from production/user networks, direct target paths, old credentials and insecure protocols; trace an approved change from commit to effective config, drift detection and rollback.",
          "boundary": "IaC coverage by “network segment,” as CAS measures, leaves device and cloud-policy coverage unresolved."
        },
        "zh": {
          "scope": "包括管理员工作站经跳板/控制器到网络设备与云/服务控制面的交互、API 和自动变更；覆盖协议、身份、可达、配置来源、秘密、备份和应急 Console。",
          "build": "使用专用管理网/资源、中央 AAA/MFA、加密协议、版本化模板/IaC、评审部署和受保护带外恢复；关闭公网与不安全接口，轮换密钥，收窄 API Scope，记录命令/配置变化。",
          "proof": "从生产/用户网、直连目标、旧凭据和不安全协议尝试管理；从提交追批准变更到有效配置、漂移和回滚，并抽查 Console/服务商支持，不能只看 SSH/HTTPS。",
          "boundary": "CAS 以“网段使用 IaC”计覆盖，不能证明全部设备或云策略受管。"
        }
      },
      "category_counts": {
        "outcome": 6,
        "scope": 6,
        "ownership": 6,
        "data": 6,
        "integration": 6,
        "control": 6,
        "timing": 6,
        "exception": 6,
        "evidence": 6,
        "security": 6,
        "testing": 6,
        "operations": 6
      },
      "requirement_count": 72,
      "requirements": [
        {
          "code": "CIS-12.3-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "12.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Securely Manage Network Infrastructure; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“安全管理网络基础设施”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-12.3-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "12.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 12.3, official Asset Class Network, Security Function Protect, and IG2 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 12.3、官方资产类别“网络”、安全功能“保护”和首次出现的 IG2，并保存来源抓取日期。"
        },
        {
          "code": "CIS-12.3-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "12.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Management includes interactive, API and automated changes to all network devices and cloud/service controls, from administrator workstation through bastion/controller to target.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“包括管理员工作站经跳板/控制器到网络设备与云/服务控制面的交互、API 和自动变更；覆盖协议、身份、可达、配置来源、秘密、备份和应急 Console。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-12.3-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "12.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-12.3-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "12.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Securely Manage Network Infrastructure to its operating object—network devices, virtual and cloud networking, topology, trust zones, routes, management planes, remote access, AAA, and administrative workstations—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“安全管理网络基础设施”连接到其运营对象——网络设备、虚拟与云网络、拓扑、信任区、路由、管理平面、远程访问、AAA 和管理工作站——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-12.3-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "12.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "For Securely Manage Network Infrastructure, express success as an observable decision over intended connectivity, trust zone, route, protocol, identity, management path, traffic decision, and observed outcome; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“安全管理网络基础设施”，以 预期连接、信任区、路由、协议、身份、管理路径、流量决策和观察结果 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-12.3-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "12.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-12.3-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "12.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-12.3-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "12.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-12.3-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "12.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-12.3-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "12.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across shadow links, overlapping address space, overlays, provider abstractions, unsupported protocols, emergency consoles, remote devices, stale diagrams, and asymmetric routes; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 影子链路、重叠地址、覆盖网络、提供商抽象、不支持协议、紧急控制台、远程设备、陈旧架构图和非对称路由 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-12.3-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "12.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Include IPv6, overlays, east-west paths, remote and roaming devices, direct egress, alternate resolvers, QUIC, asymmetric routes, provider abstraction, and emergency consoles in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 IPv6、覆盖网络、东西向路径、远程与漫游设备、直接出口、替代解析器、QUIC、非对称路由、提供商抽象和紧急控制台 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-12.3-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "12.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-12.3-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "12.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-12.3-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "12.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-12.3-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "12.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-12.3-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "12.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind network and cloud engineering, security architecture, identity, service owners, operations, and change management to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 网络与云工程、安全架构、身份、服务责任人、运营和变更管理 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-12.3-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "12.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Name who may transition requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-12.3-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "12.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-12.3-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "12.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-12.3-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "12.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV35, GV36, GV37, M1, M2, M3, M4, M5, M6, M7, M8) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV35, GV36, GV37, M1, M2, M3, M4, M5, M6, M7, M8）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-12.3-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "12.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-12.3-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "12.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the network inventory, architecture, configuration, and policy authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把网络清单、架构、配置与策略权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-12.3-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "12.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired.",
          "zh": "对生命周期“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-12.3-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "12.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 1.1, Safeguard 4.2, Safeguard 12.4; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 1.1、Safeguard 4.2、Safeguard 12.4 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-12.3-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "12.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-12.3-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "12.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-12.3-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "12.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-12.3-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "12.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile device and cloud inventories, controllers, configuration backups, IaC, diagrams, routing and firewall state, AAA, VPN, flow data, and change records and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 设备与云清单、控制器、配置备份、IaC、架构图、路由与防火墙状态、AAA、VPN、流量数据和变更记录，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-12.3-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "12.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Require every connector carrying intended connectivity, trust zone, route, protocol, identity, management path, traffic decision, and observed outcome to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 预期连接、信任区、路由、协议、身份、管理路径、流量决策和观察结果 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-12.3-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "12.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Use dedicated management networks/resources, central AAA/MFA, encrypted protocols, version-controlled templates/IaC, reviewed deployment and protected out-of-band recovery.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“使用专用管理网/资源、中央 AAA/MFA、加密协议、版本化模板/IaC、评审部署和受保护带外恢复；关闭公网与不安全接口，轮换密钥，收窄 API Scope，记录命令/配置变化。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-12.3-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "12.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-12.3-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "12.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-12.3-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "12.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-12.3-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "12.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the network inventory, architecture, configuration, and policy authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在网络清单、架构、配置与策略权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-12.3-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "12.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Implement the explicit state machine requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-12.3-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "12.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-12.3-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "12.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-12.3-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "12.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-12.3-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "12.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-12.3-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "12.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in network devices, virtual and cloud networking, topology, trust zones, routes, management planes, remote access, AAA, and administrative workstations; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 网络设备、虚拟与云网络、拓扑、信任区、路由、管理平面、远程访问、AAA 和管理工作站 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-12.3-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "12.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; alert before each deadline becomes overdue.",
          "zh": "为“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-12.3-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "12.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “IaC coverage by “network segment,” as CAS measures, leaves device and cloud-policy coverage unresolved.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“CAS 以“网段使用 IaC”计覆盖，不能证明全部设备或云策略受管。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-12.3-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "12.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-12.3-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "12.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-12.3-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "12.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-12.3-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "12.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat shadow links, overlapping address space, overlays, provider abstractions, unsupported protocols, emergency consoles, remote devices, stale diagrams, and asymmetric routes as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 影子链路、重叠地址、覆盖网络、提供商抽象、不支持协议、紧急控制台、远程设备、陈旧架构图和非对称路由 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-12.3-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "12.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Treat IPv6, overlays, east-west paths, remote and roaming devices, direct egress, alternate resolvers, QUIC, asymmetric routes, provider abstraction, and emergency consoles as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 IPv6、覆盖网络、东西向路径、远程与漫游设备、直接出口、替代解析器、QUIC、非对称路由、提供商抽象和紧急控制台 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-12.3-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "12.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Attempt management from production/user networks, direct target paths, old credentials and insecure protocols; trace an approved change from commit to effective config, drift detection and rollback.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“从生产/用户网、直连目标、旧凭据和不安全协议尝试管理；从提交追批准变更到有效配置、漂移和回滚，并抽查 Console/服务商支持，不能只看 SSH/HTTPS。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-12.3-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "12.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-12.3-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "12.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 2 pinned CAS metric branch(es), 11 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 2 个指标分支、11 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-12.3-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "12.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-12.3-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "12.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the network inventory, architecture, configuration, and policy authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以网络清单、架构、配置与策略权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-12.3-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "12.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Publish known, unknown, allowed, denied, shadow, bypassed, asymmetric, stale-rule, exception, and unobserved paths with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已知、未知、允许、拒绝、影子、绕过、非对称、陈旧规则、例外和未观测路径，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-12.3-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "12.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-12.3-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "12.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-12.3-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "12.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-12.3-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "12.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-12.3-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "12.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the network inventory, architecture, configuration, and policy authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护网络清单、架构、配置与策略权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-12.3-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "12.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Restrict authority to change requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-12.3-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "12.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-12.3-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "12.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-12.3-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "12.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-12.3-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "12.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-12.3-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "12.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise approved and rogue paths, management protocol downgrade, AAA loss, VPN split paths, route and firewall rollback, provider change, and dedicated admin workstation compromise through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 获批与异常路径、管理协议降级、AAA 丢失、VPN 分流、路由与防火墙回滚、提供商变化和专用管理工作站失陷，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-12.3-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "12.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Run the positive control an approved flow over the required secure management or business path; exercise negative, stale, duplicate, bypass, and outage controls including an unapproved route, protocol downgrade, direct egress, alternate DNS/QUIC path, segmentation bypass, AAA loss, stale rule, and rollback failure.",
          "zh": "运行正向控制“通过规定安全管理或业务路径的一项获批流量”，并执行包含“未批准路由、协议降级、直接出口、替代 DNS/QUIC 路径、分段绕过、AAA 丢失、陈旧规则和回滚失败”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-12.3-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "12.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-12.3-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "12.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-12.3-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "12.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-12.3-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "12.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-12.3-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "12.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever device and cloud inventories, controllers, configuration backups, IaC, diagrams, routing and firewall state, AAA, VPN, flow data, and change records change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 设备与云清单、控制器、配置备份、IaC、架构图、路由与防火墙状态、AAA、VPN、流量数据和变更记录 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-12.3-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "12.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Use known, unknown, allowed, denied, shadow, bypassed, asymmetric, stale-rule, exception, and unobserved paths to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已知、未知、允许、拒绝、影子、绕过、非对称、陈旧规则、例外和未观测路径 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "12.4",
      "control": 12,
      "title_en": "Establish and Maintain Architecture Diagram(s)",
      "title_zh": "架构图与网络文档",
      "first_ig": 2,
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Documentation",
      "security_function": "Govern",
      "patterns": [
        "network",
        "inventory",
        "governance"
      ],
      "expanded_complexity": true,
      "cas_context": {
        "dependencies": [],
        "variables": [
          "GV4",
          "M1",
          "M2"
        ],
        "metric_branches": 0,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [
        "annually"
      ],
      "implementation_contract": {
        "en": {
          "scope": "Documentation includes current trust zones, networks, routes, boundaries, external/provider links, Internet exposure, management/control planes, critical services, data flows and security enforcement points across on-premises and cloud.",
          "build": "Generate from authoritative inventories/IaC where possible, add business/trust meaning and owners, version changes and review annually plus on material changes.",
          "proof": "Select routes, cloud controls and services from live state and trace them onto diagrams, then select documented paths and verify reality.",
          "boundary": "Represent dynamic and autoscaled resources by pattern and control plane; enumerating every pod creates immediate staleness."
        },
        "zh": {
          "scope": "文档包含现行信任区、网络、路由、边界、外部/服务商链路、互联网暴露、管理/控制面、关键服务、数据流和强制点，横跨本地与云。",
          "build": "能从权威台账/IaC 生成的先生成，再补业务/信任含义和责任人；版本化变更，每年及重大变化时更新。",
          "proof": "从实时路由、云控制和服务抽样回图，再从图抽样回现实；引入测试变更走批准流程，记录未知链路、陈旧对象和责任缺口。",
          "boundary": "动态/自动扩容资源用模式与控制面表达，不必画每个 Pod。"
        }
      },
      "category_counts": {
        "outcome": 9,
        "scope": 9,
        "ownership": 9,
        "data": 9,
        "integration": 9,
        "control": 9,
        "timing": 9,
        "exception": 9,
        "evidence": 9,
        "security": 9,
        "testing": 9,
        "operations": 9
      },
      "requirement_count": 108,
      "requirements": [
        {
          "code": "CIS-12.4-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "12.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Establish and Maintain Architecture Diagram(s); name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“架构图与网络文档”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-12.4-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "12.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 12.4, official Asset Class Documentation, Security Function Govern, and IG2 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 12.4、官方资产类别“文档与治理”、安全功能“治理”和首次出现的 IG2，并保存来源抓取日期。"
        },
        {
          "code": "CIS-12.4-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "12.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Documentation includes current trust zones, networks, routes, boundaries, external/provider links, Internet exposure, management/control planes, critical services, data flows and security enforcement points across on-premises and cloud.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“文档包含现行信任区、网络、路由、边界、外部/服务商链路、互联网暴露、管理/控制面、关键服务、数据流和强制点，横跨本地与云。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-12.4-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "12.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-12.4-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "12.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Establish and Maintain Architecture Diagram(s) to its operating object—network devices, virtual and cloud networking, topology, trust zones, routes, management planes, remote access, AAA, and administrative workstations—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“架构图与网络文档”连接到其运营对象——网络设备、虚拟与云网络、拓扑、信任区、路由、管理平面、远程访问、AAA 和管理工作站——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-12.4-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "12.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "For Establish and Maintain Architecture Diagram(s), express success as an observable decision over intended connectivity, trust zone, route, protocol, identity, management path, traffic decision, and observed outcome; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“架构图与网络文档”，以 预期连接、信任区、路由、协议、身份、管理路径、流量决策和观察结果 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-12.4-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "12.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "For Establish and Maintain Architecture Diagram(s), express success as an observable decision over observed, approved, unapproved, ownerless, stale, duplicate, and retired object identity; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“架构图与网络文档”，以 已观测、已批准、未批准、无责任人、陈旧、重复和已退役对象身份 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-12.4-OUT-08",
          "local_code": "OUT-08",
          "display_code": "O08",
          "safeguard_id": "12.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "For Establish and Maintain Architecture Diagram(s), express success as an observable decision over a documented decision system with policy, process, procedure, accountable owner, approval, and review; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“架构图与网络文档”，以 包含策略、流程、程序、责任人、审批和复核的文档化决策系统 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-12.4-OUT-09",
          "local_code": "OUT-09",
          "display_code": "O09",
          "safeguard_id": "12.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "For the expanded Establish and Maintain Architecture Diagram(s) scope, resolve conflicts among security, safety, privacy, legal, availability, customer, and operational objectives through an explicit risk decision.",
          "zh": "对“架构图与网络文档”的扩展范围，通过显式风险决策解决安全、安全生产、隐私、法律、可用性、客户和运营目标冲突。"
        },
        {
          "code": "CIS-12.4-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "12.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-12.4-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "12.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-12.4-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "12.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-12.4-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "12.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-12.4-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "12.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across shadow links, overlapping address space, overlays, provider abstractions, unsupported protocols, emergency consoles, remote devices, stale diagrams, and asymmetric routes; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 影子链路、重叠地址、覆盖网络、提供商抽象、不支持协议、紧急控制台、远程设备、陈旧架构图和非对称路由 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-12.4-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "12.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Include IPv6, overlays, east-west paths, remote and roaming devices, direct egress, alternate resolvers, QUIC, asymmetric routes, provider abstraction, and emergency consoles in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 IPv6、覆盖网络、东西向路径、远程与漫游设备、直接出口、替代解析器、QUIC、非对称路由、提供商抽象和紧急控制台 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-12.4-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "12.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Include dormant, ephemeral, disconnected, externally managed, provider-held, aliased, cloned, and cross-tenant objects in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 休眠、短生、离线、外部托管、提供商持有、别名、克隆和跨租户对象 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-12.4-SCP-08",
          "local_code": "SCP-08",
          "display_code": "P08",
          "safeguard_id": "12.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Include missing policy clauses, conflicting authorities, local deviations, obsolete documentation, and decisions made outside the governed workflow in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 策略条款缺失、权限冲突、本地偏离、文档过期及绕过治理流程的决策 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-12.4-SCP-09",
          "local_code": "SCP-09",
          "display_code": "P09",
          "safeguard_id": "12.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Define nested scope at enterprise, business service, tenant, environment, platform, object, identity, data set, and transaction levels; prohibit a parent result from hiding a failing child.",
          "zh": "按企业、业务服务、租户、环境、平台、对象、身份、数据集和交易定义嵌套范围，禁止父级结果遮蔽失败子级。"
        },
        {
          "code": "CIS-12.4-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "12.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-12.4-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "12.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-12.4-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "12.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-12.4-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "12.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-12.4-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "12.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind network and cloud engineering, security architecture, identity, service owners, operations, and change management to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 网络与云工程、安全架构、身份、服务责任人、运营和变更管理 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-12.4-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "12.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Name who may transition requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-12.4-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "12.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Name who may transition discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-12.4-OWN-08",
          "local_code": "OWN-08",
          "display_code": "W08",
          "safeguard_id": "12.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Name who may transition draft → reviewed → approved → effective → exception/withdrawn → superseded, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-12.4-OWN-09",
          "local_code": "OWN-09",
          "display_code": "W09",
          "safeguard_id": "12.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Model delegated authority, quorum or dual approval where warranted, escalation deadlines, provider handoffs, conflict resolution, and executive risk acceptance.",
          "zh": "建模委派权限、必要时的双人或法定人数审批、升级期限、提供商交接、冲突解决和管理层风险接受。"
        },
        {
          "code": "CIS-12.4-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "12.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-12.4-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "12.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-12.4-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "12.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV4, M1, M2) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV4, M1, M2）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-12.4-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "12.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-12.4-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "12.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the network inventory, architecture, configuration, and policy authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把网络清单、架构、配置与策略权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-12.4-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "12.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired.",
          "zh": "对生命周期“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-12.4-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "12.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence.",
          "zh": "对生命周期“发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-12.4-DAT-08",
          "local_code": "DAT-08",
          "display_code": "D08",
          "safeguard_id": "12.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle draft → reviewed → approved → effective → exception/withdrawn → superseded.",
          "zh": "对生命周期“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-12.4-DAT-09",
          "local_code": "DAT-09",
          "display_code": "D09",
          "safeguard_id": "12.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Version schemas and state transitions with migration, backfill, deduplication, lineage, historical denominator, deletion, and rollback semantics.",
          "zh": "对模式和状态转换做版本管理，定义迁移、回填、去重、血缘、历史分母、删除和回滚语义。"
        },
        {
          "code": "CIS-12.4-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "12.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for no explicit predecessor in the pinned CAS page; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 固定 CAS 页面没有列出显式前置项 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-12.4-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "12.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-12.4-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "12.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-12.4-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "12.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-12.4-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "12.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile device and cloud inventories, controllers, configuration backups, IaC, diagrams, routing and firewall state, AAA, VPN, flow data, and change records and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 设备与云清单、控制器、配置备份、IaC、架构图、路由与防火墙状态、AAA、VPN、流量数据和变更记录，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-12.4-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "12.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Require every connector carrying intended connectivity, trust zone, route, protocol, identity, management path, traffic decision, and observed outcome to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 预期连接、信任区、路由、协议、身份、管理路径、流量决策和观察结果 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-12.4-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "12.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Require every connector carrying observed, approved, unapproved, ownerless, stale, duplicate, and retired object identity to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 已观测、已批准、未批准、无责任人、陈旧、重复和已退役对象身份 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-12.4-INT-08",
          "local_code": "INT-08",
          "display_code": "I08",
          "safeguard_id": "12.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Require every connector carrying a documented decision system with policy, process, procedure, accountable owner, approval, and review to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 包含策略、流程、程序、责任人、审批和复核的文档化决策系统 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-12.4-INT-09",
          "local_code": "INT-09",
          "display_code": "I09",
          "safeguard_id": "12.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Define consistency rules across disagreeing sources, source precedence, confidence, reconciliation queues, dead-letter handling, reprocessing, and end-to-end trace identity.",
          "zh": "定义冲突来源的一致性、优先级、置信度、对账队列、死信、重处理和端到端追踪身份。"
        },
        {
          "code": "CIS-12.4-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "12.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Generate from authoritative inventories/IaC where possible, add business/trust meaning and owners, version changes and review annually plus on material changes.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“能从权威台账/IaC 生成的先生成，再补业务/信任含义和责任人；版本化变更，每年及重大变化时更新。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-12.4-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "12.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-12.4-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "12.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-12.4-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "12.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-12.4-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "12.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the network inventory, architecture, configuration, and policy authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在网络清单、架构、配置与策略权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-12.4-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "12.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Implement the explicit state machine requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-12.4-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "12.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Implement the explicit state machine discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-12.4-CTL-08",
          "local_code": "CTL-08",
          "display_code": "C08",
          "safeguard_id": "12.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Implement the explicit state machine draft → reviewed → approved → effective → exception/withdrawn → superseded; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-12.4-CTL-09",
          "local_code": "CTL-09",
          "display_code": "C09",
          "safeguard_id": "12.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Specify concurrent decisions, partial success, compensating transactions, repeated requests, stale policy, dependency outage, and recovery from an interrupted state transition.",
          "zh": "定义并发决策、部分成功、补偿事务、重复请求、陈旧策略、依赖中断和中途状态转换恢复。"
        },
        {
          "code": "CIS-12.4-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "12.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (annually); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（annually）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-12.4-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "12.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-12.4-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "12.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-12.4-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "12.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-12.4-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "12.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in network devices, virtual and cloud networking, topology, trust zones, routes, management planes, remote access, AAA, and administrative workstations; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 网络设备、虚拟与云网络、拓扑、信任区、路由、管理平面、远程访问、AAA 和管理工作站 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-12.4-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "12.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; alert before each deadline becomes overdue.",
          "zh": "为“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-12.4-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "12.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence; alert before each deadline becomes overdue.",
          "zh": "为“发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-12.4-TIM-08",
          "local_code": "TIM-08",
          "display_code": "T08",
          "safeguard_id": "12.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for draft → reviewed → approved → effective → exception/withdrawn → superseded; alert before each deadline becomes overdue.",
          "zh": "为“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-12.4-TIM-09",
          "local_code": "TIM-09",
          "display_code": "T09",
          "safeguard_id": "12.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Allocate an end-to-end SLO budget across discovery, collection, processing, approval, enforcement, verification, and closure; prioritize overdue work by consequence and exposure.",
          "zh": "把端到端 SLO 预算分配到发现、采集、处理、审批、执行、验证和关闭，并按后果与暴露排列逾期工作。"
        },
        {
          "code": "CIS-12.4-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "12.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “Represent dynamic and autoscaled resources by pattern and control plane; enumerating every pod creates immediate staleness.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“动态/自动扩容资源用模式与控制面表达，不必画每个 Pod。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-12.4-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "12.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-12.4-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "12.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-12.4-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "12.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-12.4-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "12.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat shadow links, overlapping address space, overlays, provider abstractions, unsupported protocols, emergency consoles, remote devices, stale diagrams, and asymmetric routes as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 影子链路、重叠地址、覆盖网络、提供商抽象、不支持协议、紧急控制台、远程设备、陈旧架构图和非对称路由 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-12.4-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "12.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Treat IPv6, overlays, east-west paths, remote and roaming devices, direct egress, alternate resolvers, QUIC, asymmetric routes, provider abstraction, and emergency consoles as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 IPv6、覆盖网络、东西向路径、远程与漫游设备、直接出口、替代解析器、QUIC、非对称路由、提供商抽象和紧急控制台 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-12.4-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "12.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Treat dormant, ephemeral, disconnected, externally managed, provider-held, aliased, cloned, and cross-tenant objects as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 休眠、短生、离线、外部托管、提供商持有、别名、克隆和跨租户对象 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-12.4-EXC-08",
          "local_code": "EXC-08",
          "display_code": "X08",
          "safeguard_id": "12.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Treat missing policy clauses, conflicting authorities, local deviations, obsolete documentation, and decisions made outside the governed workflow as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 策略条款缺失、权限冲突、本地偏离、文档过期及绕过治理流程的决策 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-12.4-EXC-09",
          "local_code": "EXC-09",
          "display_code": "X09",
          "safeguard_id": "12.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Exercise compound failures where an exception, stale source, provider outage, unavailable owner, and degraded control overlap; define one safe command and one accountable decision.",
          "zh": "演练例外、陈旧来源、提供商中断、责任人不可用和控制降级同时出现的复合故障，明确一条安全指令和一个责任决策。"
        },
        {
          "code": "CIS-12.4-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "12.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Select routes, cloud controls and services from live state and trace them onto diagrams, then select documented paths and verify reality.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“从实时路由、云控制和服务抽样回图，再从图抽样回现实；引入测试变更走批准流程，记录未知链路、陈旧对象和责任缺口。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-12.4-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "12.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-12.4-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "12.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 0 pinned CAS metric branch(es), 3 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 0 个指标分支、3 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-12.4-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "12.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-12.4-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "12.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the network inventory, architecture, configuration, and policy authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以网络清单、架构、配置与策略权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-12.4-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "12.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Publish known, unknown, allowed, denied, shadow, bypassed, asymmetric, stale-rule, exception, and unobserved paths with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已知、未知、允许、拒绝、影子、绕过、非对称、陈旧规则、例外和未观测路径，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-12.4-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "12.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Publish matched, missing, duplicate, stale, ownerless, unapproved, unevaluable, and retired-without-proof counts with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 匹配、缺失、重复、陈旧、无责任人、未批准、不可评估及无证明退役数量，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-12.4-EVD-08",
          "local_code": "EVD-08",
          "display_code": "E08",
          "safeguard_id": "12.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Publish clause coverage, owner and reviewer completeness, approval age, triggered reviews, deviations, overdue actions, and superseded versions still in use with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 条款覆盖、责任人与复核人完整性、批准年龄、触发式复核、偏离、逾期行动及仍在使用的旧版本，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-12.4-EVD-09",
          "local_code": "EVD-09",
          "display_code": "E09",
          "safeguard_id": "12.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Require an independent party to reconstruct the decision from source receipts and reproduce the population, state transition, calculation, test result, exception, and final closure.",
          "zh": "要求独立人员使用来源回执重建决策，并复现总体、状态转换、计算、测试结果、例外和最终关闭。"
        },
        {
          "code": "CIS-12.4-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "12.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-12.4-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "12.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-12.4-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "12.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-12.4-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "12.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-12.4-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "12.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the network inventory, architecture, configuration, and policy authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护网络清单、架构、配置与策略权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-12.4-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "12.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Restrict authority to change requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-12.4-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "12.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Restrict authority to change discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-12.4-SEC-08",
          "local_code": "SEC-08",
          "display_code": "S08",
          "safeguard_id": "12.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Restrict authority to change draft → reviewed → approved → effective → exception/withdrawn → superseded; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-12.4-SEC-09",
          "local_code": "SEC-09",
          "display_code": "S09",
          "safeguard_id": "12.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Threat-model the implementation system itself: forged evidence, poisoned inventory, privilege abuse, cross-tenant confusion, policy rollback, audit deletion, denial of service, and recovery compromise.",
          "zh": "威胁建模实施系统自身：伪造证据、污染清单、权限滥用、跨租户混淆、策略回滚、审计删除、拒绝服务和恢复失陷。"
        },
        {
          "code": "CIS-12.4-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "12.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-12.4-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "12.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-12.4-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "12.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-12.4-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "12.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-12.4-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "12.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise approved and rogue paths, management protocol downgrade, AAA loss, VPN split paths, route and firewall rollback, provider change, and dedicated admin workstation compromise through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 获批与异常路径、管理协议降级、AAA 丢失、VPN 分流、路由与防火墙回滚、提供商变化和专用管理工作站失陷，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-12.4-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "12.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Run the positive control an approved flow over the required secure management or business path; exercise negative, stale, duplicate, bypass, and outage controls including an unapproved route, protocol downgrade, direct egress, alternate DNS/QUIC path, segmentation bypass, AAA loss, stale rule, and rollback failure.",
          "zh": "运行正向控制“通过规定安全管理或业务路径的一项获批流量”，并执行包含“未批准路由、协议降级、直接出口、替代 DNS/QUIC 路径、分段绕过、AAA 丢失、陈旧规则和回滚失败”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-12.4-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "12.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Run the positive control a seeded approved object reconciled from two independent sources; exercise negative, stale, duplicate, bypass, and outage controls including an unknown object, duplicate identity, stale record, vanished object, failed source, and cross-tenant collision.",
          "zh": "运行正向控制“从两个独立来源对账的一项植入已批准对象”，并执行包含“未知对象、重复身份、陈旧记录、突然消失对象、失效来源和跨租户碰撞”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-12.4-TST-08",
          "local_code": "TST-08",
          "display_code": "V08",
          "safeguard_id": "12.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Run the positive control an approved current process used for a representative decision; exercise negative, stale, duplicate, bypass, and outage controls including an obsolete version, missing approver, undocumented deviation, overdue review, and bypassed workflow.",
          "zh": "运行正向控制“使用当前获批流程完成一项代表性决策”，并执行包含“旧版本、审批人缺失、未记录偏离、逾期复核和绕过流程”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-12.4-TST-09",
          "local_code": "TST-09",
          "display_code": "V09",
          "safeguard_id": "12.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Build a pairwise platform-and-failure matrix, then add high-consequence multi-factor cases, historical regression, source substitution, red-team challenge, and assessor replay.",
          "zh": "建立平台—故障两两组合矩阵，再加入高后果多因素案例、历史回归、来源替换、红队挑战和评估方重放。"
        },
        {
          "code": "CIS-12.4-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "12.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-12.4-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "12.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-12.4-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "12.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-12.4-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "12.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-12.4-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "12.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever device and cloud inventories, controllers, configuration backups, IaC, diagrams, routing and firewall state, AAA, VPN, flow data, and change records change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 设备与云清单、控制器、配置备份、IaC、架构图、路由与防火墙状态、AAA、VPN、流量数据和变更记录 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-12.4-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "12.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Use known, unknown, allowed, denied, shadow, bypassed, asymmetric, stale-rule, exception, and unobserved paths to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已知、未知、允许、拒绝、影子、绕过、非对称、陈旧规则、例外和未观测路径 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-12.4-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "12.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Use matched, missing, duplicate, stale, ownerless, unapproved, unevaluable, and retired-without-proof counts to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 匹配、缺失、重复、陈旧、无责任人、未批准、不可评估及无证明退役数量 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-12.4-OPS-08",
          "local_code": "OPS-08",
          "display_code": "R08",
          "safeguard_id": "12.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Use clause coverage, owner and reviewer completeness, approval age, triggered reviews, deviations, overdue actions, and superseded versions still in use to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 条款覆盖、责任人与复核人完整性、批准年龄、触发式复核、偏离、逾期行动及仍在使用的旧版本 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-12.4-OPS-09",
          "local_code": "OPS-09",
          "display_code": "R09",
          "safeguard_id": "12.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Use canary deployment, kill criteria, rollback, backlog burn-down, exception reduction, source-quality targets, quarterly design review, and a measurable retirement plan.",
          "zh": "采用金丝雀、停止标准、回滚、积压燃尽、例外缩减、来源质量目标、季度设计复核和可量化退役计划。"
        }
      ]
    },
    {
      "id": "12.5",
      "control": 12,
      "title_en": "Centralize Network Authentication, Authorization, and Auditing (AAA)",
      "title_zh": "集中网络 AAA",
      "first_ig": 2,
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Network",
      "security_function": "Protect",
      "patterns": [
        "network",
        "identity",
        "telemetry"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "2.1"
        ],
        "variables": [
          "GV5",
          "GV35",
          "M1",
          "M2",
          "M3",
          "M4",
          "M5",
          "M6"
        ],
        "metric_branches": 2,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "Scope administrator and, where applicable, user/device authentication, authorization and accounting for routers, switches, wireless, VPN, firewalls, controllers and cloud network services.",
          "build": "Integrate network devices with resilient central identity/AAA, named admin accounts, MFA or strong upstream auth, role/command policy and tamper-resistant accounting; restrict and vault local fallback accounts.",
          "proof": "Authenticate allowed and denied roles, attempt prohibited commands, disable a user and test failover/outage/local fallback.",
          "boundary": "Fail-open authentication can turn an outage into unrestricted access; fail-closed can strand recovery, so local break-glass is controlled and tested."
        },
        "zh": {
          "scope": "覆盖路由、交换、无线、VPN、防火墙、控制器和云网络服务的管理员，以及适用的用户/设备认证、授权和审计。",
          "build": "接入有弹性的中央身份/AAA，实名管理员、MFA 或强上游认证、角色/命令策略和防篡改 Accounting；限制并入库本地回退账户。",
          "proof": "测试允许/拒绝角色、禁止命令、禁用用户、故障转移/停机/本地回退；把命令和配置审计追到具名人和目标，并逐设备核对有效 AAA 顺序。",
          "boundary": "Fail-open 会把故障变成无约束访问，Fail-closed 会锁死恢复，本地破窗因此必须受控、可测。"
        }
      },
      "category_counts": {
        "outcome": 8,
        "scope": 8,
        "ownership": 8,
        "data": 8,
        "integration": 8,
        "control": 8,
        "timing": 8,
        "exception": 8,
        "evidence": 8,
        "security": 8,
        "testing": 8,
        "operations": 8
      },
      "requirement_count": 96,
      "requirements": [
        {
          "code": "CIS-12.5-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "12.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Centralize Network Authentication, Authorization, and Auditing (AAA); name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“集中网络 AAA”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-12.5-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "12.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 12.5, official Asset Class Network, Security Function Protect, and IG2 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 12.5、官方资产类别“网络”、安全功能“保护”和首次出现的 IG2，并保存来源抓取日期。"
        },
        {
          "code": "CIS-12.5-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "12.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Scope administrator and, where applicable, user/device authentication, authorization and accounting for routers, switches, wireless, VPN, firewalls, controllers and cloud network services.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“覆盖路由、交换、无线、VPN、防火墙、控制器和云网络服务的管理员，以及适用的用户/设备认证、授权和审计。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-12.5-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "12.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-12.5-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "12.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Centralize Network Authentication, Authorization, and Auditing (AAA) to its operating object—network devices, virtual and cloud networking, topology, trust zones, routes, management planes, remote access, AAA, and administrative workstations—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“集中网络 AAA”连接到其运营对象——网络设备、虚拟与云网络、拓扑、信任区、路由、管理平面、远程访问、AAA 和管理工作站——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-12.5-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "12.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "For Centralize Network Authentication, Authorization, and Auditing (AAA), express success as an observable decision over intended connectivity, trust zone, route, protocol, identity, management path, traffic decision, and observed outcome; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“集中网络 AAA”，以 预期连接、信任区、路由、协议、身份、管理路径、流量决策和观察结果 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-12.5-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "12.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "For Centralize Network Authentication, Authorization, and Auditing (AAA), express success as an observable decision over effective identity, authentication, authorization, privilege, session, and revocation state across every access path; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“集中网络 AAA”，以 所有访问路径上的实际身份、认证、授权、权限、会话和撤销状态 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-12.5-OUT-08",
          "local_code": "OUT-08",
          "display_code": "O08",
          "safeguard_id": "12.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "For Centralize Network Authentication, Authorization, and Auditing (AAA), express success as an observable decision over complete, attributable, timely, protected, searchable, and actionable security telemetry plus source health; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“集中网络 AAA”，以 完整、可归因、及时、受保护、可检索、可行动的安全遥测及来源健康 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-12.5-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "12.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-12.5-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "12.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-12.5-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "12.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-12.5-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "12.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-12.5-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "12.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across shadow links, overlapping address space, overlays, provider abstractions, unsupported protocols, emergency consoles, remote devices, stale diagrams, and asymmetric routes; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 影子链路、重叠地址、覆盖网络、提供商抽象、不支持协议、紧急控制台、远程设备、陈旧架构图和非对称路由 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-12.5-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "12.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Include IPv6, overlays, east-west paths, remote and roaming devices, direct egress, alternate resolvers, QUIC, asymmetric routes, provider abstraction, and emergency consoles in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 IPv6、覆盖网络、东西向路径、远程与漫游设备、直接出口、替代解析器、QUIC、非对称路由、提供商抽象和紧急控制台 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-12.5-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "12.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Include shared and service identities, nested groups, direct grants, cached sessions, federation gaps, recovery channels, API keys, emergency access, and provider support in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 共享与服务身份、嵌套组、直接授权、缓存会话、联邦缺口、恢复通道、API 密钥、紧急访问和提供商支持 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-12.5-SCP-08",
          "local_code": "SCP-08",
          "display_code": "P08",
          "safeguard_id": "12.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Include clock skew, actor loss, field truncation, parser drift, dropped or duplicate events, privacy redaction, provider gaps, encrypted paths, quota, and archive failure in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 时钟偏移、行为者丢失、字段截断、解析漂移、事件丢失或重复、隐私脱敏、提供商缺口、加密路径、配额和归档故障 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-12.5-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "12.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-12.5-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "12.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-12.5-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "12.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-12.5-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "12.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-12.5-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "12.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind network and cloud engineering, security architecture, identity, service owners, operations, and change management to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 网络与云工程、安全架构、身份、服务责任人、运营和变更管理 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-12.5-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "12.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Name who may transition requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-12.5-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "12.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Name who may transition requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-12.5-OWN-08",
          "local_code": "OWN-08",
          "display_code": "W08",
          "safeguard_id": "12.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Name who may transition event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-12.5-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "12.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-12.5-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "12.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-12.5-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "12.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV5, GV35, M1, M2, M3, M4, M5, M6) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV5, GV35, M1, M2, M3, M4, M5, M6）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-12.5-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "12.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-12.5-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "12.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the network inventory, architecture, configuration, and policy authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把网络清单、架构、配置与策略权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-12.5-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "12.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired.",
          "zh": "对生命周期“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-12.5-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "12.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated.",
          "zh": "对生命周期“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-12.5-DAT-08",
          "local_code": "DAT-08",
          "display_code": "D08",
          "safeguard_id": "12.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired.",
          "zh": "对生命周期“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-12.5-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "12.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 2.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 2.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-12.5-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "12.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-12.5-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "12.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-12.5-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "12.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-12.5-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "12.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile device and cloud inventories, controllers, configuration backups, IaC, diagrams, routing and firewall state, AAA, VPN, flow data, and change records and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 设备与云清单、控制器、配置备份、IaC、架构图、路由与防火墙状态、AAA、VPN、流量数据和变更记录，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-12.5-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "12.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Require every connector carrying intended connectivity, trust zone, route, protocol, identity, management path, traffic decision, and observed outcome to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 预期连接、信任区、路由、协议、身份、管理路径、流量决策和观察结果 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-12.5-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "12.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Require every connector carrying effective identity, authentication, authorization, privilege, session, and revocation state across every access path to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 所有访问路径上的实际身份、认证、授权、权限、会话和撤销状态 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-12.5-INT-08",
          "local_code": "INT-08",
          "display_code": "I08",
          "safeguard_id": "12.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Require every connector carrying complete, attributable, timely, protected, searchable, and actionable security telemetry plus source health to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 完整、可归因、及时、受保护、可检索、可行动的安全遥测及来源健康 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-12.5-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "12.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Integrate network devices with resilient central identity/AAA, named admin accounts, MFA or strong upstream auth, role/command policy and tamper-resistant accounting; restrict and vault local fallback accounts.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“接入有弹性的中央身份/AAA，实名管理员、MFA 或强上游认证、角色/命令策略和防篡改 Accounting；限制并入库本地回退账户。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-12.5-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "12.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-12.5-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "12.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-12.5-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "12.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-12.5-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "12.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the network inventory, architecture, configuration, and policy authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在网络清单、架构、配置与策略权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-12.5-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "12.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Implement the explicit state machine requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-12.5-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "12.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Implement the explicit state machine requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-12.5-CTL-08",
          "local_code": "CTL-08",
          "display_code": "C08",
          "safeguard_id": "12.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Implement the explicit state machine event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-12.5-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "12.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-12.5-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "12.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-12.5-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "12.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-12.5-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "12.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-12.5-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "12.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in network devices, virtual and cloud networking, topology, trust zones, routes, management planes, remote access, AAA, and administrative workstations; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 网络设备、虚拟与云网络、拓扑、信任区、路由、管理平面、远程访问、AAA 和管理工作站 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-12.5-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "12.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; alert before each deadline becomes overdue.",
          "zh": "为“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-12.5-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "12.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated; alert before each deadline becomes overdue.",
          "zh": "为“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-12.5-TIM-08",
          "local_code": "TIM-08",
          "display_code": "T08",
          "safeguard_id": "12.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired; alert before each deadline becomes overdue.",
          "zh": "为“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-12.5-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "12.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “Fail-open authentication can turn an outage into unrestricted access; fail-closed can strand recovery, so local break-glass is controlled and tested.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“Fail-open 会把故障变成无约束访问，Fail-closed 会锁死恢复，本地破窗因此必须受控、可测。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-12.5-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "12.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-12.5-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "12.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-12.5-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "12.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-12.5-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "12.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat shadow links, overlapping address space, overlays, provider abstractions, unsupported protocols, emergency consoles, remote devices, stale diagrams, and asymmetric routes as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 影子链路、重叠地址、覆盖网络、提供商抽象、不支持协议、紧急控制台、远程设备、陈旧架构图和非对称路由 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-12.5-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "12.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Treat IPv6, overlays, east-west paths, remote and roaming devices, direct egress, alternate resolvers, QUIC, asymmetric routes, provider abstraction, and emergency consoles as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 IPv6、覆盖网络、东西向路径、远程与漫游设备、直接出口、替代解析器、QUIC、非对称路由、提供商抽象和紧急控制台 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-12.5-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "12.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Treat shared and service identities, nested groups, direct grants, cached sessions, federation gaps, recovery channels, API keys, emergency access, and provider support as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 共享与服务身份、嵌套组、直接授权、缓存会话、联邦缺口、恢复通道、API 密钥、紧急访问和提供商支持 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-12.5-EXC-08",
          "local_code": "EXC-08",
          "display_code": "X08",
          "safeguard_id": "12.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Treat clock skew, actor loss, field truncation, parser drift, dropped or duplicate events, privacy redaction, provider gaps, encrypted paths, quota, and archive failure as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 时钟偏移、行为者丢失、字段截断、解析漂移、事件丢失或重复、隐私脱敏、提供商缺口、加密路径、配额和归档故障 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-12.5-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "12.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Authenticate allowed and denied roles, attempt prohibited commands, disable a user and test failover/outage/local fallback.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“测试允许/拒绝角色、禁止命令、禁用用户、故障转移/停机/本地回退；把命令和配置审计追到具名人和目标，并逐设备核对有效 AAA 顺序。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-12.5-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "12.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-12.5-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "12.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 2 pinned CAS metric branch(es), 8 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 2 个指标分支、8 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-12.5-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "12.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-12.5-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "12.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the network inventory, architecture, configuration, and policy authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以网络清单、架构、配置与策略权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-12.5-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "12.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Publish known, unknown, allowed, denied, shadow, bypassed, asymmetric, stale-rule, exception, and unobserved paths with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已知、未知、允许、拒绝、影子、绕过、非对称、陈旧规则、例外和未观测路径，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-12.5-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "12.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Publish requested, approved, effective, excessive, orphaned, stale, emergency, revoked-but-active, and independently reviewed rights with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 申请、批准、实际、过度、孤儿、陈旧、紧急、已撤销仍活跃及独立复核权限，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-12.5-EVD-08",
          "local_code": "EVD-08",
          "display_code": "E08",
          "safeguard_id": "12.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Publish healthy, silent, partial, late, malformed, duplicate, unowned, unreviewed, alerted, investigated, and archived sources or events with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 健康、静默、部分、迟到、畸形、重复、无责任人、未审阅、已告警、已调查和已归档来源或事件，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-12.5-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "12.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-12.5-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "12.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-12.5-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "12.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-12.5-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "12.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-12.5-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "12.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the network inventory, architecture, configuration, and policy authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护网络清单、架构、配置与策略权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-12.5-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "12.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Restrict authority to change requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-12.5-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "12.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Restrict authority to change requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-12.5-SEC-08",
          "local_code": "SEC-08",
          "display_code": "S08",
          "safeguard_id": "12.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Restrict authority to change event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-12.5-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "12.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-12.5-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "12.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-12.5-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "12.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-12.5-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "12.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-12.5-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "12.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise approved and rogue paths, management protocol downgrade, AAA loss, VPN split paths, route and firewall rollback, provider change, and dedicated admin workstation compromise through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 获批与异常路径、管理协议降级、AAA 丢失、VPN 分流、路由与防火墙回滚、提供商变化和专用管理工作站失陷，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-12.5-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "12.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Run the positive control an approved flow over the required secure management or business path; exercise negative, stale, duplicate, bypass, and outage controls including an unapproved route, protocol downgrade, direct egress, alternate DNS/QUIC path, segmentation bypass, AAA loss, stale rule, and rollback failure.",
          "zh": "运行正向控制“通过规定安全管理或业务路径的一项获批流量”，并执行包含“未批准路由、协议降级、直接出口、替代 DNS/QUIC 路径、分段绕过、AAA 丢失、陈旧规则和回滚失败”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-12.5-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "12.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Run the positive control an authorized identity using the required assurance and least privilege; exercise negative, stale, duplicate, bypass, and outage controls including an unauthorized identity, missing factor, stale session, direct grant, inherited excess, revoked token, and recovery bypass.",
          "zh": "运行正向控制“使用所需保证级别和最小权限的授权身份”，并执行包含“未授权身份、缺失认证因子、陈旧会话、直接授权、继承过权、已撤销令牌和恢复绕过”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-12.5-TST-08",
          "local_code": "TST-08",
          "display_code": "V08",
          "safeguard_id": "12.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Run the positive control an allowed and denied canary event traced from source through review; exercise negative, stale, duplicate, bypass, and outage controls including source loss, parser/schema change, time skew, queue overflow, duplicate delivery, provider export outage, missed alert, and unreadable archive.",
          "zh": "运行正向控制“一项允许与拒绝金丝雀事件从来源贯穿到审阅”，并执行包含“来源丢失、解析器/模式变化、时钟偏移、队列溢出、重复投递、提供商导出中断、漏报和归档不可读”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-12.5-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "12.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-12.5-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "12.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-12.5-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "12.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-12.5-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "12.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-12.5-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "12.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever device and cloud inventories, controllers, configuration backups, IaC, diagrams, routing and firewall state, AAA, VPN, flow data, and change records change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 设备与云清单、控制器、配置备份、IaC、架构图、路由与防火墙状态、AAA、VPN、流量数据和变更记录 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-12.5-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "12.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Use known, unknown, allowed, denied, shadow, bypassed, asymmetric, stale-rule, exception, and unobserved paths to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已知、未知、允许、拒绝、影子、绕过、非对称、陈旧规则、例外和未观测路径 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-12.5-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "12.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Use requested, approved, effective, excessive, orphaned, stale, emergency, revoked-but-active, and independently reviewed rights to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 申请、批准、实际、过度、孤儿、陈旧、紧急、已撤销仍活跃及独立复核权限 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-12.5-OPS-08",
          "local_code": "OPS-08",
          "display_code": "R08",
          "safeguard_id": "12.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Use healthy, silent, partial, late, malformed, duplicate, unowned, unreviewed, alerted, investigated, and archived sources or events to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 健康、静默、部分、迟到、畸形、重复、无责任人、未审阅、已告警、已调查和已归档来源或事件 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "12.6",
      "control": 12,
      "title_en": "Use of Secure Network Management and Communication Protocols",
      "title_zh": "安全网络管理与通信协议",
      "first_ig": 2,
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Network",
      "security_function": "Protect",
      "patterns": [
        "network",
        "encryption"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "4.2",
          "12.2"
        ],
        "variables": [
          "GV36",
          "GV37",
          "M1",
          "M2",
          "M3",
          "M4",
          "M5",
          "M6",
          "M7",
          "M8",
          "M9"
        ],
        "metric_branches": 2,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "The population includes management and access/communication protocols on wired, wireless, WAN, VPN, device and cloud networks: SSH/HTTPS/SNMPv3, secure routing/control, 802.1X, WPA2-Enterprise or stronger and authenticated/encrypted equivalents.",
          "build": "Maintain an authorized protocol/configuration catalog, disable plaintext/legacy versions, manage certificates/keys, enforce enterprise wireless and port identity, and monitor downgrade or rogue service.",
          "proof": "Scan and negotiate every representative management/access path for protocols, versions and ciphers; attempt downgrade, weak credential, rogue AP/server and invalid certificate.",
          "boundary": "An “approved protocol” with anonymous, shared, expired or weak configuration still fails."
        },
        "zh": {
          "scope": "包括有线、无线、WAN、VPN、设备与云网络的管理和接入/通信协议：SSH/HTTPS/SNMPv3、安全路由控制、802.1X、WPA2-Enterprise 或更强同类。",
          "build": "维护批准协议/配置目录，关闭明文与旧版本，管理证书/密钥，强制企业无线和端口身份，监测降级/Rogue 服务；无法移除的旧协议分段并经安全网关代理。",
          "proof": "扫描并协商代表管理/接入路径的协议、版本与算法，尝试降级、弱凭据、Rogue AP/服务器和无效证书；主/备路径都验证业务与日志。",
          "boundary": "“批准协议”若匿名、共享、过期或弱配置仍失败。"
        }
      },
      "category_counts": {
        "outcome": 7,
        "scope": 7,
        "ownership": 7,
        "data": 7,
        "integration": 7,
        "control": 7,
        "timing": 7,
        "exception": 7,
        "evidence": 7,
        "security": 7,
        "testing": 7,
        "operations": 7
      },
      "requirement_count": 84,
      "requirements": [
        {
          "code": "CIS-12.6-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "12.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Use of Secure Network Management and Communication Protocols; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“安全网络管理与通信协议”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-12.6-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "12.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 12.6, official Asset Class Network, Security Function Protect, and IG2 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 12.6、官方资产类别“网络”、安全功能“保护”和首次出现的 IG2，并保存来源抓取日期。"
        },
        {
          "code": "CIS-12.6-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "12.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “The population includes management and access/communication protocols on wired, wireless, WAN, VPN, device and cloud networks: SSH/HTTPS/SNMPv3, secure routing/control, 802.1X, WPA2-Enterprise or stronger and authenticated/encrypted equivalents.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“包括有线、无线、WAN、VPN、设备与云网络的管理和接入/通信协议：SSH/HTTPS/SNMPv3、安全路由控制、802.1X、WPA2-Enterprise 或更强同类。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-12.6-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "12.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-12.6-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "12.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Use of Secure Network Management and Communication Protocols to its operating object—network devices, virtual and cloud networking, topology, trust zones, routes, management planes, remote access, AAA, and administrative workstations—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“安全网络管理与通信协议”连接到其运营对象——网络设备、虚拟与云网络、拓扑、信任区、路由、管理平面、远程访问、AAA 和管理工作站——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-12.6-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "12.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "For Use of Secure Network Management and Communication Protocols, express success as an observable decision over intended connectivity, trust zone, route, protocol, identity, management path, traffic decision, and observed outcome; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“安全网络管理与通信协议”，以 预期连接、信任区、路由、协议、身份、管理路径、流量决策和观察结果 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-12.6-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "12.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original encryption pattern analysis",
          "basis_zh": "SOSEC 原创 encryption 模式分析",
          "en": "For Use of Secure Network Management and Communication Protocols, express success as an observable decision over plaintext exposure against a named loss, theft, interception, storage-administrator, provider, or cross-tenant threat; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“安全网络管理与通信协议”，以 针对丢失、盗窃、截获、存储管理员、提供商或跨租户威胁的明文暴露 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-12.6-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "12.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-12.6-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "12.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-12.6-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "12.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-12.6-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "12.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-12.6-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "12.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across shadow links, overlapping address space, overlays, provider abstractions, unsupported protocols, emergency consoles, remote devices, stale diagrams, and asymmetric routes; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 影子链路、重叠地址、覆盖网络、提供商抽象、不支持协议、紧急控制台、远程设备、陈旧架构图和非对称路由 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-12.6-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "12.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Include IPv6, overlays, east-west paths, remote and roaming devices, direct egress, alternate resolvers, QUIC, asymmetric routes, provider abstraction, and emergency consoles in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 IPv6、覆盖网络、东西向路径、远程与漫游设备、直接出口、替代解析器、QUIC、非对称路由、提供商抽象和紧急控制台 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-12.6-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "12.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original encryption pattern analysis",
          "basis_zh": "SOSEC 原创 encryption 模式分析",
          "en": "Include unsupported endpoints, boot and unlocked state, alternate protocols, downgrade, copied data, key export, shared keys, backups, logs, and recovery in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 不支持终端、启动与解锁状态、替代协议、降级、数据副本、密钥导出、共享密钥、备份、日志和恢复 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-12.6-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "12.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-12.6-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "12.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-12.6-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "12.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-12.6-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "12.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-12.6-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "12.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind network and cloud engineering, security architecture, identity, service owners, operations, and change management to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 网络与云工程、安全架构、身份、服务责任人、运营和变更管理 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-12.6-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "12.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Name who may transition requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-12.6-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "12.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original encryption pattern analysis",
          "basis_zh": "SOSEC 原创 encryption 模式分析",
          "en": "Name who may transition data identified → policy selected → keys provisioned → encryption enforced → use/decrypt authorized → keys rotated/revoked → data retired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 识别数据 → 选择策略 → 配发密钥 → 强制加密 → 授权使用/解密 → 轮换/撤销密钥 → 退役数据，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-12.6-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "12.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-12.6-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "12.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-12.6-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "12.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV36, GV37, M1, M2, M3, M4, M5, M6, M7, M8, M9) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV36, GV37, M1, M2, M3, M4, M5, M6, M7, M8, M9）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-12.6-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "12.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-12.6-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "12.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the network inventory, architecture, configuration, and policy authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把网络清单、架构、配置与策略权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-12.6-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "12.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired.",
          "zh": "对生命周期“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-12.6-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "12.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original encryption pattern analysis",
          "basis_zh": "SOSEC 原创 encryption 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle data identified → policy selected → keys provisioned → encryption enforced → use/decrypt authorized → keys rotated/revoked → data retired.",
          "zh": "对生命周期“识别数据 → 选择策略 → 配发密钥 → 强制加密 → 授权使用/解密 → 轮换/撤销密钥 → 退役数据”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-12.6-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "12.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 4.2, Safeguard 12.2; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 4.2、Safeguard 12.2 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-12.6-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "12.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-12.6-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "12.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-12.6-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "12.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-12.6-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "12.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile device and cloud inventories, controllers, configuration backups, IaC, diagrams, routing and firewall state, AAA, VPN, flow data, and change records and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 设备与云清单、控制器、配置备份、IaC、架构图、路由与防火墙状态、AAA、VPN、流量数据和变更记录，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-12.6-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "12.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Require every connector carrying intended connectivity, trust zone, route, protocol, identity, management path, traffic decision, and observed outcome to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 预期连接、信任区、路由、协议、身份、管理路径、流量决策和观察结果 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-12.6-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "12.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original encryption pattern analysis",
          "basis_zh": "SOSEC 原创 encryption 模式分析",
          "en": "Require every connector carrying plaintext exposure against a named loss, theft, interception, storage-administrator, provider, or cross-tenant threat to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 针对丢失、盗窃、截获、存储管理员、提供商或跨租户威胁的明文暴露 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-12.6-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "12.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Maintain an authorized protocol/configuration catalog, disable plaintext/legacy versions, manage certificates/keys, enforce enterprise wireless and port identity, and monitor downgrade or rogue service.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“维护批准协议/配置目录，关闭明文与旧版本，管理证书/密钥，强制企业无线和端口身份，监测降级/Rogue 服务；无法移除的旧协议分段并经安全网关代理。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-12.6-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "12.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-12.6-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "12.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-12.6-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "12.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-12.6-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "12.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the network inventory, architecture, configuration, and policy authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在网络清单、架构、配置与策略权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-12.6-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "12.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Implement the explicit state machine requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-12.6-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "12.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original encryption pattern analysis",
          "basis_zh": "SOSEC 原创 encryption 模式分析",
          "en": "Implement the explicit state machine data identified → policy selected → keys provisioned → encryption enforced → use/decrypt authorized → keys rotated/revoked → data retired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“识别数据 → 选择策略 → 配发密钥 → 强制加密 → 授权使用/解密 → 轮换/撤销密钥 → 退役数据”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-12.6-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "12.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-12.6-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "12.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-12.6-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "12.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-12.6-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "12.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-12.6-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "12.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in network devices, virtual and cloud networking, topology, trust zones, routes, management planes, remote access, AAA, and administrative workstations; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 网络设备、虚拟与云网络、拓扑、信任区、路由、管理平面、远程访问、AAA 和管理工作站 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-12.6-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "12.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; alert before each deadline becomes overdue.",
          "zh": "为“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-12.6-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "12.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original encryption pattern analysis",
          "basis_zh": "SOSEC 原创 encryption 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for data identified → policy selected → keys provisioned → encryption enforced → use/decrypt authorized → keys rotated/revoked → data retired; alert before each deadline becomes overdue.",
          "zh": "为“识别数据 → 选择策略 → 配发密钥 → 强制加密 → 授权使用/解密 → 轮换/撤销密钥 → 退役数据”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-12.6-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "12.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “An “approved protocol” with anonymous, shared, expired or weak configuration still fails.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：““批准协议”若匿名、共享、过期或弱配置仍失败。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-12.6-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "12.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-12.6-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "12.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-12.6-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "12.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-12.6-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "12.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat shadow links, overlapping address space, overlays, provider abstractions, unsupported protocols, emergency consoles, remote devices, stale diagrams, and asymmetric routes as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 影子链路、重叠地址、覆盖网络、提供商抽象、不支持协议、紧急控制台、远程设备、陈旧架构图和非对称路由 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-12.6-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "12.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Treat IPv6, overlays, east-west paths, remote and roaming devices, direct egress, alternate resolvers, QUIC, asymmetric routes, provider abstraction, and emergency consoles as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 IPv6、覆盖网络、东西向路径、远程与漫游设备、直接出口、替代解析器、QUIC、非对称路由、提供商抽象和紧急控制台 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-12.6-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "12.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original encryption pattern analysis",
          "basis_zh": "SOSEC 原创 encryption 模式分析",
          "en": "Treat unsupported endpoints, boot and unlocked state, alternate protocols, downgrade, copied data, key export, shared keys, backups, logs, and recovery as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 不支持终端、启动与解锁状态、替代协议、降级、数据副本、密钥导出、共享密钥、备份、日志和恢复 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-12.6-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "12.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Scan and negotiate every representative management/access path for protocols, versions and ciphers; attempt downgrade, weak credential, rogue AP/server and invalid certificate.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“扫描并协商代表管理/接入路径的协议、版本与算法，尝试降级、弱凭据、Rogue AP/服务器和无效证书；主/备路径都验证业务与日志。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-12.6-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "12.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-12.6-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "12.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 2 pinned CAS metric branch(es), 11 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 2 个指标分支、11 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-12.6-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "12.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-12.6-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "12.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the network inventory, architecture, configuration, and policy authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以网络清单、架构、配置与策略权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-12.6-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "12.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Publish known, unknown, allowed, denied, shadow, bypassed, asymmetric, stale-rule, exception, and unobserved paths with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已知、未知、允许、拒绝、影子、绕过、非对称、陈旧规则、例外和未观测路径，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-12.6-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "12.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original encryption pattern analysis",
          "basis_zh": "SOSEC 原创 encryption 模式分析",
          "en": "Publish eligible, protected, weak/legacy, keyless, shared-key, decryptable-by-unintended-party, exception, and recovery-tested objects with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 适用、已保护、弱/旧算法、无密钥、共享密钥、非预期主体可解密、例外及恢复已测试对象，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-12.6-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "12.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-12.6-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "12.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-12.6-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "12.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-12.6-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "12.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-12.6-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "12.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the network inventory, architecture, configuration, and policy authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护网络清单、架构、配置与策略权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-12.6-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "12.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Restrict authority to change requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-12.6-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "12.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original encryption pattern analysis",
          "basis_zh": "SOSEC 原创 encryption 模式分析",
          "en": "Restrict authority to change data identified → policy selected → keys provisioned → encryption enforced → use/decrypt authorized → keys rotated/revoked → data retired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“识别数据 → 选择策略 → 配发密钥 → 强制加密 → 授权使用/解密 → 轮换/撤销密钥 → 退役数据”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-12.6-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "12.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-12.6-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "12.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-12.6-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "12.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-12.6-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "12.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-12.6-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "12.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise approved and rogue paths, management protocol downgrade, AAA loss, VPN split paths, route and firewall rollback, provider change, and dedicated admin workstation compromise through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 获批与异常路径、管理协议降级、AAA 丢失、VPN 分流、路由与防火墙回滚、提供商变化和专用管理工作站失陷，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-12.6-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "12.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Run the positive control an approved flow over the required secure management or business path; exercise negative, stale, duplicate, bypass, and outage controls including an unapproved route, protocol downgrade, direct egress, alternate DNS/QUIC path, segmentation bypass, AAA loss, stale rule, and rollback failure.",
          "zh": "运行正向控制“通过规定安全管理或业务路径的一项获批流量”，并执行包含“未批准路由、协议降级、直接出口、替代 DNS/QUIC 路径、分段绕过、AAA 丢失、陈旧规则和回滚失败”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-12.6-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "12.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original encryption pattern analysis",
          "basis_zh": "SOSEC 原创 encryption 模式分析",
          "en": "Run the positive control authorized encryption, decryption, rotation, and recovery for representative data; exercise negative, stale, duplicate, bypass, and outage controls including plaintext path, protocol downgrade, lost device, copied storage, unauthorized principal, revoked key, failed rotation, and unavailable recovery key.",
          "zh": "运行正向控制“代表性数据的授权加密、解密、轮换和恢复”，并执行包含“明文路径、协议降级、设备丢失、复制存储、未授权主体、撤销密钥、轮换失败和恢复密钥不可用”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-12.6-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "12.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-12.6-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "12.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-12.6-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "12.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-12.6-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "12.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-12.6-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "12.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever device and cloud inventories, controllers, configuration backups, IaC, diagrams, routing and firewall state, AAA, VPN, flow data, and change records change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 设备与云清单、控制器、配置备份、IaC、架构图、路由与防火墙状态、AAA、VPN、流量数据和变更记录 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-12.6-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "12.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Use known, unknown, allowed, denied, shadow, bypassed, asymmetric, stale-rule, exception, and unobserved paths to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已知、未知、允许、拒绝、影子、绕过、非对称、陈旧规则、例外和未观测路径 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-12.6-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "12.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original encryption pattern analysis",
          "basis_zh": "SOSEC 原创 encryption 模式分析",
          "en": "Use eligible, protected, weak/legacy, keyless, shared-key, decryptable-by-unintended-party, exception, and recovery-tested objects to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 适用、已保护、弱/旧算法、无密钥、共享密钥、非预期主体可解密、例外及恢复已测试对象 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "12.7",
      "control": 12,
      "title_en": "Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise’s AAA Infrastructure",
      "title_zh": "远程设备 VPN 与 AAA",
      "first_ig": 2,
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Devices",
      "security_function": "Protect",
      "patterns": [
        "network",
        "identity"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "1.1",
          "2.1",
          "12.5"
        ],
        "variables": [
          "GV1",
          "GV5",
          "GV37",
          "GV38",
          "GV39",
          "M1",
          "M2",
          "M3",
          "M4",
          "M5",
          "M6",
          "M7",
          "M8",
          "M9",
          "M10",
          "M11",
          "M12"
        ],
        "metric_branches": 3,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "Scope remote end-user devices accessing private enterprise resources; require authentication through enterprise-managed VPN and AAA before access.",
          "build": "Configure approved VPN/ZTNA clients and gateways, MFA/AAA, device identity/posture, destination least privilege, session limits and revocation.",
          "proof": "Connect approved/unapproved devices and identities through primary, fallback and alternate protocols; verify pre-auth isolation, AAA decision, destination scope, logs and session termination after revocation.",
          "boundary": "The CAS final operation labels the intersection M1 instead of M11, so literal automation overwrites the denominator."
        },
        "zh": {
          "scope": "覆盖远程终端访问私有企业资源，要求在访问前经企业管理 VPN 与 AAA。",
          "build": "配置批准 VPN/ZTNA Client/Gateway、MFA/AAA、设备身份/姿态、最小目的、会话限制和撤销；防直连备用路径，保护 Profile，注册取决于受管设备状态，分开厂商/管理员。",
          "proof": "用批准/未批准设备和身份走主、备、替代协议，验证预认证隔离、AAA、目的范围、日志和撤销后终止；只计算真实私有资源路径同时经过两项控制的远程资产。",
          "boundary": "CAS 最后交集写成 M1 而非 M11，照抄会覆盖分母。"
        }
      },
      "category_counts": {
        "outcome": 7,
        "scope": 7,
        "ownership": 7,
        "data": 7,
        "integration": 7,
        "control": 7,
        "timing": 7,
        "exception": 7,
        "evidence": 7,
        "security": 7,
        "testing": 7,
        "operations": 7
      },
      "requirement_count": 84,
      "requirements": [
        {
          "code": "CIS-12.7-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "12.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise’s AAA Infrastructure; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“远程设备 VPN 与 AAA”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-12.7-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "12.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 12.7, official Asset Class Devices, Security Function Protect, and IG2 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 12.7、官方资产类别“设备”、安全功能“保护”和首次出现的 IG2，并保存来源抓取日期。"
        },
        {
          "code": "CIS-12.7-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "12.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Scope remote end-user devices accessing private enterprise resources; require authentication through enterprise-managed VPN and AAA before access.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“覆盖远程终端访问私有企业资源，要求在访问前经企业管理 VPN 与 AAA。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-12.7-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "12.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-12.7-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "12.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise’s AAA Infrastructure to its operating object—network devices, virtual and cloud networking, topology, trust zones, routes, management planes, remote access, AAA, and administrative workstations—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“远程设备 VPN 与 AAA”连接到其运营对象——网络设备、虚拟与云网络、拓扑、信任区、路由、管理平面、远程访问、AAA 和管理工作站——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-12.7-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "12.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "For Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise’s AAA Infrastructure, express success as an observable decision over intended connectivity, trust zone, route, protocol, identity, management path, traffic decision, and observed outcome; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“远程设备 VPN 与 AAA”，以 预期连接、信任区、路由、协议、身份、管理路径、流量决策和观察结果 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-12.7-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "12.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "For Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise’s AAA Infrastructure, express success as an observable decision over effective identity, authentication, authorization, privilege, session, and revocation state across every access path; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“远程设备 VPN 与 AAA”，以 所有访问路径上的实际身份、认证、授权、权限、会话和撤销状态 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-12.7-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "12.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-12.7-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "12.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-12.7-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "12.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-12.7-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "12.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-12.7-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "12.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across shadow links, overlapping address space, overlays, provider abstractions, unsupported protocols, emergency consoles, remote devices, stale diagrams, and asymmetric routes; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 影子链路、重叠地址、覆盖网络、提供商抽象、不支持协议、紧急控制台、远程设备、陈旧架构图和非对称路由 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-12.7-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "12.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Include IPv6, overlays, east-west paths, remote and roaming devices, direct egress, alternate resolvers, QUIC, asymmetric routes, provider abstraction, and emergency consoles in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 IPv6、覆盖网络、东西向路径、远程与漫游设备、直接出口、替代解析器、QUIC、非对称路由、提供商抽象和紧急控制台 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-12.7-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "12.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Include shared and service identities, nested groups, direct grants, cached sessions, federation gaps, recovery channels, API keys, emergency access, and provider support in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 共享与服务身份、嵌套组、直接授权、缓存会话、联邦缺口、恢复通道、API 密钥、紧急访问和提供商支持 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-12.7-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "12.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-12.7-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "12.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-12.7-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "12.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-12.7-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "12.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-12.7-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "12.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind network and cloud engineering, security architecture, identity, service owners, operations, and change management to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 网络与云工程、安全架构、身份、服务责任人、运营和变更管理 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-12.7-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "12.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Name who may transition requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-12.7-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "12.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Name who may transition requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-12.7-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "12.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-12.7-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "12.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-12.7-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "12.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV1, GV5, GV37, GV38, GV39, M1, M2, M3, M4, M5, M6, M7, and 5 more) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV1, GV5, GV37, GV38, GV39, M1, M2, M3, M4, M5, M6, M7, and 5 more）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-12.7-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "12.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-12.7-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "12.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the network inventory, architecture, configuration, and policy authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把网络清单、架构、配置与策略权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-12.7-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "12.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired.",
          "zh": "对生命周期“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-12.7-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "12.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated.",
          "zh": "对生命周期“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-12.7-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "12.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 1.1, Safeguard 2.1, Safeguard 12.5; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 1.1、Safeguard 2.1、Safeguard 12.5 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-12.7-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "12.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-12.7-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "12.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-12.7-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "12.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-12.7-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "12.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile device and cloud inventories, controllers, configuration backups, IaC, diagrams, routing and firewall state, AAA, VPN, flow data, and change records and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 设备与云清单、控制器、配置备份、IaC、架构图、路由与防火墙状态、AAA、VPN、流量数据和变更记录，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-12.7-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "12.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Require every connector carrying intended connectivity, trust zone, route, protocol, identity, management path, traffic decision, and observed outcome to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 预期连接、信任区、路由、协议、身份、管理路径、流量决策和观察结果 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-12.7-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "12.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Require every connector carrying effective identity, authentication, authorization, privilege, session, and revocation state across every access path to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 所有访问路径上的实际身份、认证、授权、权限、会话和撤销状态 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-12.7-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "12.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Configure approved VPN/ZTNA clients and gateways, MFA/AAA, device identity/posture, destination least privilege, session limits and revocation.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“配置批准 VPN/ZTNA Client/Gateway、MFA/AAA、设备身份/姿态、最小目的、会话限制和撤销；防直连备用路径，保护 Profile，注册取决于受管设备状态，分开厂商/管理员。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-12.7-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "12.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-12.7-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "12.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-12.7-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "12.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-12.7-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "12.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the network inventory, architecture, configuration, and policy authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在网络清单、架构、配置与策略权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-12.7-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "12.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Implement the explicit state machine requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-12.7-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "12.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Implement the explicit state machine requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-12.7-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "12.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-12.7-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "12.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-12.7-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "12.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-12.7-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "12.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-12.7-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "12.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in network devices, virtual and cloud networking, topology, trust zones, routes, management planes, remote access, AAA, and administrative workstations; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 网络设备、虚拟与云网络、拓扑、信任区、路由、管理平面、远程访问、AAA 和管理工作站 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-12.7-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "12.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; alert before each deadline becomes overdue.",
          "zh": "为“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-12.7-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "12.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated; alert before each deadline becomes overdue.",
          "zh": "为“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-12.7-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "12.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “The CAS final operation labels the intersection M1 instead of M11, so literal automation overwrites the denominator.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“CAS 最后交集写成 M1 而非 M11，照抄会覆盖分母。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-12.7-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "12.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-12.7-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "12.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-12.7-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "12.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-12.7-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "12.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat shadow links, overlapping address space, overlays, provider abstractions, unsupported protocols, emergency consoles, remote devices, stale diagrams, and asymmetric routes as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 影子链路、重叠地址、覆盖网络、提供商抽象、不支持协议、紧急控制台、远程设备、陈旧架构图和非对称路由 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-12.7-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "12.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Treat IPv6, overlays, east-west paths, remote and roaming devices, direct egress, alternate resolvers, QUIC, asymmetric routes, provider abstraction, and emergency consoles as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 IPv6、覆盖网络、东西向路径、远程与漫游设备、直接出口、替代解析器、QUIC、非对称路由、提供商抽象和紧急控制台 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-12.7-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "12.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Treat shared and service identities, nested groups, direct grants, cached sessions, federation gaps, recovery channels, API keys, emergency access, and provider support as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 共享与服务身份、嵌套组、直接授权、缓存会话、联邦缺口、恢复通道、API 密钥、紧急访问和提供商支持 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-12.7-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "12.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Connect approved/unapproved devices and identities through primary, fallback and alternate protocols; verify pre-auth isolation, AAA decision, destination scope, logs and session termination after revocation.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“用批准/未批准设备和身份走主、备、替代协议，验证预认证隔离、AAA、目的范围、日志和撤销后终止；只计算真实私有资源路径同时经过两项控制的远程资产。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-12.7-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "12.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-12.7-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "12.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 3 pinned CAS metric branch(es), 17 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 3 个指标分支、17 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-12.7-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "12.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-12.7-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "12.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the network inventory, architecture, configuration, and policy authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以网络清单、架构、配置与策略权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-12.7-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "12.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Publish known, unknown, allowed, denied, shadow, bypassed, asymmetric, stale-rule, exception, and unobserved paths with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已知、未知、允许、拒绝、影子、绕过、非对称、陈旧规则、例外和未观测路径，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-12.7-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "12.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Publish requested, approved, effective, excessive, orphaned, stale, emergency, revoked-but-active, and independently reviewed rights with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 申请、批准、实际、过度、孤儿、陈旧、紧急、已撤销仍活跃及独立复核权限，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-12.7-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "12.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-12.7-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "12.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-12.7-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "12.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-12.7-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "12.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-12.7-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "12.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the network inventory, architecture, configuration, and policy authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护网络清单、架构、配置与策略权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-12.7-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "12.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Restrict authority to change requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-12.7-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "12.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Restrict authority to change requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-12.7-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "12.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-12.7-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "12.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-12.7-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "12.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-12.7-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "12.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-12.7-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "12.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise approved and rogue paths, management protocol downgrade, AAA loss, VPN split paths, route and firewall rollback, provider change, and dedicated admin workstation compromise through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 获批与异常路径、管理协议降级、AAA 丢失、VPN 分流、路由与防火墙回滚、提供商变化和专用管理工作站失陷，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-12.7-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "12.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Run the positive control an approved flow over the required secure management or business path; exercise negative, stale, duplicate, bypass, and outage controls including an unapproved route, protocol downgrade, direct egress, alternate DNS/QUIC path, segmentation bypass, AAA loss, stale rule, and rollback failure.",
          "zh": "运行正向控制“通过规定安全管理或业务路径的一项获批流量”，并执行包含“未批准路由、协议降级、直接出口、替代 DNS/QUIC 路径、分段绕过、AAA 丢失、陈旧规则和回滚失败”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-12.7-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "12.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Run the positive control an authorized identity using the required assurance and least privilege; exercise negative, stale, duplicate, bypass, and outage controls including an unauthorized identity, missing factor, stale session, direct grant, inherited excess, revoked token, and recovery bypass.",
          "zh": "运行正向控制“使用所需保证级别和最小权限的授权身份”，并执行包含“未授权身份、缺失认证因子、陈旧会话、直接授权、继承过权、已撤销令牌和恢复绕过”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-12.7-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "12.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-12.7-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "12.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-12.7-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "12.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-12.7-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "12.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-12.7-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "12.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever device and cloud inventories, controllers, configuration backups, IaC, diagrams, routing and firewall state, AAA, VPN, flow data, and change records change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 设备与云清单、控制器、配置备份、IaC、架构图、路由与防火墙状态、AAA、VPN、流量数据和变更记录 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-12.7-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "12.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Use known, unknown, allowed, denied, shadow, bypassed, asymmetric, stale-rule, exception, and unobserved paths to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已知、未知、允许、拒绝、影子、绕过、非对称、陈旧规则、例外和未观测路径 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-12.7-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "12.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Use requested, approved, effective, excessive, orphaned, stale, emergency, revoked-but-active, and independently reviewed rights to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 申请、批准、实际、过度、孤儿、陈旧、紧急、已撤销仍活跃及独立复核权限 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "12.8",
      "control": 12,
      "title_en": "Establish and Maintain Dedicated Computing Resources for All Administrative Work",
      "title_zh": "专用管理计算环境",
      "first_ig": 3,
      "implementation_groups": [
        3
      ],
      "asset_class": "Devices",
      "security_function": "Protect",
      "patterns": [
        "network"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "1.1",
          "4.2"
        ],
        "variables": [
          "GV1",
          "GV37",
          "M1",
          "M2",
          "M3",
          "M4",
          "M5",
          "M6"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "Include every workstation, virtual desktop, bastion or isolated browser/terminal used for privileged work.",
          "build": "Issue hardened privileged access workstations or dedicated virtual sessions, restrict software and destinations, use separate admin identities/MFA, prevent email/web/productivity use and mediate files/updates.",
          "proof": "Attempt general Internet, email, unapproved software, user-network and direct management access from both privileged and ordinary workstations.",
          "boundary": "A second VM on the same compromised daily endpoint offers weak separation unless host and credential risk are addressed."
        },
        "zh": {
          "scope": "包括用于特权工作的工作站、VDI、跳板或隔离浏览/终端。",
          "build": "发放加固 PAW 或专用虚拟会话，限制软件与目的，使用独立管理员身份/MFA，禁止邮件/Web/办公并中介文件/更新；保护启动、设备、剪贴板和凭据边界，监测会话。",
          "proof": "分别从特权和普通工作站尝试通用互联网、邮件、未批准软件、用户网和直连管理；只允许批准管理目标和受控更新，检查 DNS、代理、剪贴板、磁盘和浏览器逃逸。",
          "boundary": "在同一已污染日常主机开第二 VM，除非 Host/凭据风险受控，否则隔离很弱。"
        }
      },
      "category_counts": {
        "outcome": 6,
        "scope": 6,
        "ownership": 6,
        "data": 6,
        "integration": 6,
        "control": 6,
        "timing": 6,
        "exception": 6,
        "evidence": 6,
        "security": 6,
        "testing": 6,
        "operations": 6
      },
      "requirement_count": 72,
      "requirements": [
        {
          "code": "CIS-12.8-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "12.8",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Establish and Maintain Dedicated Computing Resources for All Administrative Work; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“专用管理计算环境”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-12.8-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "12.8",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 12.8, official Asset Class Devices, Security Function Protect, and IG3 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 12.8、官方资产类别“设备”、安全功能“保护”和首次出现的 IG3，并保存来源抓取日期。"
        },
        {
          "code": "CIS-12.8-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "12.8",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Include every workstation, virtual desktop, bastion or isolated browser/terminal used for privileged work.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“包括用于特权工作的工作站、VDI、跳板或隔离浏览/终端。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-12.8-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "12.8",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-12.8-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "12.8",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Establish and Maintain Dedicated Computing Resources for All Administrative Work to its operating object—network devices, virtual and cloud networking, topology, trust zones, routes, management planes, remote access, AAA, and administrative workstations—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“专用管理计算环境”连接到其运营对象——网络设备、虚拟与云网络、拓扑、信任区、路由、管理平面、远程访问、AAA 和管理工作站——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-12.8-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "12.8",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "For Establish and Maintain Dedicated Computing Resources for All Administrative Work, express success as an observable decision over intended connectivity, trust zone, route, protocol, identity, management path, traffic decision, and observed outcome; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“专用管理计算环境”，以 预期连接、信任区、路由、协议、身份、管理路径、流量决策和观察结果 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-12.8-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "12.8",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-12.8-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "12.8",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-12.8-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "12.8",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-12.8-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "12.8",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-12.8-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "12.8",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across shadow links, overlapping address space, overlays, provider abstractions, unsupported protocols, emergency consoles, remote devices, stale diagrams, and asymmetric routes; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 影子链路、重叠地址、覆盖网络、提供商抽象、不支持协议、紧急控制台、远程设备、陈旧架构图和非对称路由 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-12.8-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "12.8",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Include IPv6, overlays, east-west paths, remote and roaming devices, direct egress, alternate resolvers, QUIC, asymmetric routes, provider abstraction, and emergency consoles in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 IPv6、覆盖网络、东西向路径、远程与漫游设备、直接出口、替代解析器、QUIC、非对称路由、提供商抽象和紧急控制台 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-12.8-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "12.8",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-12.8-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "12.8",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-12.8-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "12.8",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-12.8-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "12.8",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-12.8-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "12.8",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind network and cloud engineering, security architecture, identity, service owners, operations, and change management to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 网络与云工程、安全架构、身份、服务责任人、运营和变更管理 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-12.8-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "12.8",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Name who may transition requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-12.8-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "12.8",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-12.8-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "12.8",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-12.8-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "12.8",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV1, GV37, M1, M2, M3, M4, M5, M6) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV1, GV37, M1, M2, M3, M4, M5, M6）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-12.8-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "12.8",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-12.8-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "12.8",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the network inventory, architecture, configuration, and policy authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把网络清单、架构、配置与策略权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-12.8-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "12.8",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired.",
          "zh": "对生命周期“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-12.8-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "12.8",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 1.1, Safeguard 4.2; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 1.1、Safeguard 4.2 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-12.8-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "12.8",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-12.8-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "12.8",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-12.8-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "12.8",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-12.8-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "12.8",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile device and cloud inventories, controllers, configuration backups, IaC, diagrams, routing and firewall state, AAA, VPN, flow data, and change records and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 设备与云清单、控制器、配置备份、IaC、架构图、路由与防火墙状态、AAA、VPN、流量数据和变更记录，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-12.8-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "12.8",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Require every connector carrying intended connectivity, trust zone, route, protocol, identity, management path, traffic decision, and observed outcome to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 预期连接、信任区、路由、协议、身份、管理路径、流量决策和观察结果 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-12.8-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "12.8",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Issue hardened privileged access workstations or dedicated virtual sessions, restrict software and destinations, use separate admin identities/MFA, prevent email/web/productivity use and mediate files/updates.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“发放加固 PAW 或专用虚拟会话，限制软件与目的，使用独立管理员身份/MFA，禁止邮件/Web/办公并中介文件/更新；保护启动、设备、剪贴板和凭据边界，监测会话。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-12.8-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "12.8",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-12.8-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "12.8",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-12.8-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "12.8",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-12.8-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "12.8",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the network inventory, architecture, configuration, and policy authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在网络清单、架构、配置与策略权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-12.8-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "12.8",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Implement the explicit state machine requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-12.8-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "12.8",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-12.8-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "12.8",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-12.8-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "12.8",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-12.8-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "12.8",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-12.8-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "12.8",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in network devices, virtual and cloud networking, topology, trust zones, routes, management planes, remote access, AAA, and administrative workstations; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 网络设备、虚拟与云网络、拓扑、信任区、路由、管理平面、远程访问、AAA 和管理工作站 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-12.8-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "12.8",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; alert before each deadline becomes overdue.",
          "zh": "为“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-12.8-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "12.8",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “A second VM on the same compromised daily endpoint offers weak separation unless host and credential risk are addressed.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“在同一已污染日常主机开第二 VM，除非 Host/凭据风险受控，否则隔离很弱。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-12.8-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "12.8",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-12.8-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "12.8",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-12.8-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "12.8",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-12.8-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "12.8",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat shadow links, overlapping address space, overlays, provider abstractions, unsupported protocols, emergency consoles, remote devices, stale diagrams, and asymmetric routes as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 影子链路、重叠地址、覆盖网络、提供商抽象、不支持协议、紧急控制台、远程设备、陈旧架构图和非对称路由 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-12.8-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "12.8",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Treat IPv6, overlays, east-west paths, remote and roaming devices, direct egress, alternate resolvers, QUIC, asymmetric routes, provider abstraction, and emergency consoles as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 IPv6、覆盖网络、东西向路径、远程与漫游设备、直接出口、替代解析器、QUIC、非对称路由、提供商抽象和紧急控制台 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-12.8-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "12.8",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Attempt general Internet, email, unapproved software, user-network and direct management access from both privileged and ordinary workstations.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“分别从特权和普通工作站尝试通用互联网、邮件、未批准软件、用户网和直连管理；只允许批准管理目标和受控更新，检查 DNS、代理、剪贴板、磁盘和浏览器逃逸。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-12.8-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "12.8",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-12.8-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "12.8",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 8 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、8 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-12.8-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "12.8",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-12.8-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "12.8",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the network inventory, architecture, configuration, and policy authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以网络清单、架构、配置与策略权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-12.8-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "12.8",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Publish known, unknown, allowed, denied, shadow, bypassed, asymmetric, stale-rule, exception, and unobserved paths with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已知、未知、允许、拒绝、影子、绕过、非对称、陈旧规则、例外和未观测路径，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-12.8-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "12.8",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-12.8-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "12.8",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-12.8-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "12.8",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-12.8-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "12.8",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-12.8-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "12.8",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the network inventory, architecture, configuration, and policy authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护网络清单、架构、配置与策略权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-12.8-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "12.8",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Restrict authority to change requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-12.8-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "12.8",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-12.8-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "12.8",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-12.8-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "12.8",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-12.8-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "12.8",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-12.8-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "12.8",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise approved and rogue paths, management protocol downgrade, AAA loss, VPN split paths, route and firewall rollback, provider change, and dedicated admin workstation compromise through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 获批与异常路径、管理协议降级、AAA 丢失、VPN 分流、路由与防火墙回滚、提供商变化和专用管理工作站失陷，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-12.8-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "12.8",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Run the positive control an approved flow over the required secure management or business path; exercise negative, stale, duplicate, bypass, and outage controls including an unapproved route, protocol downgrade, direct egress, alternate DNS/QUIC path, segmentation bypass, AAA loss, stale rule, and rollback failure.",
          "zh": "运行正向控制“通过规定安全管理或业务路径的一项获批流量”，并执行包含“未批准路由、协议降级、直接出口、替代 DNS/QUIC 路径、分段绕过、AAA 丢失、陈旧规则和回滚失败”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-12.8-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "12.8",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-12.8-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "12.8",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-12.8-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "12.8",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-12.8-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "12.8",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-12.8-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "12.8",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever device and cloud inventories, controllers, configuration backups, IaC, diagrams, routing and firewall state, AAA, VPN, flow data, and change records change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 设备与云清单、控制器、配置备份、IaC、架构图、路由与防火墙状态、AAA、VPN、流量数据和变更记录 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-12.8-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "12.8",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Use known, unknown, allowed, denied, shadow, bypassed, asymmetric, stale-rule, exception, and unobserved paths to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已知、未知、允许、拒绝、影子、绕过、非对称、陈旧规则、例外和未观测路径 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "13.1",
      "control": 13,
      "title_en": "Centralize Security Event Alerting",
      "title_zh": "安全告警集中化",
      "first_ig": 2,
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Network",
      "security_function": "Detect",
      "patterns": [
        "telemetry"
      ],
      "expanded_complexity": true,
      "cas_context": {
        "dependencies": [
          "1.1",
          "2.1"
        ],
        "variables": [
          "GV1",
          "GV42",
          "M1",
          "M2",
          "M3",
          "M4"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "Central alerting covers security-relevant events from endpoint, identity, network, cloud/SaaS, application, data and provider sources, including source-health alerts.",
          "build": "Route normalized high-value alerts to a SIEM or equivalent analytics platform, map stable asset/account identities, assign severity, owner, playbook and SLO, deduplicate without losing scope and monitor rule/source health.",
          "proof": "Generate cross-source canary behavior and verify correlation, case creation, enrichment, analyst decision and response; then stop one source and break one parser.",
          "boundary": "Central logs without security rules do not satisfy alerting, and vendor defaults rarely reflect local architecture."
        },
        "zh": {
          "scope": "集中告警覆盖终端、身份、网络、云/SaaS、应用、数据和服务商的安全事件，也包括源健康。",
          "build": "把归一高价值告警送 SIEM/分析平台，映射稳定资产/账户身份，设严重度、责任人、Playbook 和 SLO；去重但不丢范围，监测规则/来源健康，并分离检测工程、平台管理和案件处置。",
          "proof": "生成跨源金丝雀行为，验证关联、开案、富化、分析决定和响应；再停一个源、破一个 Parser。",
          "boundary": "中央有日志但无安全规则，不满足告警；厂商默认很少贴合本地架构。"
        }
      },
      "category_counts": {
        "outcome": 7,
        "scope": 7,
        "ownership": 7,
        "data": 7,
        "integration": 7,
        "control": 7,
        "timing": 7,
        "exception": 7,
        "evidence": 7,
        "security": 7,
        "testing": 7,
        "operations": 7
      },
      "requirement_count": 84,
      "requirements": [
        {
          "code": "CIS-13.1-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "13.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Centralize Security Event Alerting; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“安全告警集中化”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-13.1-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "13.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 13.1, official Asset Class Network, Security Function Detect, and IG2 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 13.1、官方资产类别“网络”、安全功能“检测”和首次出现的 IG2，并保存来源抓取日期。"
        },
        {
          "code": "CIS-13.1-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "13.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Central alerting covers security-relevant events from endpoint, identity, network, cloud/SaaS, application, data and provider sources, including source-health alerts.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“集中告警覆盖终端、身份、网络、云/SaaS、应用、数据和服务商的安全事件，也包括源健康。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-13.1-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "13.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-13.1-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "13.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Centralize Security Event Alerting to its operating object—host, network, cloud, identity, application, and provider security signals, detections, prevention decisions, traffic boundaries, and response handoffs—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“安全告警集中化”连接到其运营对象——主机、网络、云、身份、应用和提供商安全信号、检测、阻断决策、流量边界和响应交接——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-13.1-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "13.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "For Centralize Security Event Alerting, express success as an observable decision over complete, attributable, timely, protected, searchable, and actionable security telemetry plus source health; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“安全告警集中化”，以 完整、可归因、及时、受保护、可检索、可行动的安全遥测及来源健康 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-13.1-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "13.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "For the expanded Centralize Security Event Alerting scope, resolve conflicts among security, safety, privacy, legal, availability, customer, and operational objectives through an explicit risk decision.",
          "zh": "对“安全告警集中化”的扩展范围，通过显式风险决策解决安全、安全生产、隐私、法律、可用性、客户和运营目标冲突。"
        },
        {
          "code": "CIS-13.1-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "13.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-13.1-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "13.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-13.1-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "13.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-13.1-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "13.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-13.1-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "13.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across encrypted traffic, east-west and overlay paths, sensor blind spots, duplicate alerts, stale rules, threshold drift, provider outages, bypass protocols, and unsafe prevention; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 加密流量、东西向与覆盖路径、传感器盲区、重复告警、陈旧规则、阈值漂移、提供商中断、绕过协议和不安全阻断 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-13.1-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "13.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Include clock skew, actor loss, field truncation, parser drift, dropped or duplicate events, privacy redaction, provider gaps, encrypted paths, quota, and archive failure in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 时钟偏移、行为者丢失、字段截断、解析漂移、事件丢失或重复、隐私脱敏、提供商缺口、加密路径、配额和归档故障 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-13.1-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "13.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Define nested scope at enterprise, business service, tenant, environment, platform, object, identity, data set, and transaction levels; prohibit a parent result from hiding a failing child.",
          "zh": "按企业、业务服务、租户、环境、平台、对象、身份、数据集和交易定义嵌套范围，禁止父级结果遮蔽失败子级。"
        },
        {
          "code": "CIS-13.1-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "13.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-13.1-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "13.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-13.1-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "13.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-13.1-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "13.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-13.1-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "13.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind detection and security operations, endpoint/network/cloud engineering, threat intelligence, incident response, service owners, and risk owners to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 检测与安全运营、终端/网络/云工程、威胁情报、事件响应、服务责任人和风险责任人 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-13.1-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "13.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Name who may transition event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-13.1-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "13.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Model delegated authority, quorum or dual approval where warranted, escalation deadlines, provider handoffs, conflict resolution, and executive risk acceptance.",
          "zh": "建模委派权限、必要时的双人或法定人数审批、升级期限、提供商交接、冲突解决和管理层风险接受。"
        },
        {
          "code": "CIS-13.1-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "13.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-13.1-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "13.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-13.1-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "13.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV1, GV42, M1, M2, M3, M4) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV1, GV42, M1, M2, M3, M4）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-13.1-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "13.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-13.1-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "13.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the monitored-surface inventory, detection content, threshold, and alert-case authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把受监测面清单、检测内容、阈值与告警案件权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-13.1-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "13.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired.",
          "zh": "对生命周期“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-13.1-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "13.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Version schemas and state transitions with migration, backfill, deduplication, lineage, historical denominator, deletion, and rollback semantics.",
          "zh": "对模式和状态转换做版本管理，定义迁移、回填、去重、血缘、历史分母、删除和回滚语义。"
        },
        {
          "code": "CIS-13.1-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "13.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 1.1, Safeguard 2.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 1.1、Safeguard 2.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-13.1-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "13.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-13.1-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "13.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-13.1-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "13.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-13.1-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "13.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile EDR/NDR/IDS/IPS, network and cloud flow, firewalls, NAC, identity, applications, providers, threat intelligence, SIEM, and case management and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 EDR/NDR/IDS/IPS、网络与云流量、防火墙、NAC、身份、应用、提供商、威胁情报、SIEM 和案件管理，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-13.1-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "13.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Require every connector carrying complete, attributable, timely, protected, searchable, and actionable security telemetry plus source health to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 完整、可归因、及时、受保护、可检索、可行动的安全遥测及来源健康 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-13.1-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "13.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Define consistency rules across disagreeing sources, source precedence, confidence, reconciliation queues, dead-letter handling, reprocessing, and end-to-end trace identity.",
          "zh": "定义冲突来源的一致性、优先级、置信度、对账队列、死信、重处理和端到端追踪身份。"
        },
        {
          "code": "CIS-13.1-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "13.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Route normalized high-value alerts to a SIEM or equivalent analytics platform, map stable asset/account identities, assign severity, owner, playbook and SLO, deduplicate without losing scope and monitor rule/source health.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“把归一高价值告警送 SIEM/分析平台，映射稳定资产/账户身份，设严重度、责任人、Playbook 和 SLO；去重但不丢范围，监测规则/来源健康，并分离检测工程、平台管理和案件处置。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-13.1-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "13.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-13.1-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "13.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-13.1-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "13.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-13.1-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "13.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the monitored-surface inventory, detection content, threshold, and alert-case authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在受监测面清单、检测内容、阈值与告警案件权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-13.1-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "13.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Implement the explicit state machine event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-13.1-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "13.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Specify concurrent decisions, partial success, compensating transactions, repeated requests, stale policy, dependency outage, and recovery from an interrupted state transition.",
          "zh": "定义并发决策、部分成功、补偿事务、重复请求、陈旧策略、依赖中断和中途状态转换恢复。"
        },
        {
          "code": "CIS-13.1-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "13.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-13.1-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "13.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-13.1-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "13.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-13.1-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "13.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-13.1-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "13.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in host, network, cloud, identity, application, and provider security signals, detections, prevention decisions, traffic boundaries, and response handoffs; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 主机、网络、云、身份、应用和提供商安全信号、检测、阻断决策、流量边界和响应交接 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-13.1-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "13.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired; alert before each deadline becomes overdue.",
          "zh": "为“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-13.1-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "13.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Allocate an end-to-end SLO budget across discovery, collection, processing, approval, enforcement, verification, and closure; prioritize overdue work by consequence and exposure.",
          "zh": "把端到端 SLO 预算分配到发现、采集、处理、审批、执行、验证和关闭，并按后果与暴露排列逾期工作。"
        },
        {
          "code": "CIS-13.1-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "13.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “Central logs without security rules do not satisfy alerting, and vendor defaults rarely reflect local architecture.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“中央有日志但无安全规则，不满足告警；厂商默认很少贴合本地架构。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-13.1-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "13.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-13.1-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "13.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-13.1-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "13.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-13.1-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "13.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat encrypted traffic, east-west and overlay paths, sensor blind spots, duplicate alerts, stale rules, threshold drift, provider outages, bypass protocols, and unsafe prevention as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 加密流量、东西向与覆盖路径、传感器盲区、重复告警、陈旧规则、阈值漂移、提供商中断、绕过协议和不安全阻断 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-13.1-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "13.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Treat clock skew, actor loss, field truncation, parser drift, dropped or duplicate events, privacy redaction, provider gaps, encrypted paths, quota, and archive failure as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 时钟偏移、行为者丢失、字段截断、解析漂移、事件丢失或重复、隐私脱敏、提供商缺口、加密路径、配额和归档故障 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-13.1-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "13.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Exercise compound failures where an exception, stale source, provider outage, unavailable owner, and degraded control overlap; define one safe command and one accountable decision.",
          "zh": "演练例外、陈旧来源、提供商中断、责任人不可用和控制降级同时出现的复合故障，明确一条安全指令和一个责任决策。"
        },
        {
          "code": "CIS-13.1-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "13.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Generate cross-source canary behavior and verify correlation, case creation, enrichment, analyst decision and response; then stop one source and break one parser.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“生成跨源金丝雀行为，验证关联、开案、富化、分析决定和响应；再停一个源、破一个 Parser。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-13.1-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "13.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-13.1-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "13.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 6 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、6 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-13.1-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "13.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-13.1-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "13.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the monitored-surface inventory, detection content, threshold, and alert-case authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以受监测面清单、检测内容、阈值与告警案件权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-13.1-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "13.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Publish healthy, silent, partial, late, malformed, duplicate, unowned, unreviewed, alerted, investigated, and archived sources or events with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 健康、静默、部分、迟到、畸形、重复、无责任人、未审阅、已告警、已调查和已归档来源或事件，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-13.1-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "13.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Require an independent party to reconstruct the decision from source receipts and reproduce the population, state transition, calculation, test result, exception, and final closure.",
          "zh": "要求独立人员使用来源回执重建决策，并复现总体、状态转换、计算、测试结果、例外和最终关闭。"
        },
        {
          "code": "CIS-13.1-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "13.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-13.1-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "13.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-13.1-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "13.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-13.1-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "13.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-13.1-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "13.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the monitored-surface inventory, detection content, threshold, and alert-case authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护受监测面清单、检测内容、阈值与告警案件权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-13.1-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "13.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Restrict authority to change event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-13.1-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "13.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Threat-model the implementation system itself: forged evidence, poisoned inventory, privilege abuse, cross-tenant confusion, policy rollback, audit deletion, denial of service, and recovery compromise.",
          "zh": "威胁建模实施系统自身：伪造证据、污染清单、权限滥用、跨租户混淆、策略回滚、审计删除、拒绝服务和恢复失陷。"
        },
        {
          "code": "CIS-13.1-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "13.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-13.1-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "13.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-13.1-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "13.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-13.1-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "13.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-13.1-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "13.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise benign and malicious-like canaries, sensor and collector loss, threshold boundaries, segmentation bypass, fail-open/closed behavior, rule rollback, and response escalation through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 安全与恶意特征金丝雀、传感器与采集器丢失、阈值边界、分段绕过、故障开闭、规则回滚和响应升级，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-13.1-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "13.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Run the positive control an allowed and denied canary event traced from source through review; exercise negative, stale, duplicate, bypass, and outage controls including source loss, parser/schema change, time skew, queue overflow, duplicate delivery, provider export outage, missed alert, and unreadable archive.",
          "zh": "运行正向控制“一项允许与拒绝金丝雀事件从来源贯穿到审阅”，并执行包含“来源丢失、解析器/模式变化、时钟偏移、队列溢出、重复投递、提供商导出中断、漏报和归档不可读”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-13.1-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "13.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Build a pairwise platform-and-failure matrix, then add high-consequence multi-factor cases, historical regression, source substitution, red-team challenge, and assessor replay.",
          "zh": "建立平台—故障两两组合矩阵，再加入高后果多因素案例、历史回归、来源替换、红队挑战和评估方重放。"
        },
        {
          "code": "CIS-13.1-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "13.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-13.1-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "13.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-13.1-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "13.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-13.1-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "13.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-13.1-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "13.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever EDR/NDR/IDS/IPS, network and cloud flow, firewalls, NAC, identity, applications, providers, threat intelligence, SIEM, and case management change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 EDR/NDR/IDS/IPS、网络与云流量、防火墙、NAC、身份、应用、提供商、威胁情报、SIEM 和案件管理 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-13.1-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "13.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Use healthy, silent, partial, late, malformed, duplicate, unowned, unreviewed, alerted, investigated, and archived sources or events to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 健康、静默、部分、迟到、畸形、重复、无责任人、未审阅、已告警、已调查和已归档来源或事件 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-13.1-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "13.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Use canary deployment, kill criteria, rollback, backlog burn-down, exception reduction, source-quality targets, quarterly design review, and a measurable retirement plan.",
          "zh": "采用金丝雀、停止标准、回滚、积压燃尽、例外缩减、来源质量目标、季度设计复核和可量化退役计划。"
        }
      ]
    },
    {
      "id": "13.2",
      "control": 13,
      "title_en": "Deploy a Host-Based Intrusion Detection Solution",
      "title_zh": "主机入侵检测",
      "first_ig": 2,
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Devices",
      "security_function": "Detect",
      "patterns": [
        "telemetry"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "1.1",
          "2.1"
        ],
        "variables": [
          "GV1",
          "GV5",
          "M1",
          "M2",
          "M3"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "Eligible assets are endpoints, servers and workloads where host telemetry can detect unauthorized change or behavior, including file/process, identity, configuration and integrity signals.",
          "build": "Deploy HIDS/EDR or platform-native telemetry with protected sensors, tuned rules, central health and alert routing.",
          "proof": "Modify a monitored benign file/configuration, simulate safe suspicious process behavior and stop the agent; verify detection, identity, context, alert and analyst action.",
          "boundary": "Installed software is the only thing CAS measures, so a silent or untuned agent can pass."
        },
        "zh": {
          "scope": "适用资产是能用主机遥测发现未授权变化/行为的终端、服务器和工作负载，包括文件/进程、身份、配置、完整性。",
          "build": "部署 HIDS/EDR 或原生遥测，保护 Sensor、调优规则、集中健康/告警；为关键文件/配置和可疑行为建基线，关联资产角色并留足调查证据。",
          "proof": "修改受监控无害文件/配置，安全模拟可疑进程，再停 Agent，验证发现、身份、上下文、告警与分析动作；以近期健康且规则实测的资产/合格资产为覆盖，另列 Blind/Degraded。",
          "boundary": "CAS 只测软件安装，静默或未调优 Agent 也可通过。"
        }
      },
      "category_counts": {
        "outcome": 6,
        "scope": 6,
        "ownership": 6,
        "data": 6,
        "integration": 6,
        "control": 6,
        "timing": 6,
        "exception": 6,
        "evidence": 6,
        "security": 6,
        "testing": 6,
        "operations": 6
      },
      "requirement_count": 72,
      "requirements": [
        {
          "code": "CIS-13.2-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "13.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Deploy a Host-Based Intrusion Detection Solution; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“主机入侵检测”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-13.2-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "13.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 13.2, official Asset Class Devices, Security Function Detect, and IG2 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 13.2、官方资产类别“设备”、安全功能“检测”和首次出现的 IG2，并保存来源抓取日期。"
        },
        {
          "code": "CIS-13.2-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "13.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Eligible assets are endpoints, servers and workloads where host telemetry can detect unauthorized change or behavior, including file/process, identity, configuration and integrity signals.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“适用资产是能用主机遥测发现未授权变化/行为的终端、服务器和工作负载，包括文件/进程、身份、配置、完整性。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-13.2-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "13.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-13.2-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "13.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Deploy a Host-Based Intrusion Detection Solution to its operating object—host, network, cloud, identity, application, and provider security signals, detections, prevention decisions, traffic boundaries, and response handoffs—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“主机入侵检测”连接到其运营对象——主机、网络、云、身份、应用和提供商安全信号、检测、阻断决策、流量边界和响应交接——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-13.2-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "13.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "For Deploy a Host-Based Intrusion Detection Solution, express success as an observable decision over complete, attributable, timely, protected, searchable, and actionable security telemetry plus source health; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“主机入侵检测”，以 完整、可归因、及时、受保护、可检索、可行动的安全遥测及来源健康 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-13.2-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "13.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-13.2-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "13.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-13.2-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "13.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-13.2-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "13.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-13.2-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "13.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across encrypted traffic, east-west and overlay paths, sensor blind spots, duplicate alerts, stale rules, threshold drift, provider outages, bypass protocols, and unsafe prevention; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 加密流量、东西向与覆盖路径、传感器盲区、重复告警、陈旧规则、阈值漂移、提供商中断、绕过协议和不安全阻断 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-13.2-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "13.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Include clock skew, actor loss, field truncation, parser drift, dropped or duplicate events, privacy redaction, provider gaps, encrypted paths, quota, and archive failure in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 时钟偏移、行为者丢失、字段截断、解析漂移、事件丢失或重复、隐私脱敏、提供商缺口、加密路径、配额和归档故障 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-13.2-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "13.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-13.2-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "13.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-13.2-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "13.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-13.2-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "13.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-13.2-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "13.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind detection and security operations, endpoint/network/cloud engineering, threat intelligence, incident response, service owners, and risk owners to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 检测与安全运营、终端/网络/云工程、威胁情报、事件响应、服务责任人和风险责任人 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-13.2-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "13.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Name who may transition event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-13.2-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "13.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-13.2-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "13.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-13.2-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "13.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV1, GV5, M1, M2, M3) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV1, GV5, M1, M2, M3）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-13.2-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "13.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-13.2-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "13.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the monitored-surface inventory, detection content, threshold, and alert-case authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把受监测面清单、检测内容、阈值与告警案件权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-13.2-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "13.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired.",
          "zh": "对生命周期“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-13.2-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "13.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 1.1, Safeguard 2.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 1.1、Safeguard 2.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-13.2-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "13.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-13.2-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "13.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-13.2-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "13.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-13.2-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "13.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile EDR/NDR/IDS/IPS, network and cloud flow, firewalls, NAC, identity, applications, providers, threat intelligence, SIEM, and case management and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 EDR/NDR/IDS/IPS、网络与云流量、防火墙、NAC、身份、应用、提供商、威胁情报、SIEM 和案件管理，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-13.2-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "13.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Require every connector carrying complete, attributable, timely, protected, searchable, and actionable security telemetry plus source health to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 完整、可归因、及时、受保护、可检索、可行动的安全遥测及来源健康 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-13.2-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "13.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Deploy HIDS/EDR or platform-native telemetry with protected sensors, tuned rules, central health and alert routing.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“部署 HIDS/EDR 或原生遥测，保护 Sensor、调优规则、集中健康/告警；为关键文件/配置和可疑行为建基线，关联资产角色并留足调查证据。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-13.2-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "13.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-13.2-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "13.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-13.2-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "13.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-13.2-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "13.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the monitored-surface inventory, detection content, threshold, and alert-case authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在受监测面清单、检测内容、阈值与告警案件权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-13.2-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "13.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Implement the explicit state machine event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-13.2-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "13.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-13.2-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "13.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-13.2-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "13.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-13.2-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "13.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-13.2-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "13.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in host, network, cloud, identity, application, and provider security signals, detections, prevention decisions, traffic boundaries, and response handoffs; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 主机、网络、云、身份、应用和提供商安全信号、检测、阻断决策、流量边界和响应交接 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-13.2-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "13.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired; alert before each deadline becomes overdue.",
          "zh": "为“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-13.2-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "13.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “Installed software is the only thing CAS measures, so a silent or untuned agent can pass.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“CAS 只测软件安装，静默或未调优 Agent 也可通过。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-13.2-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "13.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-13.2-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "13.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-13.2-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "13.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-13.2-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "13.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat encrypted traffic, east-west and overlay paths, sensor blind spots, duplicate alerts, stale rules, threshold drift, provider outages, bypass protocols, and unsafe prevention as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 加密流量、东西向与覆盖路径、传感器盲区、重复告警、陈旧规则、阈值漂移、提供商中断、绕过协议和不安全阻断 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-13.2-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "13.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Treat clock skew, actor loss, field truncation, parser drift, dropped or duplicate events, privacy redaction, provider gaps, encrypted paths, quota, and archive failure as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 时钟偏移、行为者丢失、字段截断、解析漂移、事件丢失或重复、隐私脱敏、提供商缺口、加密路径、配额和归档故障 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-13.2-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "13.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Modify a monitored benign file/configuration, simulate safe suspicious process behavior and stop the agent; verify detection, identity, context, alert and analyst action.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“修改受监控无害文件/配置，安全模拟可疑进程，再停 Agent，验证发现、身份、上下文、告警与分析动作；以近期健康且规则实测的资产/合格资产为覆盖，另列 Blind/Degraded。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-13.2-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "13.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-13.2-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "13.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 5 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、5 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-13.2-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "13.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-13.2-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "13.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the monitored-surface inventory, detection content, threshold, and alert-case authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以受监测面清单、检测内容、阈值与告警案件权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-13.2-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "13.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Publish healthy, silent, partial, late, malformed, duplicate, unowned, unreviewed, alerted, investigated, and archived sources or events with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 健康、静默、部分、迟到、畸形、重复、无责任人、未审阅、已告警、已调查和已归档来源或事件，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-13.2-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "13.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-13.2-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "13.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-13.2-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "13.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-13.2-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "13.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-13.2-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "13.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the monitored-surface inventory, detection content, threshold, and alert-case authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护受监测面清单、检测内容、阈值与告警案件权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-13.2-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "13.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Restrict authority to change event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-13.2-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "13.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-13.2-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "13.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-13.2-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "13.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-13.2-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "13.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-13.2-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "13.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise benign and malicious-like canaries, sensor and collector loss, threshold boundaries, segmentation bypass, fail-open/closed behavior, rule rollback, and response escalation through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 安全与恶意特征金丝雀、传感器与采集器丢失、阈值边界、分段绕过、故障开闭、规则回滚和响应升级，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-13.2-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "13.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Run the positive control an allowed and denied canary event traced from source through review; exercise negative, stale, duplicate, bypass, and outage controls including source loss, parser/schema change, time skew, queue overflow, duplicate delivery, provider export outage, missed alert, and unreadable archive.",
          "zh": "运行正向控制“一项允许与拒绝金丝雀事件从来源贯穿到审阅”，并执行包含“来源丢失、解析器/模式变化、时钟偏移、队列溢出、重复投递、提供商导出中断、漏报和归档不可读”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-13.2-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "13.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-13.2-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "13.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-13.2-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "13.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-13.2-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "13.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-13.2-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "13.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever EDR/NDR/IDS/IPS, network and cloud flow, firewalls, NAC, identity, applications, providers, threat intelligence, SIEM, and case management change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 EDR/NDR/IDS/IPS、网络与云流量、防火墙、NAC、身份、应用、提供商、威胁情报、SIEM 和案件管理 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-13.2-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "13.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Use healthy, silent, partial, late, malformed, duplicate, unowned, unreviewed, alerted, investigated, and archived sources or events to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 健康、静默、部分、迟到、畸形、重复、无责任人、未审阅、已告警、已调查和已归档来源或事件 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "13.3",
      "control": 13,
      "title_en": "Deploy a Network Intrusion Detection Solution",
      "title_zh": "网络入侵检测",
      "first_ig": 2,
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Network",
      "security_function": "Detect",
      "patterns": [
        "telemetry",
        "network"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "1.1",
          "12.4"
        ],
        "variables": [
          "GV4",
          "GV35",
          "M1",
          "M2",
          "M3"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "The coverage population is risk-relevant boundaries and internal chokepoints across Internet, cloud, data center, campus, wireless, remote, partner and sensitive east-west paths.",
          "build": "Place NIDS or cloud-native equivalents from architecture and threat paths, engineer taps/mirrors/flow, manage signatures and analytics, decrypt only where lawful/needed, centralize alerts and monitor packet loss, asymmetry, clock and sensor health.",
          "proof": "Replay safe protocol and detection fixtures from both directions at representative boundaries; verify packet visibility, decoding, alert and source/destination attribution.",
          "boundary": "CAS counts covered boundaries without verifying traffic reaches a sensor."
        },
        "zh": {
          "scope": "覆盖互联网、云、数据中心、园区、无线、远程、伙伴和敏感东西向的风险边界/关键点。",
          "build": "按架构与威胁路径布置 NIDS/云等效物，正确设计 TAP/Mirror/Flow，管理签名和分析；仅在合法必要时解密，集中告警，并监测丢包、非对称、时钟和 Sensor 健康。",
          "proof": "从双向在代表边界回放安全协议/检测 Fixture，验证流量可见、解码、告警与源目的归因；测试高流量丢失、加密和故障转移。",
          "boundary": "CAS 数边界覆盖却不证流量进入 Sensor。"
        }
      },
      "category_counts": {
        "outcome": 7,
        "scope": 7,
        "ownership": 7,
        "data": 7,
        "integration": 7,
        "control": 7,
        "timing": 7,
        "exception": 7,
        "evidence": 7,
        "security": 7,
        "testing": 7,
        "operations": 7
      },
      "requirement_count": 84,
      "requirements": [
        {
          "code": "CIS-13.3-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "13.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Deploy a Network Intrusion Detection Solution; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“网络入侵检测”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-13.3-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "13.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 13.3, official Asset Class Network, Security Function Detect, and IG2 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 13.3、官方资产类别“网络”、安全功能“检测”和首次出现的 IG2，并保存来源抓取日期。"
        },
        {
          "code": "CIS-13.3-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "13.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “The coverage population is risk-relevant boundaries and internal chokepoints across Internet, cloud, data center, campus, wireless, remote, partner and sensitive east-west paths.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“覆盖互联网、云、数据中心、园区、无线、远程、伙伴和敏感东西向的风险边界/关键点。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-13.3-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "13.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-13.3-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "13.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Deploy a Network Intrusion Detection Solution to its operating object—host, network, cloud, identity, application, and provider security signals, detections, prevention decisions, traffic boundaries, and response handoffs—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“网络入侵检测”连接到其运营对象——主机、网络、云、身份、应用和提供商安全信号、检测、阻断决策、流量边界和响应交接——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-13.3-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "13.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "For Deploy a Network Intrusion Detection Solution, express success as an observable decision over complete, attributable, timely, protected, searchable, and actionable security telemetry plus source health; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“网络入侵检测”，以 完整、可归因、及时、受保护、可检索、可行动的安全遥测及来源健康 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-13.3-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "13.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "For Deploy a Network Intrusion Detection Solution, express success as an observable decision over intended connectivity, trust zone, route, protocol, identity, management path, traffic decision, and observed outcome; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“网络入侵检测”，以 预期连接、信任区、路由、协议、身份、管理路径、流量决策和观察结果 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-13.3-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "13.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-13.3-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "13.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-13.3-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "13.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-13.3-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "13.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-13.3-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "13.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across encrypted traffic, east-west and overlay paths, sensor blind spots, duplicate alerts, stale rules, threshold drift, provider outages, bypass protocols, and unsafe prevention; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 加密流量、东西向与覆盖路径、传感器盲区、重复告警、陈旧规则、阈值漂移、提供商中断、绕过协议和不安全阻断 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-13.3-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "13.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Include clock skew, actor loss, field truncation, parser drift, dropped or duplicate events, privacy redaction, provider gaps, encrypted paths, quota, and archive failure in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 时钟偏移、行为者丢失、字段截断、解析漂移、事件丢失或重复、隐私脱敏、提供商缺口、加密路径、配额和归档故障 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-13.3-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "13.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Include IPv6, overlays, east-west paths, remote and roaming devices, direct egress, alternate resolvers, QUIC, asymmetric routes, provider abstraction, and emergency consoles in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 IPv6、覆盖网络、东西向路径、远程与漫游设备、直接出口、替代解析器、QUIC、非对称路由、提供商抽象和紧急控制台 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-13.3-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "13.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-13.3-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "13.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-13.3-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "13.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-13.3-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "13.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-13.3-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "13.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind detection and security operations, endpoint/network/cloud engineering, threat intelligence, incident response, service owners, and risk owners to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 检测与安全运营、终端/网络/云工程、威胁情报、事件响应、服务责任人和风险责任人 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-13.3-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "13.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Name who may transition event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-13.3-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "13.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Name who may transition requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-13.3-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "13.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-13.3-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "13.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-13.3-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "13.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV4, GV35, M1, M2, M3) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV4, GV35, M1, M2, M3）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-13.3-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "13.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-13.3-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "13.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the monitored-surface inventory, detection content, threshold, and alert-case authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把受监测面清单、检测内容、阈值与告警案件权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-13.3-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "13.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired.",
          "zh": "对生命周期“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-13.3-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "13.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired.",
          "zh": "对生命周期“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-13.3-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "13.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 1.1, Safeguard 12.4; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 1.1、Safeguard 12.4 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-13.3-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "13.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-13.3-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "13.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-13.3-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "13.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-13.3-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "13.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile EDR/NDR/IDS/IPS, network and cloud flow, firewalls, NAC, identity, applications, providers, threat intelligence, SIEM, and case management and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 EDR/NDR/IDS/IPS、网络与云流量、防火墙、NAC、身份、应用、提供商、威胁情报、SIEM 和案件管理，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-13.3-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "13.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Require every connector carrying complete, attributable, timely, protected, searchable, and actionable security telemetry plus source health to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 完整、可归因、及时、受保护、可检索、可行动的安全遥测及来源健康 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-13.3-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "13.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Require every connector carrying intended connectivity, trust zone, route, protocol, identity, management path, traffic decision, and observed outcome to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 预期连接、信任区、路由、协议、身份、管理路径、流量决策和观察结果 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-13.3-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "13.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Place NIDS or cloud-native equivalents from architecture and threat paths, engineer taps/mirrors/flow, manage signatures and analytics, decrypt only where lawful/needed, centralize alerts and monitor packet loss, asymmetry, clock and sensor health.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“按架构与威胁路径布置 NIDS/云等效物，正确设计 TAP/Mirror/Flow，管理签名和分析；仅在合法必要时解密，集中告警，并监测丢包、非对称、时钟和 Sensor 健康。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-13.3-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "13.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-13.3-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "13.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-13.3-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "13.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-13.3-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "13.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the monitored-surface inventory, detection content, threshold, and alert-case authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在受监测面清单、检测内容、阈值与告警案件权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-13.3-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "13.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Implement the explicit state machine event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-13.3-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "13.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Implement the explicit state machine requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-13.3-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "13.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-13.3-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "13.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-13.3-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "13.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-13.3-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "13.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-13.3-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "13.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in host, network, cloud, identity, application, and provider security signals, detections, prevention decisions, traffic boundaries, and response handoffs; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 主机、网络、云、身份、应用和提供商安全信号、检测、阻断决策、流量边界和响应交接 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-13.3-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "13.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired; alert before each deadline becomes overdue.",
          "zh": "为“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-13.3-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "13.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; alert before each deadline becomes overdue.",
          "zh": "为“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-13.3-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "13.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “CAS counts covered boundaries without verifying traffic reaches a sensor.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“CAS 数边界覆盖却不证流量进入 Sensor。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-13.3-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "13.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-13.3-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "13.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-13.3-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "13.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-13.3-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "13.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat encrypted traffic, east-west and overlay paths, sensor blind spots, duplicate alerts, stale rules, threshold drift, provider outages, bypass protocols, and unsafe prevention as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 加密流量、东西向与覆盖路径、传感器盲区、重复告警、陈旧规则、阈值漂移、提供商中断、绕过协议和不安全阻断 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-13.3-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "13.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Treat clock skew, actor loss, field truncation, parser drift, dropped or duplicate events, privacy redaction, provider gaps, encrypted paths, quota, and archive failure as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 时钟偏移、行为者丢失、字段截断、解析漂移、事件丢失或重复、隐私脱敏、提供商缺口、加密路径、配额和归档故障 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-13.3-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "13.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Treat IPv6, overlays, east-west paths, remote and roaming devices, direct egress, alternate resolvers, QUIC, asymmetric routes, provider abstraction, and emergency consoles as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 IPv6、覆盖网络、东西向路径、远程与漫游设备、直接出口、替代解析器、QUIC、非对称路由、提供商抽象和紧急控制台 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-13.3-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "13.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Replay safe protocol and detection fixtures from both directions at representative boundaries; verify packet visibility, decoding, alert and source/destination attribution.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“从双向在代表边界回放安全协议/检测 Fixture，验证流量可见、解码、告警与源目的归因；测试高流量丢失、加密和故障转移。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-13.3-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "13.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-13.3-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "13.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 5 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、5 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-13.3-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "13.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-13.3-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "13.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the monitored-surface inventory, detection content, threshold, and alert-case authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以受监测面清单、检测内容、阈值与告警案件权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-13.3-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "13.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Publish healthy, silent, partial, late, malformed, duplicate, unowned, unreviewed, alerted, investigated, and archived sources or events with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 健康、静默、部分、迟到、畸形、重复、无责任人、未审阅、已告警、已调查和已归档来源或事件，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-13.3-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "13.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Publish known, unknown, allowed, denied, shadow, bypassed, asymmetric, stale-rule, exception, and unobserved paths with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已知、未知、允许、拒绝、影子、绕过、非对称、陈旧规则、例外和未观测路径，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-13.3-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "13.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-13.3-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "13.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-13.3-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "13.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-13.3-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "13.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-13.3-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "13.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the monitored-surface inventory, detection content, threshold, and alert-case authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护受监测面清单、检测内容、阈值与告警案件权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-13.3-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "13.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Restrict authority to change event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-13.3-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "13.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Restrict authority to change requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-13.3-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "13.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-13.3-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "13.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-13.3-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "13.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-13.3-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "13.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-13.3-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "13.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise benign and malicious-like canaries, sensor and collector loss, threshold boundaries, segmentation bypass, fail-open/closed behavior, rule rollback, and response escalation through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 安全与恶意特征金丝雀、传感器与采集器丢失、阈值边界、分段绕过、故障开闭、规则回滚和响应升级，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-13.3-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "13.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Run the positive control an allowed and denied canary event traced from source through review; exercise negative, stale, duplicate, bypass, and outage controls including source loss, parser/schema change, time skew, queue overflow, duplicate delivery, provider export outage, missed alert, and unreadable archive.",
          "zh": "运行正向控制“一项允许与拒绝金丝雀事件从来源贯穿到审阅”，并执行包含“来源丢失、解析器/模式变化、时钟偏移、队列溢出、重复投递、提供商导出中断、漏报和归档不可读”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-13.3-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "13.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Run the positive control an approved flow over the required secure management or business path; exercise negative, stale, duplicate, bypass, and outage controls including an unapproved route, protocol downgrade, direct egress, alternate DNS/QUIC path, segmentation bypass, AAA loss, stale rule, and rollback failure.",
          "zh": "运行正向控制“通过规定安全管理或业务路径的一项获批流量”，并执行包含“未批准路由、协议降级、直接出口、替代 DNS/QUIC 路径、分段绕过、AAA 丢失、陈旧规则和回滚失败”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-13.3-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "13.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-13.3-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "13.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-13.3-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "13.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-13.3-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "13.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-13.3-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "13.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever EDR/NDR/IDS/IPS, network and cloud flow, firewalls, NAC, identity, applications, providers, threat intelligence, SIEM, and case management change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 EDR/NDR/IDS/IPS、网络与云流量、防火墙、NAC、身份、应用、提供商、威胁情报、SIEM 和案件管理 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-13.3-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "13.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Use healthy, silent, partial, late, malformed, duplicate, unowned, unreviewed, alerted, investigated, and archived sources or events to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 健康、静默、部分、迟到、畸形、重复、无责任人、未审阅、已告警、已调查和已归档来源或事件 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-13.3-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "13.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Use known, unknown, allowed, denied, shadow, bypassed, asymmetric, stale-rule, exception, and unobserved paths to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已知、未知、允许、拒绝、影子、绕过、非对称、陈旧规则、例外和未观测路径 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "13.4",
      "control": 13,
      "title_en": "Perform Traffic Filtering Between Network Segments",
      "title_zh": "网段间流量过滤",
      "first_ig": 2,
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Network",
      "security_function": "Protect",
      "patterns": [
        "telemetry",
        "network",
        "enforcement"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [],
        "variables": [
          "GV35",
          "GV36",
          "GV37",
          "M1",
          "M2",
          "M3"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "Scope every route between trust segments, accounts/projects, clusters, management planes and partner/remote zones, including IPv4/IPv6, overlay, transit and failover paths.",
          "build": "Default-deny new inter-zone communication, permit narrow source/destination/service/identity flows, manage through reviewed policy-as-code, expire temporary rules and remove shadowed/unused access.",
          "proof": "Test every representative allowed flow and denied lateral/management path, including alternate route, IPv6 and failover.",
          "boundary": "A “properly configured” device can still enforce an over-broad design."
        },
        "zh": {
          "scope": "覆盖信任区、云账号/项目、集群、管理面、伙伴/远程之间的全部路由，含 IPv4/IPv6、Overlay、Transit 和 Failover。",
          "build": "新跨区默认拒绝，只允许窄源、目的、服务/身份；通过评审策略即代码管理，临时规则到期，清除 Shadow/未用权限，在离信任边界最近的强制点执行并记日志。",
          "proof": "代表性测试所有允许业务流和拒绝横向/管理路径，包括备用路由、IPv6、故障转移；计算有效可达，查宽泛、遮蔽、过期规则，每条 Permit 追责任、用途和最后使用。",
          "boundary": "设备“配置正确”仍可能执行过宽设计。"
        }
      },
      "category_counts": {
        "outcome": 8,
        "scope": 8,
        "ownership": 8,
        "data": 8,
        "integration": 8,
        "control": 8,
        "timing": 8,
        "exception": 8,
        "evidence": 8,
        "security": 8,
        "testing": 8,
        "operations": 8
      },
      "requirement_count": 96,
      "requirements": [
        {
          "code": "CIS-13.4-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "13.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Perform Traffic Filtering Between Network Segments; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“网段间流量过滤”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-13.4-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "13.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 13.4, official Asset Class Network, Security Function Protect, and IG2 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 13.4、官方资产类别“网络”、安全功能“保护”和首次出现的 IG2，并保存来源抓取日期。"
        },
        {
          "code": "CIS-13.4-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "13.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Scope every route between trust segments, accounts/projects, clusters, management planes and partner/remote zones, including IPv4/IPv6, overlay, transit and failover paths.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“覆盖信任区、云账号/项目、集群、管理面、伙伴/远程之间的全部路由，含 IPv4/IPv6、Overlay、Transit 和 Failover。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-13.4-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "13.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-13.4-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "13.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Perform Traffic Filtering Between Network Segments to its operating object—host, network, cloud, identity, application, and provider security signals, detections, prevention decisions, traffic boundaries, and response handoffs—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“网段间流量过滤”连接到其运营对象——主机、网络、云、身份、应用和提供商安全信号、检测、阻断决策、流量边界和响应交接——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-13.4-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "13.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "For Perform Traffic Filtering Between Network Segments, express success as an observable decision over complete, attributable, timely, protected, searchable, and actionable security telemetry plus source health; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“网段间流量过滤”，以 完整、可归因、及时、受保护、可检索、可行动的安全遥测及来源健康 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-13.4-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "13.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "For Perform Traffic Filtering Between Network Segments, express success as an observable decision over intended connectivity, trust zone, route, protocol, identity, management path, traffic decision, and observed outcome; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“网段间流量过滤”，以 预期连接、信任区、路由、协议、身份、管理路径、流量决策和观察结果 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-13.4-OUT-08",
          "local_code": "OUT-08",
          "display_code": "O08",
          "safeguard_id": "13.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "For Perform Traffic Filtering Between Network Segments, express success as an observable decision over an enforceable allow, deny, contain, quarantine, require, remove, or transform decision at the closest reliable control point; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“网段间流量过滤”，以 在最近可靠控制点执行允许、拒绝、遏制、隔离、强制、移除或转换决策 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-13.4-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "13.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-13.4-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "13.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-13.4-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "13.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-13.4-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "13.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-13.4-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "13.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across encrypted traffic, east-west and overlay paths, sensor blind spots, duplicate alerts, stale rules, threshold drift, provider outages, bypass protocols, and unsafe prevention; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 加密流量、东西向与覆盖路径、传感器盲区、重复告警、陈旧规则、阈值漂移、提供商中断、绕过协议和不安全阻断 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-13.4-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "13.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Include clock skew, actor loss, field truncation, parser drift, dropped or duplicate events, privacy redaction, provider gaps, encrypted paths, quota, and archive failure in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 时钟偏移、行为者丢失、字段截断、解析漂移、事件丢失或重复、隐私脱敏、提供商缺口、加密路径、配额和归档故障 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-13.4-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "13.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Include IPv6, overlays, east-west paths, remote and roaming devices, direct egress, alternate resolvers, QUIC, asymmetric routes, provider abstraction, and emergency consoles in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 IPv6、覆盖网络、东西向路径、远程与漫游设备、直接出口、替代解析器、QUIC、非对称路由、提供商抽象和紧急控制台 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-13.4-SCP-08",
          "local_code": "SCP-08",
          "display_code": "P08",
          "safeguard_id": "13.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Include audit-only mode, unsupported platforms, local overrides, race conditions, cached state, alternate paths, fail-open behavior, and emergency bypass in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 仅审计模式、不支持平台、本地覆盖、竞态、缓存状态、替代路径、故障开放和紧急绕过 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-13.4-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "13.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-13.4-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "13.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-13.4-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "13.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-13.4-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "13.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-13.4-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "13.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind detection and security operations, endpoint/network/cloud engineering, threat intelligence, incident response, service owners, and risk owners to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 检测与安全运营、终端/网络/云工程、威胁情报、事件响应、服务责任人和风险责任人 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-13.4-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "13.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Name who may transition event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-13.4-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "13.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Name who may transition requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-13.4-OWN-08",
          "local_code": "OWN-08",
          "display_code": "W08",
          "safeguard_id": "13.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Name who may transition observe → evaluate → decide → enforce → verify outcome → rollback/close, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-13.4-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "13.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-13.4-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "13.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-13.4-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "13.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV35, GV36, GV37, M1, M2, M3) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV35, GV36, GV37, M1, M2, M3）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-13.4-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "13.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-13.4-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "13.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the monitored-surface inventory, detection content, threshold, and alert-case authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把受监测面清单、检测内容、阈值与告警案件权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-13.4-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "13.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired.",
          "zh": "对生命周期“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-13.4-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "13.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired.",
          "zh": "对生命周期“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-13.4-DAT-08",
          "local_code": "DAT-08",
          "display_code": "D08",
          "safeguard_id": "13.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle observe → evaluate → decide → enforce → verify outcome → rollback/close.",
          "zh": "对生命周期“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-13.4-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "13.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for no explicit predecessor in the pinned CAS page; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 固定 CAS 页面没有列出显式前置项 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-13.4-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "13.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-13.4-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "13.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-13.4-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "13.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-13.4-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "13.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile EDR/NDR/IDS/IPS, network and cloud flow, firewalls, NAC, identity, applications, providers, threat intelligence, SIEM, and case management and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 EDR/NDR/IDS/IPS、网络与云流量、防火墙、NAC、身份、应用、提供商、威胁情报、SIEM 和案件管理，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-13.4-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "13.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Require every connector carrying complete, attributable, timely, protected, searchable, and actionable security telemetry plus source health to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 完整、可归因、及时、受保护、可检索、可行动的安全遥测及来源健康 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-13.4-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "13.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Require every connector carrying intended connectivity, trust zone, route, protocol, identity, management path, traffic decision, and observed outcome to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 预期连接、信任区、路由、协议、身份、管理路径、流量决策和观察结果 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-13.4-INT-08",
          "local_code": "INT-08",
          "display_code": "I08",
          "safeguard_id": "13.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Require every connector carrying an enforceable allow, deny, contain, quarantine, require, remove, or transform decision at the closest reliable control point to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 在最近可靠控制点执行允许、拒绝、遏制、隔离、强制、移除或转换决策 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-13.4-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "13.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Default-deny new inter-zone communication, permit narrow source/destination/service/identity flows, manage through reviewed policy-as-code, expire temporary rules and remove shadowed/unused access.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“新跨区默认拒绝，只允许窄源、目的、服务/身份；通过评审策略即代码管理，临时规则到期，清除 Shadow/未用权限，在离信任边界最近的强制点执行并记日志。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-13.4-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "13.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-13.4-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "13.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-13.4-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "13.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-13.4-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "13.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the monitored-surface inventory, detection content, threshold, and alert-case authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在受监测面清单、检测内容、阈值与告警案件权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-13.4-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "13.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Implement the explicit state machine event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-13.4-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "13.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Implement the explicit state machine requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-13.4-CTL-08",
          "local_code": "CTL-08",
          "display_code": "C08",
          "safeguard_id": "13.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Implement the explicit state machine observe → evaluate → decide → enforce → verify outcome → rollback/close; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-13.4-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "13.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-13.4-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "13.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-13.4-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "13.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-13.4-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "13.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-13.4-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "13.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in host, network, cloud, identity, application, and provider security signals, detections, prevention decisions, traffic boundaries, and response handoffs; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 主机、网络、云、身份、应用和提供商安全信号、检测、阻断决策、流量边界和响应交接 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-13.4-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "13.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired; alert before each deadline becomes overdue.",
          "zh": "为“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-13.4-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "13.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; alert before each deadline becomes overdue.",
          "zh": "为“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-13.4-TIM-08",
          "local_code": "TIM-08",
          "display_code": "T08",
          "safeguard_id": "13.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for observe → evaluate → decide → enforce → verify outcome → rollback/close; alert before each deadline becomes overdue.",
          "zh": "为“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-13.4-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "13.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “A “properly configured” device can still enforce an over-broad design.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“设备“配置正确”仍可能执行过宽设计。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-13.4-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "13.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-13.4-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "13.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-13.4-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "13.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-13.4-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "13.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat encrypted traffic, east-west and overlay paths, sensor blind spots, duplicate alerts, stale rules, threshold drift, provider outages, bypass protocols, and unsafe prevention as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 加密流量、东西向与覆盖路径、传感器盲区、重复告警、陈旧规则、阈值漂移、提供商中断、绕过协议和不安全阻断 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-13.4-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "13.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Treat clock skew, actor loss, field truncation, parser drift, dropped or duplicate events, privacy redaction, provider gaps, encrypted paths, quota, and archive failure as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 时钟偏移、行为者丢失、字段截断、解析漂移、事件丢失或重复、隐私脱敏、提供商缺口、加密路径、配额和归档故障 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-13.4-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "13.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Treat IPv6, overlays, east-west paths, remote and roaming devices, direct egress, alternate resolvers, QUIC, asymmetric routes, provider abstraction, and emergency consoles as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 IPv6、覆盖网络、东西向路径、远程与漫游设备、直接出口、替代解析器、QUIC、非对称路由、提供商抽象和紧急控制台 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-13.4-EXC-08",
          "local_code": "EXC-08",
          "display_code": "X08",
          "safeguard_id": "13.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Treat audit-only mode, unsupported platforms, local overrides, race conditions, cached state, alternate paths, fail-open behavior, and emergency bypass as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 仅审计模式、不支持平台、本地覆盖、竞态、缓存状态、替代路径、故障开放和紧急绕过 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-13.4-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "13.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Test every representative allowed flow and denied lateral/management path, including alternate route, IPv6 and failover.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“代表性测试所有允许业务流和拒绝横向/管理路径，包括备用路由、IPv6、故障转移；计算有效可达，查宽泛、遮蔽、过期规则，每条 Permit 追责任、用途和最后使用。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-13.4-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "13.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-13.4-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "13.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 6 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、6 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-13.4-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "13.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-13.4-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "13.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the monitored-surface inventory, detection content, threshold, and alert-case authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以受监测面清单、检测内容、阈值与告警案件权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-13.4-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "13.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Publish healthy, silent, partial, late, malformed, duplicate, unowned, unreviewed, alerted, investigated, and archived sources or events with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 健康、静默、部分、迟到、畸形、重复、无责任人、未审阅、已告警、已调查和已归档来源或事件，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-13.4-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "13.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Publish known, unknown, allowed, denied, shadow, bypassed, asymmetric, stale-rule, exception, and unobserved paths with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已知、未知、允许、拒绝、影子、绕过、非对称、陈旧规则、例外和未观测路径，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-13.4-EVD-08",
          "local_code": "EVD-08",
          "display_code": "E08",
          "safeguard_id": "13.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Publish eligible, enforcing, audit-only, failed, bypassed, excepted, rolled-back, and outcome-verified populations with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 适用、已执行、仅审计、失败、被绕过、例外、已回滚和结果已验证总体，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-13.4-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "13.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-13.4-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "13.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-13.4-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "13.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-13.4-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "13.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-13.4-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "13.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the monitored-surface inventory, detection content, threshold, and alert-case authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护受监测面清单、检测内容、阈值与告警案件权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-13.4-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "13.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Restrict authority to change event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-13.4-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "13.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Restrict authority to change requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-13.4-SEC-08",
          "local_code": "SEC-08",
          "display_code": "S08",
          "safeguard_id": "13.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Restrict authority to change observe → evaluate → decide → enforce → verify outcome → rollback/close; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-13.4-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "13.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-13.4-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "13.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-13.4-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "13.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-13.4-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "13.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-13.4-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "13.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise benign and malicious-like canaries, sensor and collector loss, threshold boundaries, segmentation bypass, fail-open/closed behavior, rule rollback, and response escalation through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 安全与恶意特征金丝雀、传感器与采集器丢失、阈值边界、分段绕过、故障开闭、规则回滚和响应升级，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-13.4-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "13.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Run the positive control an allowed and denied canary event traced from source through review; exercise negative, stale, duplicate, bypass, and outage controls including source loss, parser/schema change, time skew, queue overflow, duplicate delivery, provider export outage, missed alert, and unreadable archive.",
          "zh": "运行正向控制“一项允许与拒绝金丝雀事件从来源贯穿到审阅”，并执行包含“来源丢失、解析器/模式变化、时钟偏移、队列溢出、重复投递、提供商导出中断、漏报和归档不可读”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-13.4-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "13.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Run the positive control an approved flow over the required secure management or business path; exercise negative, stale, duplicate, bypass, and outage controls including an unapproved route, protocol downgrade, direct egress, alternate DNS/QUIC path, segmentation bypass, AAA loss, stale rule, and rollback failure.",
          "zh": "运行正向控制“通过规定安全管理或业务路径的一项获批流量”，并执行包含“未批准路由、协议降级、直接出口、替代 DNS/QUIC 路径、分段绕过、AAA 丢失、陈旧规则和回滚失败”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-13.4-TST-08",
          "local_code": "TST-08",
          "display_code": "V08",
          "safeguard_id": "13.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Run the positive control an approved business action that completes through the enforced path; exercise negative, stale, duplicate, bypass, and outage controls including a prohibited action, alternate path, local override, stale policy, control outage, emergency bypass, and rollback failure.",
          "zh": "运行正向控制“通过受控路径完成的一项获批业务动作”，并执行包含“禁止动作、替代路径、本地覆盖、陈旧策略、控制中断、紧急绕过和回滚失败”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-13.4-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "13.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-13.4-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "13.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-13.4-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "13.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-13.4-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "13.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-13.4-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "13.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever EDR/NDR/IDS/IPS, network and cloud flow, firewalls, NAC, identity, applications, providers, threat intelligence, SIEM, and case management change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 EDR/NDR/IDS/IPS、网络与云流量、防火墙、NAC、身份、应用、提供商、威胁情报、SIEM 和案件管理 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-13.4-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "13.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Use healthy, silent, partial, late, malformed, duplicate, unowned, unreviewed, alerted, investigated, and archived sources or events to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 健康、静默、部分、迟到、畸形、重复、无责任人、未审阅、已告警、已调查和已归档来源或事件 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-13.4-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "13.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Use known, unknown, allowed, denied, shadow, bypassed, asymmetric, stale-rule, exception, and unobserved paths to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已知、未知、允许、拒绝、影子、绕过、非对称、陈旧规则、例外和未观测路径 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-13.4-OPS-08",
          "local_code": "OPS-08",
          "display_code": "R08",
          "safeguard_id": "13.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Use eligible, enforcing, audit-only, failed, bypassed, excepted, rolled-back, and outcome-verified populations to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 适用、已执行、仅审计、失败、被绕过、例外、已回滚和结果已验证总体 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "13.5",
      "control": 13,
      "title_en": "Manage Access Control for Remote Assets",
      "title_zh": "远程资产访问准入",
      "first_ig": 2,
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Devices",
      "security_function": "Protect",
      "patterns": [
        "telemetry",
        "identity",
        "network"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "1.1",
          "4.1",
          "6.6"
        ],
        "variables": [
          "GV3",
          "GV23",
          "GV39",
          "M1",
          "M2",
          "M3",
          "M4",
          "M5",
          "M6"
        ],
        "metric_branches": 2,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "The population is remote assets and sessions accessing enterprise resources, managed or otherwise.",
          "build": "Use NAC/ZTNA/VPN/conditional access to evaluate device identity and fresh posture, grant least resource scope, quarantine or limit noncompliant devices and provide remediation.",
          "proof": "Connect compliant, stale-patch, disabled-protection, tampered/unmanaged and offline-status devices; verify decisions, limited remediation path, logs and state change during an existing session.",
          "boundary": "CAS counts authorization systems configured with policies but does not test whether posture is true or current."
        },
        "zh": {
          "scope": "总体是所有远程接入企业资源的资产/会话，无论受管与否；访问量依据反恶意软件/EDR、基线合规、OS/应用更新和身份的当前状态，一次注册合规不能永久授权。",
          "build": "用 NAC/ZTNA/VPN/条件访问评估设备身份与新鲜姿态，按资源最小授权，对不合规资产隔离/限制并提供修复；签名保护姿态信号，定义故障行为，区分员工、BYOD、厂商和管理员。",
          "proof": "让合规、缺补丁、停防护、被篡改/未管和状态离线设备接入，验证决定、有限修复通道、日志与会话中状态变化。",
          "boundary": "CAS 只数授权系统配置了政策，不验证姿态真假/新鲜度；客户端自报可伪造。"
        }
      },
      "category_counts": {
        "outcome": 8,
        "scope": 8,
        "ownership": 8,
        "data": 8,
        "integration": 8,
        "control": 8,
        "timing": 8,
        "exception": 8,
        "evidence": 8,
        "security": 8,
        "testing": 8,
        "operations": 8
      },
      "requirement_count": 96,
      "requirements": [
        {
          "code": "CIS-13.5-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "13.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Manage Access Control for Remote Assets; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“远程资产访问准入”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-13.5-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "13.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 13.5, official Asset Class Devices, Security Function Protect, and IG2 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 13.5、官方资产类别“设备”、安全功能“保护”和首次出现的 IG2，并保存来源抓取日期。"
        },
        {
          "code": "CIS-13.5-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "13.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “The population is remote assets and sessions accessing enterprise resources, managed or otherwise.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“总体是所有远程接入企业资源的资产/会话，无论受管与否；访问量依据反恶意软件/EDR、基线合规、OS/应用更新和身份的当前状态，一次注册合规不能永久授权。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-13.5-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "13.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-13.5-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "13.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Manage Access Control for Remote Assets to its operating object—host, network, cloud, identity, application, and provider security signals, detections, prevention decisions, traffic boundaries, and response handoffs—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“远程资产访问准入”连接到其运营对象——主机、网络、云、身份、应用和提供商安全信号、检测、阻断决策、流量边界和响应交接——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-13.5-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "13.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "For Manage Access Control for Remote Assets, express success as an observable decision over complete, attributable, timely, protected, searchable, and actionable security telemetry plus source health; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“远程资产访问准入”，以 完整、可归因、及时、受保护、可检索、可行动的安全遥测及来源健康 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-13.5-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "13.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "For Manage Access Control for Remote Assets, express success as an observable decision over effective identity, authentication, authorization, privilege, session, and revocation state across every access path; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“远程资产访问准入”，以 所有访问路径上的实际身份、认证、授权、权限、会话和撤销状态 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-13.5-OUT-08",
          "local_code": "OUT-08",
          "display_code": "O08",
          "safeguard_id": "13.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "For Manage Access Control for Remote Assets, express success as an observable decision over intended connectivity, trust zone, route, protocol, identity, management path, traffic decision, and observed outcome; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“远程资产访问准入”，以 预期连接、信任区、路由、协议、身份、管理路径、流量决策和观察结果 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-13.5-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "13.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-13.5-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "13.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-13.5-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "13.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-13.5-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "13.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-13.5-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "13.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across encrypted traffic, east-west and overlay paths, sensor blind spots, duplicate alerts, stale rules, threshold drift, provider outages, bypass protocols, and unsafe prevention; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 加密流量、东西向与覆盖路径、传感器盲区、重复告警、陈旧规则、阈值漂移、提供商中断、绕过协议和不安全阻断 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-13.5-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "13.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Include clock skew, actor loss, field truncation, parser drift, dropped or duplicate events, privacy redaction, provider gaps, encrypted paths, quota, and archive failure in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 时钟偏移、行为者丢失、字段截断、解析漂移、事件丢失或重复、隐私脱敏、提供商缺口、加密路径、配额和归档故障 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-13.5-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "13.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Include shared and service identities, nested groups, direct grants, cached sessions, federation gaps, recovery channels, API keys, emergency access, and provider support in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 共享与服务身份、嵌套组、直接授权、缓存会话、联邦缺口、恢复通道、API 密钥、紧急访问和提供商支持 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-13.5-SCP-08",
          "local_code": "SCP-08",
          "display_code": "P08",
          "safeguard_id": "13.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Include IPv6, overlays, east-west paths, remote and roaming devices, direct egress, alternate resolvers, QUIC, asymmetric routes, provider abstraction, and emergency consoles in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 IPv6、覆盖网络、东西向路径、远程与漫游设备、直接出口、替代解析器、QUIC、非对称路由、提供商抽象和紧急控制台 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-13.5-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "13.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-13.5-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "13.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-13.5-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "13.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-13.5-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "13.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-13.5-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "13.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind detection and security operations, endpoint/network/cloud engineering, threat intelligence, incident response, service owners, and risk owners to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 检测与安全运营、终端/网络/云工程、威胁情报、事件响应、服务责任人和风险责任人 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-13.5-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "13.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Name who may transition event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-13.5-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "13.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Name who may transition requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-13.5-OWN-08",
          "local_code": "OWN-08",
          "display_code": "W08",
          "safeguard_id": "13.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Name who may transition requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-13.5-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "13.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-13.5-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "13.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-13.5-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "13.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV3, GV23, GV39, M1, M2, M3, M4, M5, M6) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV3, GV23, GV39, M1, M2, M3, M4, M5, M6）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-13.5-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "13.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-13.5-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "13.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the monitored-surface inventory, detection content, threshold, and alert-case authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把受监测面清单、检测内容、阈值与告警案件权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-13.5-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "13.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired.",
          "zh": "对生命周期“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-13.5-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "13.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated.",
          "zh": "对生命周期“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-13.5-DAT-08",
          "local_code": "DAT-08",
          "display_code": "D08",
          "safeguard_id": "13.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired.",
          "zh": "对生命周期“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-13.5-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "13.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 1.1, Safeguard 4.1, Safeguard 6.6; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 1.1、Safeguard 4.1、Safeguard 6.6 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-13.5-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "13.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-13.5-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "13.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-13.5-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "13.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-13.5-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "13.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile EDR/NDR/IDS/IPS, network and cloud flow, firewalls, NAC, identity, applications, providers, threat intelligence, SIEM, and case management and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 EDR/NDR/IDS/IPS、网络与云流量、防火墙、NAC、身份、应用、提供商、威胁情报、SIEM 和案件管理，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-13.5-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "13.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Require every connector carrying complete, attributable, timely, protected, searchable, and actionable security telemetry plus source health to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 完整、可归因、及时、受保护、可检索、可行动的安全遥测及来源健康 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-13.5-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "13.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Require every connector carrying effective identity, authentication, authorization, privilege, session, and revocation state across every access path to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 所有访问路径上的实际身份、认证、授权、权限、会话和撤销状态 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-13.5-INT-08",
          "local_code": "INT-08",
          "display_code": "I08",
          "safeguard_id": "13.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Require every connector carrying intended connectivity, trust zone, route, protocol, identity, management path, traffic decision, and observed outcome to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 预期连接、信任区、路由、协议、身份、管理路径、流量决策和观察结果 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-13.5-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "13.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Use NAC/ZTNA/VPN/conditional access to evaluate device identity and fresh posture, grant least resource scope, quarantine or limit noncompliant devices and provide remediation.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“用 NAC/ZTNA/VPN/条件访问评估设备身份与新鲜姿态，按资源最小授权，对不合规资产隔离/限制并提供修复；签名保护姿态信号，定义故障行为，区分员工、BYOD、厂商和管理员。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-13.5-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "13.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-13.5-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "13.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-13.5-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "13.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-13.5-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "13.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the monitored-surface inventory, detection content, threshold, and alert-case authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在受监测面清单、检测内容、阈值与告警案件权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-13.5-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "13.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Implement the explicit state machine event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-13.5-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "13.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Implement the explicit state machine requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-13.5-CTL-08",
          "local_code": "CTL-08",
          "display_code": "C08",
          "safeguard_id": "13.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Implement the explicit state machine requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-13.5-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "13.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-13.5-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "13.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-13.5-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "13.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-13.5-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "13.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-13.5-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "13.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in host, network, cloud, identity, application, and provider security signals, detections, prevention decisions, traffic boundaries, and response handoffs; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 主机、网络、云、身份、应用和提供商安全信号、检测、阻断决策、流量边界和响应交接 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-13.5-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "13.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired; alert before each deadline becomes overdue.",
          "zh": "为“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-13.5-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "13.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated; alert before each deadline becomes overdue.",
          "zh": "为“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-13.5-TIM-08",
          "local_code": "TIM-08",
          "display_code": "T08",
          "safeguard_id": "13.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; alert before each deadline becomes overdue.",
          "zh": "为“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-13.5-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "13.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “CAS counts authorization systems configured with policies but does not test whether posture is true or current.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“CAS 只数授权系统配置了政策，不验证姿态真假/新鲜度；客户端自报可伪造。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-13.5-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "13.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-13.5-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "13.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-13.5-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "13.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-13.5-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "13.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat encrypted traffic, east-west and overlay paths, sensor blind spots, duplicate alerts, stale rules, threshold drift, provider outages, bypass protocols, and unsafe prevention as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 加密流量、东西向与覆盖路径、传感器盲区、重复告警、陈旧规则、阈值漂移、提供商中断、绕过协议和不安全阻断 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-13.5-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "13.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Treat clock skew, actor loss, field truncation, parser drift, dropped or duplicate events, privacy redaction, provider gaps, encrypted paths, quota, and archive failure as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 时钟偏移、行为者丢失、字段截断、解析漂移、事件丢失或重复、隐私脱敏、提供商缺口、加密路径、配额和归档故障 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-13.5-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "13.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Treat shared and service identities, nested groups, direct grants, cached sessions, federation gaps, recovery channels, API keys, emergency access, and provider support as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 共享与服务身份、嵌套组、直接授权、缓存会话、联邦缺口、恢复通道、API 密钥、紧急访问和提供商支持 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-13.5-EXC-08",
          "local_code": "EXC-08",
          "display_code": "X08",
          "safeguard_id": "13.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Treat IPv6, overlays, east-west paths, remote and roaming devices, direct egress, alternate resolvers, QUIC, asymmetric routes, provider abstraction, and emergency consoles as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 IPv6、覆盖网络、东西向路径、远程与漫游设备、直接出口、替代解析器、QUIC、非对称路由、提供商抽象和紧急控制台 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-13.5-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "13.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Connect compliant, stale-patch, disabled-protection, tampered/unmanaged and offline-status devices; verify decisions, limited remediation path, logs and state change during an existing session.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“让合规、缺补丁、停防护、被篡改/未管和状态离线设备接入，验证决定、有限修复通道、日志与会话中状态变化。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-13.5-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "13.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-13.5-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "13.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 2 pinned CAS metric branch(es), 9 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 2 个指标分支、9 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-13.5-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "13.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-13.5-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "13.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the monitored-surface inventory, detection content, threshold, and alert-case authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以受监测面清单、检测内容、阈值与告警案件权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-13.5-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "13.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Publish healthy, silent, partial, late, malformed, duplicate, unowned, unreviewed, alerted, investigated, and archived sources or events with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 健康、静默、部分、迟到、畸形、重复、无责任人、未审阅、已告警、已调查和已归档来源或事件，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-13.5-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "13.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Publish requested, approved, effective, excessive, orphaned, stale, emergency, revoked-but-active, and independently reviewed rights with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 申请、批准、实际、过度、孤儿、陈旧、紧急、已撤销仍活跃及独立复核权限，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-13.5-EVD-08",
          "local_code": "EVD-08",
          "display_code": "E08",
          "safeguard_id": "13.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Publish known, unknown, allowed, denied, shadow, bypassed, asymmetric, stale-rule, exception, and unobserved paths with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已知、未知、允许、拒绝、影子、绕过、非对称、陈旧规则、例外和未观测路径，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-13.5-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "13.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-13.5-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "13.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-13.5-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "13.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-13.5-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "13.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-13.5-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "13.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the monitored-surface inventory, detection content, threshold, and alert-case authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护受监测面清单、检测内容、阈值与告警案件权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-13.5-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "13.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Restrict authority to change event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-13.5-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "13.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Restrict authority to change requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-13.5-SEC-08",
          "local_code": "SEC-08",
          "display_code": "S08",
          "safeguard_id": "13.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Restrict authority to change requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-13.5-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "13.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-13.5-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "13.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-13.5-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "13.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-13.5-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "13.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-13.5-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "13.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise benign and malicious-like canaries, sensor and collector loss, threshold boundaries, segmentation bypass, fail-open/closed behavior, rule rollback, and response escalation through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 安全与恶意特征金丝雀、传感器与采集器丢失、阈值边界、分段绕过、故障开闭、规则回滚和响应升级，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-13.5-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "13.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Run the positive control an allowed and denied canary event traced from source through review; exercise negative, stale, duplicate, bypass, and outage controls including source loss, parser/schema change, time skew, queue overflow, duplicate delivery, provider export outage, missed alert, and unreadable archive.",
          "zh": "运行正向控制“一项允许与拒绝金丝雀事件从来源贯穿到审阅”，并执行包含“来源丢失、解析器/模式变化、时钟偏移、队列溢出、重复投递、提供商导出中断、漏报和归档不可读”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-13.5-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "13.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Run the positive control an authorized identity using the required assurance and least privilege; exercise negative, stale, duplicate, bypass, and outage controls including an unauthorized identity, missing factor, stale session, direct grant, inherited excess, revoked token, and recovery bypass.",
          "zh": "运行正向控制“使用所需保证级别和最小权限的授权身份”，并执行包含“未授权身份、缺失认证因子、陈旧会话、直接授权、继承过权、已撤销令牌和恢复绕过”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-13.5-TST-08",
          "local_code": "TST-08",
          "display_code": "V08",
          "safeguard_id": "13.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Run the positive control an approved flow over the required secure management or business path; exercise negative, stale, duplicate, bypass, and outage controls including an unapproved route, protocol downgrade, direct egress, alternate DNS/QUIC path, segmentation bypass, AAA loss, stale rule, and rollback failure.",
          "zh": "运行正向控制“通过规定安全管理或业务路径的一项获批流量”，并执行包含“未批准路由、协议降级、直接出口、替代 DNS/QUIC 路径、分段绕过、AAA 丢失、陈旧规则和回滚失败”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-13.5-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "13.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-13.5-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "13.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-13.5-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "13.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-13.5-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "13.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-13.5-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "13.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever EDR/NDR/IDS/IPS, network and cloud flow, firewalls, NAC, identity, applications, providers, threat intelligence, SIEM, and case management change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 EDR/NDR/IDS/IPS、网络与云流量、防火墙、NAC、身份、应用、提供商、威胁情报、SIEM 和案件管理 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-13.5-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "13.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Use healthy, silent, partial, late, malformed, duplicate, unowned, unreviewed, alerted, investigated, and archived sources or events to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 健康、静默、部分、迟到、畸形、重复、无责任人、未审阅、已告警、已调查和已归档来源或事件 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-13.5-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "13.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Use requested, approved, effective, excessive, orphaned, stale, emergency, revoked-but-active, and independently reviewed rights to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 申请、批准、实际、过度、孤儿、陈旧、紧急、已撤销仍活跃及独立复核权限 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-13.5-OPS-08",
          "local_code": "OPS-08",
          "display_code": "R08",
          "safeguard_id": "13.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Use known, unknown, allowed, denied, shadow, bypassed, asymmetric, stale-rule, exception, and unobserved paths to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已知、未知、允许、拒绝、影子、绕过、非对称、陈旧规则、例外和未观测路径 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "13.6",
      "control": 13,
      "title_en": "Collect Network Traffic Flow Logs",
      "title_zh": "网络流量与流日志",
      "first_ig": 2,
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Network",
      "security_function": "Detect",
      "patterns": [
        "telemetry",
        "discovery",
        "network"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "1.1",
          "4.2",
          "12.4"
        ],
        "variables": [
          "GV35",
          "GV37",
          "M1",
          "M2",
          "M3"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "Collect flow records and/or packet data from network devices at boundaries and internal paths needed for detection and investigation, with direction, endpoints, ports/protocol, time, bytes/packets, action and tenant/segment context.",
          "build": "Enable NetFlow/IPFIX/VPC flow or packet capture at selected points, synchronize time, centralize securely, document sampling and retention, map translated/overlay identities and monitor exporter/collector loss.",
          "proof": "Generate allowed, denied, east-west, IPv6 and failover flows and trace expected fields through export and analytics.",
          "boundary": "CAS focuses on boundary devices, which can omit lateral movement."
        },
        "zh": {
          "scope": "采集用于检测/调查的边界和内部路径流记录或包，包含方向、端点、端口/协议、时间、字节/包、动作和租户/网段上下文；采样与 NAT 会限制推断。",
          "build": "在选定点启用 NetFlow/IPFIX/VPC Flow 或 Packet，统一时钟，安全集中，记录采样/保留，映射 NAT/Overlay 身份并监测出口/收集丢失；只有收益、隐私、容量合理时才抓包。",
          "proof": "生成允许、拒绝、东西向、IPv6 和故障转移流，追踪全部字段；突发时比较接口计数与导出/接收记录，验证 NAT 映射和 Sensor 健康告警。",
          "boundary": "CAS 聚焦边界设备，可能漏横向。"
        }
      },
      "category_counts": {
        "outcome": 8,
        "scope": 8,
        "ownership": 8,
        "data": 8,
        "integration": 8,
        "control": 8,
        "timing": 8,
        "exception": 8,
        "evidence": 8,
        "security": 8,
        "testing": 8,
        "operations": 8
      },
      "requirement_count": 96,
      "requirements": [
        {
          "code": "CIS-13.6-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "13.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Collect Network Traffic Flow Logs; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“网络流量与流日志”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-13.6-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "13.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 13.6, official Asset Class Network, Security Function Detect, and IG2 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 13.6、官方资产类别“网络”、安全功能“检测”和首次出现的 IG2，并保存来源抓取日期。"
        },
        {
          "code": "CIS-13.6-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "13.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Collect flow records and/or packet data from network devices at boundaries and internal paths needed for detection and investigation, with direction, endpoints, ports/protocol, time, bytes/packets, action and tenant/segment context.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“采集用于检测/调查的边界和内部路径流记录或包，包含方向、端点、端口/协议、时间、字节/包、动作和租户/网段上下文；采样与 NAT 会限制推断。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-13.6-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "13.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-13.6-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "13.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Collect Network Traffic Flow Logs to its operating object—host, network, cloud, identity, application, and provider security signals, detections, prevention decisions, traffic boundaries, and response handoffs—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“网络流量与流日志”连接到其运营对象——主机、网络、云、身份、应用和提供商安全信号、检测、阻断决策、流量边界和响应交接——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-13.6-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "13.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "For Collect Network Traffic Flow Logs, express success as an observable decision over complete, attributable, timely, protected, searchable, and actionable security telemetry plus source health; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“网络流量与流日志”，以 完整、可归因、及时、受保护、可检索、可行动的安全遥测及来源健康 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-13.6-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "13.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "For Collect Network Traffic Flow Logs, express success as an observable decision over coverage of every intended discovery vantage point, source, job, parser, and reconciliation path; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“网络流量与流日志”，以 所有预期发现视角、来源、任务、解析器和对账路径的覆盖 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-13.6-OUT-08",
          "local_code": "OUT-08",
          "display_code": "O08",
          "safeguard_id": "13.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "For Collect Network Traffic Flow Logs, express success as an observable decision over intended connectivity, trust zone, route, protocol, identity, management path, traffic decision, and observed outcome; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“网络流量与流日志”，以 预期连接、信任区、路由、协议、身份、管理路径、流量决策和观察结果 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-13.6-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "13.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-13.6-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "13.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-13.6-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "13.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-13.6-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "13.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-13.6-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "13.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across encrypted traffic, east-west and overlay paths, sensor blind spots, duplicate alerts, stale rules, threshold drift, provider outages, bypass protocols, and unsafe prevention; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 加密流量、东西向与覆盖路径、传感器盲区、重复告警、陈旧规则、阈值漂移、提供商中断、绕过协议和不安全阻断 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-13.6-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "13.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Include clock skew, actor loss, field truncation, parser drift, dropped or duplicate events, privacy redaction, provider gaps, encrypted paths, quota, and archive failure in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 时钟偏移、行为者丢失、字段截断、解析漂移、事件丢失或重复、隐私脱敏、提供商缺口、加密路径、配额和归档故障 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-13.6-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "13.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Include unreachable zones, short-lived objects, blind spots, rate limits, credential failure, encrypted or proprietary protocols, and silent sensors in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 不可达区域、短生对象、盲区、限流、凭据失败、加密或专有协议和静默传感器 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-13.6-SCP-08",
          "local_code": "SCP-08",
          "display_code": "P08",
          "safeguard_id": "13.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Include IPv6, overlays, east-west paths, remote and roaming devices, direct egress, alternate resolvers, QUIC, asymmetric routes, provider abstraction, and emergency consoles in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 IPv6、覆盖网络、东西向路径、远程与漫游设备、直接出口、替代解析器、QUIC、非对称路由、提供商抽象和紧急控制台 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-13.6-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "13.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-13.6-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "13.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-13.6-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "13.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-13.6-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "13.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-13.6-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "13.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind detection and security operations, endpoint/network/cloud engineering, threat intelligence, incident response, service owners, and risk owners to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 检测与安全运营、终端/网络/云工程、威胁情报、事件响应、服务责任人和风险责任人 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-13.6-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "13.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Name who may transition event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-13.6-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "13.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Name who may transition scheduled → started → observed → normalized → reconciled → dispositioned, with explicit partial and failed states, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 计划 → 启动 → 观测 → 归一化 → 对账 → 处置，并显式保留部分与失败状态，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-13.6-OWN-08",
          "local_code": "OWN-08",
          "display_code": "W08",
          "safeguard_id": "13.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Name who may transition requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-13.6-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "13.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-13.6-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "13.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-13.6-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "13.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV35, GV37, M1, M2, M3) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV35, GV37, M1, M2, M3）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-13.6-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "13.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-13.6-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "13.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the monitored-surface inventory, detection content, threshold, and alert-case authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把受监测面清单、检测内容、阈值与告警案件权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-13.6-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "13.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired.",
          "zh": "对生命周期“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-13.6-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "13.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle scheduled → started → observed → normalized → reconciled → dispositioned, with explicit partial and failed states.",
          "zh": "对生命周期“计划 → 启动 → 观测 → 归一化 → 对账 → 处置，并显式保留部分与失败状态”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-13.6-DAT-08",
          "local_code": "DAT-08",
          "display_code": "D08",
          "safeguard_id": "13.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired.",
          "zh": "对生命周期“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-13.6-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "13.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 1.1, Safeguard 4.2, Safeguard 12.4; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 1.1、Safeguard 4.2、Safeguard 12.4 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-13.6-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "13.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-13.6-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "13.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-13.6-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "13.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-13.6-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "13.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile EDR/NDR/IDS/IPS, network and cloud flow, firewalls, NAC, identity, applications, providers, threat intelligence, SIEM, and case management and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 EDR/NDR/IDS/IPS、网络与云流量、防火墙、NAC、身份、应用、提供商、威胁情报、SIEM 和案件管理，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-13.6-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "13.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Require every connector carrying complete, attributable, timely, protected, searchable, and actionable security telemetry plus source health to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 完整、可归因、及时、受保护、可检索、可行动的安全遥测及来源健康 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-13.6-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "13.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Require every connector carrying coverage of every intended discovery vantage point, source, job, parser, and reconciliation path to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 所有预期发现视角、来源、任务、解析器和对账路径的覆盖 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-13.6-INT-08",
          "local_code": "INT-08",
          "display_code": "I08",
          "safeguard_id": "13.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Require every connector carrying intended connectivity, trust zone, route, protocol, identity, management path, traffic decision, and observed outcome to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 预期连接、信任区、路由、协议、身份、管理路径、流量决策和观察结果 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-13.6-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "13.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Enable NetFlow/IPFIX/VPC flow or packet capture at selected points, synchronize time, centralize securely, document sampling and retention, map translated/overlay identities and monitor exporter/collector loss.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“在选定点启用 NetFlow/IPFIX/VPC Flow 或 Packet，统一时钟，安全集中，记录采样/保留，映射 NAT/Overlay 身份并监测出口/收集丢失；只有收益、隐私、容量合理时才抓包。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-13.6-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "13.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-13.6-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "13.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-13.6-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "13.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-13.6-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "13.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the monitored-surface inventory, detection content, threshold, and alert-case authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在受监测面清单、检测内容、阈值与告警案件权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-13.6-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "13.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Implement the explicit state machine event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-13.6-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "13.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Implement the explicit state machine scheduled → started → observed → normalized → reconciled → dispositioned, with explicit partial and failed states; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“计划 → 启动 → 观测 → 归一化 → 对账 → 处置，并显式保留部分与失败状态”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-13.6-CTL-08",
          "local_code": "CTL-08",
          "display_code": "C08",
          "safeguard_id": "13.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Implement the explicit state machine requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-13.6-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "13.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-13.6-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "13.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-13.6-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "13.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-13.6-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "13.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-13.6-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "13.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in host, network, cloud, identity, application, and provider security signals, detections, prevention decisions, traffic boundaries, and response handoffs; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 主机、网络、云、身份、应用和提供商安全信号、检测、阻断决策、流量边界和响应交接 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-13.6-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "13.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired; alert before each deadline becomes overdue.",
          "zh": "为“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-13.6-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "13.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for scheduled → started → observed → normalized → reconciled → dispositioned, with explicit partial and failed states; alert before each deadline becomes overdue.",
          "zh": "为“计划 → 启动 → 观测 → 归一化 → 对账 → 处置，并显式保留部分与失败状态”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-13.6-TIM-08",
          "local_code": "TIM-08",
          "display_code": "T08",
          "safeguard_id": "13.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; alert before each deadline becomes overdue.",
          "zh": "为“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-13.6-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "13.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “CAS focuses on boundary devices, which can omit lateral movement.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“CAS 聚焦边界设备，可能漏横向。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-13.6-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "13.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-13.6-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "13.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-13.6-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "13.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-13.6-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "13.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat encrypted traffic, east-west and overlay paths, sensor blind spots, duplicate alerts, stale rules, threshold drift, provider outages, bypass protocols, and unsafe prevention as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 加密流量、东西向与覆盖路径、传感器盲区、重复告警、陈旧规则、阈值漂移、提供商中断、绕过协议和不安全阻断 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-13.6-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "13.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Treat clock skew, actor loss, field truncation, parser drift, dropped or duplicate events, privacy redaction, provider gaps, encrypted paths, quota, and archive failure as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 时钟偏移、行为者丢失、字段截断、解析漂移、事件丢失或重复、隐私脱敏、提供商缺口、加密路径、配额和归档故障 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-13.6-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "13.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Treat unreachable zones, short-lived objects, blind spots, rate limits, credential failure, encrypted or proprietary protocols, and silent sensors as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 不可达区域、短生对象、盲区、限流、凭据失败、加密或专有协议和静默传感器 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-13.6-EXC-08",
          "local_code": "EXC-08",
          "display_code": "X08",
          "safeguard_id": "13.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Treat IPv6, overlays, east-west paths, remote and roaming devices, direct egress, alternate resolvers, QUIC, asymmetric routes, provider abstraction, and emergency consoles as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 IPv6、覆盖网络、东西向路径、远程与漫游设备、直接出口、替代解析器、QUIC、非对称路由、提供商抽象和紧急控制台 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-13.6-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "13.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Generate allowed, denied, east-west, IPv6 and failover flows and trace expected fields through export and analytics.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“生成允许、拒绝、东西向、IPv6 和故障转移流，追踪全部字段；突发时比较接口计数与导出/接收记录，验证 NAT 映射和 Sensor 健康告警。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-13.6-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "13.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-13.6-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "13.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 5 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、5 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-13.6-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "13.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-13.6-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "13.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the monitored-surface inventory, detection content, threshold, and alert-case authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以受监测面清单、检测内容、阈值与告警案件权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-13.6-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "13.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Publish healthy, silent, partial, late, malformed, duplicate, unowned, unreviewed, alerted, investigated, and archived sources or events with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 健康、静默、部分、迟到、畸形、重复、无责任人、未审阅、已告警、已调查和已归档来源或事件，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-13.6-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "13.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Publish scheduled, successful, partial, failed, stale, blind, newly discovered, unmatched, and reconciled observations with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 计划、成功、部分、失败、陈旧、盲区、新发现、未匹配和已对账观测，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-13.6-EVD-08",
          "local_code": "EVD-08",
          "display_code": "E08",
          "safeguard_id": "13.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Publish known, unknown, allowed, denied, shadow, bypassed, asymmetric, stale-rule, exception, and unobserved paths with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已知、未知、允许、拒绝、影子、绕过、非对称、陈旧规则、例外和未观测路径，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-13.6-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "13.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-13.6-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "13.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-13.6-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "13.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-13.6-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "13.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-13.6-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "13.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the monitored-surface inventory, detection content, threshold, and alert-case authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护受监测面清单、检测内容、阈值与告警案件权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-13.6-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "13.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Restrict authority to change event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-13.6-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "13.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Restrict authority to change scheduled → started → observed → normalized → reconciled → dispositioned, with explicit partial and failed states; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“计划 → 启动 → 观测 → 归一化 → 对账 → 处置，并显式保留部分与失败状态”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-13.6-SEC-08",
          "local_code": "SEC-08",
          "display_code": "S08",
          "safeguard_id": "13.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Restrict authority to change requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-13.6-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "13.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-13.6-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "13.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-13.6-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "13.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-13.6-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "13.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-13.6-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "13.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise benign and malicious-like canaries, sensor and collector loss, threshold boundaries, segmentation bypass, fail-open/closed behavior, rule rollback, and response escalation through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 安全与恶意特征金丝雀、传感器与采集器丢失、阈值边界、分段绕过、故障开闭、规则回滚和响应升级，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-13.6-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "13.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Run the positive control an allowed and denied canary event traced from source through review; exercise negative, stale, duplicate, bypass, and outage controls including source loss, parser/schema change, time skew, queue overflow, duplicate delivery, provider export outage, missed alert, and unreadable archive.",
          "zh": "运行正向控制“一项允许与拒绝金丝雀事件从来源贯穿到审阅”，并执行包含“来源丢失、解析器/模式变化、时钟偏移、队列溢出、重复投递、提供商导出中断、漏报和归档不可读”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-13.6-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "13.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Run the positive control a known object visible from each representative vantage point; exercise negative, stale, duplicate, bypass, and outage controls including an unknown and short-lived object, failed credential, blocked scan, silent sensor, parser drift, and uncovered segment.",
          "zh": "运行正向控制“从每个代表性视角可见的一项已知对象”，并执行包含“未知与短生对象、凭据失败、扫描受阻、传感器静默、解析漂移和未覆盖网段”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-13.6-TST-08",
          "local_code": "TST-08",
          "display_code": "V08",
          "safeguard_id": "13.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Run the positive control an approved flow over the required secure management or business path; exercise negative, stale, duplicate, bypass, and outage controls including an unapproved route, protocol downgrade, direct egress, alternate DNS/QUIC path, segmentation bypass, AAA loss, stale rule, and rollback failure.",
          "zh": "运行正向控制“通过规定安全管理或业务路径的一项获批流量”，并执行包含“未批准路由、协议降级、直接出口、替代 DNS/QUIC 路径、分段绕过、AAA 丢失、陈旧规则和回滚失败”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-13.6-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "13.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-13.6-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "13.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-13.6-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "13.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-13.6-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "13.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-13.6-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "13.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever EDR/NDR/IDS/IPS, network and cloud flow, firewalls, NAC, identity, applications, providers, threat intelligence, SIEM, and case management change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 EDR/NDR/IDS/IPS、网络与云流量、防火墙、NAC、身份、应用、提供商、威胁情报、SIEM 和案件管理 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-13.6-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "13.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Use healthy, silent, partial, late, malformed, duplicate, unowned, unreviewed, alerted, investigated, and archived sources or events to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 健康、静默、部分、迟到、畸形、重复、无责任人、未审阅、已告警、已调查和已归档来源或事件 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-13.6-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "13.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Use scheduled, successful, partial, failed, stale, blind, newly discovered, unmatched, and reconciled observations to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 计划、成功、部分、失败、陈旧、盲区、新发现、未匹配和已对账观测 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-13.6-OPS-08",
          "local_code": "OPS-08",
          "display_code": "R08",
          "safeguard_id": "13.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Use known, unknown, allowed, denied, shadow, bypassed, asymmetric, stale-rule, exception, and unobserved paths to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已知、未知、允许、拒绝、影子、绕过、非对称、陈旧规则、例外和未观测路径 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "13.7",
      "control": 13,
      "title_en": "Deploy a Host-Based Intrusion Prevention Solution",
      "title_zh": "主机入侵防御",
      "first_ig": 3,
      "implementation_groups": [
        3
      ],
      "asset_class": "Devices",
      "security_function": "Protect",
      "patterns": [
        "telemetry",
        "enforcement"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "1.1",
          "2.1"
        ],
        "variables": [
          "GV1",
          "GV5",
          "M1",
          "M2",
          "M3"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "Eligible assets support a host control capable of blocking or containing malicious behavior, not merely alerting.",
          "build": "Enable risk-appropriate prevention for exploit, behavior, file/integrity and network actions, protect policy and sensor, stage tuning with benign controls and connect isolation/rollback to incident response.",
          "proof": "Run safe simulations that should block and similar legitimate administrative tasks that should pass; verify prevention, process/system outcome, telemetry and recovery.",
          "boundary": "Prevention can disrupt critical systems and attackers can evade or kill sensors."
        },
        "zh": {
          "scope": "合格资产要有能阻断/遏制恶意行为的主机控制，而非只告警；明确保护技术、强制模式和工作负载。",
          "build": "按风险启用 Exploit、行为、文件/完整性和网络防护，保护策略/Sensor，从观察到强制逐步调优，并连接隔离/回滚；用角色级例外，不可全局关闭。",
          "proof": "运行应被阻断的安全模拟和应通过的相似正常运维，验证阻断、系统结果、遥测和恢复；在测试范围篡改 Sensor、耗资源，指标看健康强制资产和例外年龄。",
          "boundary": "防护会干扰关键系统，攻击者也会规避/终止 Sensor。"
        }
      },
      "category_counts": {
        "outcome": 7,
        "scope": 7,
        "ownership": 7,
        "data": 7,
        "integration": 7,
        "control": 7,
        "timing": 7,
        "exception": 7,
        "evidence": 7,
        "security": 7,
        "testing": 7,
        "operations": 7
      },
      "requirement_count": 84,
      "requirements": [
        {
          "code": "CIS-13.7-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "13.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Deploy a Host-Based Intrusion Prevention Solution; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“主机入侵防御”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-13.7-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "13.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 13.7, official Asset Class Devices, Security Function Protect, and IG3 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 13.7、官方资产类别“设备”、安全功能“保护”和首次出现的 IG3，并保存来源抓取日期。"
        },
        {
          "code": "CIS-13.7-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "13.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Eligible assets support a host control capable of blocking or containing malicious behavior, not merely alerting.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“合格资产要有能阻断/遏制恶意行为的主机控制，而非只告警；明确保护技术、强制模式和工作负载。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-13.7-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "13.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-13.7-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "13.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Deploy a Host-Based Intrusion Prevention Solution to its operating object—host, network, cloud, identity, application, and provider security signals, detections, prevention decisions, traffic boundaries, and response handoffs—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“主机入侵防御”连接到其运营对象——主机、网络、云、身份、应用和提供商安全信号、检测、阻断决策、流量边界和响应交接——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-13.7-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "13.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "For Deploy a Host-Based Intrusion Prevention Solution, express success as an observable decision over complete, attributable, timely, protected, searchable, and actionable security telemetry plus source health; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“主机入侵防御”，以 完整、可归因、及时、受保护、可检索、可行动的安全遥测及来源健康 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-13.7-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "13.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "For Deploy a Host-Based Intrusion Prevention Solution, express success as an observable decision over an enforceable allow, deny, contain, quarantine, require, remove, or transform decision at the closest reliable control point; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“主机入侵防御”，以 在最近可靠控制点执行允许、拒绝、遏制、隔离、强制、移除或转换决策 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-13.7-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "13.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-13.7-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "13.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-13.7-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "13.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-13.7-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "13.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-13.7-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "13.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across encrypted traffic, east-west and overlay paths, sensor blind spots, duplicate alerts, stale rules, threshold drift, provider outages, bypass protocols, and unsafe prevention; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 加密流量、东西向与覆盖路径、传感器盲区、重复告警、陈旧规则、阈值漂移、提供商中断、绕过协议和不安全阻断 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-13.7-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "13.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Include clock skew, actor loss, field truncation, parser drift, dropped or duplicate events, privacy redaction, provider gaps, encrypted paths, quota, and archive failure in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 时钟偏移、行为者丢失、字段截断、解析漂移、事件丢失或重复、隐私脱敏、提供商缺口、加密路径、配额和归档故障 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-13.7-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "13.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Include audit-only mode, unsupported platforms, local overrides, race conditions, cached state, alternate paths, fail-open behavior, and emergency bypass in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 仅审计模式、不支持平台、本地覆盖、竞态、缓存状态、替代路径、故障开放和紧急绕过 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-13.7-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "13.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-13.7-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "13.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-13.7-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "13.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-13.7-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "13.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-13.7-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "13.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind detection and security operations, endpoint/network/cloud engineering, threat intelligence, incident response, service owners, and risk owners to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 检测与安全运营、终端/网络/云工程、威胁情报、事件响应、服务责任人和风险责任人 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-13.7-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "13.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Name who may transition event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-13.7-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "13.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Name who may transition observe → evaluate → decide → enforce → verify outcome → rollback/close, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-13.7-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "13.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-13.7-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "13.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-13.7-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "13.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV1, GV5, M1, M2, M3) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV1, GV5, M1, M2, M3）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-13.7-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "13.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-13.7-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "13.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the monitored-surface inventory, detection content, threshold, and alert-case authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把受监测面清单、检测内容、阈值与告警案件权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-13.7-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "13.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired.",
          "zh": "对生命周期“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-13.7-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "13.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle observe → evaluate → decide → enforce → verify outcome → rollback/close.",
          "zh": "对生命周期“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-13.7-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "13.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 1.1, Safeguard 2.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 1.1、Safeguard 2.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-13.7-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "13.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-13.7-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "13.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-13.7-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "13.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-13.7-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "13.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile EDR/NDR/IDS/IPS, network and cloud flow, firewalls, NAC, identity, applications, providers, threat intelligence, SIEM, and case management and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 EDR/NDR/IDS/IPS、网络与云流量、防火墙、NAC、身份、应用、提供商、威胁情报、SIEM 和案件管理，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-13.7-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "13.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Require every connector carrying complete, attributable, timely, protected, searchable, and actionable security telemetry plus source health to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 完整、可归因、及时、受保护、可检索、可行动的安全遥测及来源健康 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-13.7-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "13.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Require every connector carrying an enforceable allow, deny, contain, quarantine, require, remove, or transform decision at the closest reliable control point to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 在最近可靠控制点执行允许、拒绝、遏制、隔离、强制、移除或转换决策 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-13.7-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "13.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Enable risk-appropriate prevention for exploit, behavior, file/integrity and network actions, protect policy and sensor, stage tuning with benign controls and connect isolation/rollback to incident response.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“按风险启用 Exploit、行为、文件/完整性和网络防护，保护策略/Sensor，从观察到强制逐步调优，并连接隔离/回滚；用角色级例外，不可全局关闭。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-13.7-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "13.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-13.7-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "13.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-13.7-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "13.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-13.7-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "13.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the monitored-surface inventory, detection content, threshold, and alert-case authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在受监测面清单、检测内容、阈值与告警案件权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-13.7-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "13.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Implement the explicit state machine event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-13.7-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "13.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Implement the explicit state machine observe → evaluate → decide → enforce → verify outcome → rollback/close; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-13.7-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "13.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-13.7-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "13.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-13.7-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "13.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-13.7-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "13.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-13.7-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "13.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in host, network, cloud, identity, application, and provider security signals, detections, prevention decisions, traffic boundaries, and response handoffs; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 主机、网络、云、身份、应用和提供商安全信号、检测、阻断决策、流量边界和响应交接 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-13.7-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "13.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired; alert before each deadline becomes overdue.",
          "zh": "为“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-13.7-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "13.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for observe → evaluate → decide → enforce → verify outcome → rollback/close; alert before each deadline becomes overdue.",
          "zh": "为“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-13.7-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "13.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “Prevention can disrupt critical systems and attackers can evade or kill sensors.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“防护会干扰关键系统，攻击者也会规避/终止 Sensor。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-13.7-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "13.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-13.7-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "13.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-13.7-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "13.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-13.7-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "13.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat encrypted traffic, east-west and overlay paths, sensor blind spots, duplicate alerts, stale rules, threshold drift, provider outages, bypass protocols, and unsafe prevention as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 加密流量、东西向与覆盖路径、传感器盲区、重复告警、陈旧规则、阈值漂移、提供商中断、绕过协议和不安全阻断 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-13.7-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "13.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Treat clock skew, actor loss, field truncation, parser drift, dropped or duplicate events, privacy redaction, provider gaps, encrypted paths, quota, and archive failure as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 时钟偏移、行为者丢失、字段截断、解析漂移、事件丢失或重复、隐私脱敏、提供商缺口、加密路径、配额和归档故障 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-13.7-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "13.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Treat audit-only mode, unsupported platforms, local overrides, race conditions, cached state, alternate paths, fail-open behavior, and emergency bypass as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 仅审计模式、不支持平台、本地覆盖、竞态、缓存状态、替代路径、故障开放和紧急绕过 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-13.7-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "13.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Run safe simulations that should block and similar legitimate administrative tasks that should pass; verify prevention, process/system outcome, telemetry and recovery.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“运行应被阻断的安全模拟和应通过的相似正常运维，验证阻断、系统结果、遥测和恢复；在测试范围篡改 Sensor、耗资源，指标看健康强制资产和例外年龄。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-13.7-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "13.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-13.7-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "13.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 5 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、5 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-13.7-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "13.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-13.7-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "13.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the monitored-surface inventory, detection content, threshold, and alert-case authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以受监测面清单、检测内容、阈值与告警案件权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-13.7-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "13.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Publish healthy, silent, partial, late, malformed, duplicate, unowned, unreviewed, alerted, investigated, and archived sources or events with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 健康、静默、部分、迟到、畸形、重复、无责任人、未审阅、已告警、已调查和已归档来源或事件，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-13.7-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "13.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Publish eligible, enforcing, audit-only, failed, bypassed, excepted, rolled-back, and outcome-verified populations with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 适用、已执行、仅审计、失败、被绕过、例外、已回滚和结果已验证总体，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-13.7-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "13.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-13.7-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "13.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-13.7-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "13.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-13.7-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "13.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-13.7-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "13.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the monitored-surface inventory, detection content, threshold, and alert-case authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护受监测面清单、检测内容、阈值与告警案件权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-13.7-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "13.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Restrict authority to change event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-13.7-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "13.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Restrict authority to change observe → evaluate → decide → enforce → verify outcome → rollback/close; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-13.7-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "13.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-13.7-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "13.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-13.7-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "13.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-13.7-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "13.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-13.7-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "13.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise benign and malicious-like canaries, sensor and collector loss, threshold boundaries, segmentation bypass, fail-open/closed behavior, rule rollback, and response escalation through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 安全与恶意特征金丝雀、传感器与采集器丢失、阈值边界、分段绕过、故障开闭、规则回滚和响应升级，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-13.7-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "13.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Run the positive control an allowed and denied canary event traced from source through review; exercise negative, stale, duplicate, bypass, and outage controls including source loss, parser/schema change, time skew, queue overflow, duplicate delivery, provider export outage, missed alert, and unreadable archive.",
          "zh": "运行正向控制“一项允许与拒绝金丝雀事件从来源贯穿到审阅”，并执行包含“来源丢失、解析器/模式变化、时钟偏移、队列溢出、重复投递、提供商导出中断、漏报和归档不可读”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-13.7-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "13.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Run the positive control an approved business action that completes through the enforced path; exercise negative, stale, duplicate, bypass, and outage controls including a prohibited action, alternate path, local override, stale policy, control outage, emergency bypass, and rollback failure.",
          "zh": "运行正向控制“通过受控路径完成的一项获批业务动作”，并执行包含“禁止动作、替代路径、本地覆盖、陈旧策略、控制中断、紧急绕过和回滚失败”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-13.7-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "13.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-13.7-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "13.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-13.7-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "13.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-13.7-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "13.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-13.7-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "13.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever EDR/NDR/IDS/IPS, network and cloud flow, firewalls, NAC, identity, applications, providers, threat intelligence, SIEM, and case management change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 EDR/NDR/IDS/IPS、网络与云流量、防火墙、NAC、身份、应用、提供商、威胁情报、SIEM 和案件管理 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-13.7-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "13.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Use healthy, silent, partial, late, malformed, duplicate, unowned, unreviewed, alerted, investigated, and archived sources or events to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 健康、静默、部分、迟到、畸形、重复、无责任人、未审阅、已告警、已调查和已归档来源或事件 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-13.7-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "13.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Use eligible, enforcing, audit-only, failed, bypassed, excepted, rolled-back, and outcome-verified populations to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 适用、已执行、仅审计、失败、被绕过、例外、已回滚和结果已验证总体 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "13.8",
      "control": 13,
      "title_en": "Deploy a Network Intrusion Prevention Solution",
      "title_zh": "网络入侵防御",
      "first_ig": 3,
      "implementation_groups": [
        3
      ],
      "asset_class": "Network",
      "security_function": "Protect",
      "patterns": [
        "telemetry",
        "network",
        "enforcement"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "1.1",
          "12.4"
        ],
        "variables": [
          "GV35",
          "GV40",
          "M1",
          "M2",
          "M3"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "Scope boundaries and paths where inline or provider controls can safely block known exploit, protocol or policy violations, including cloud gateways and internal high-value zones.",
          "build": "Deploy NIPS/NGFW/cloud controls in staged detect-to-block modes, keep signatures/engines current, tune with local traffic, use HA and rollback, and route blocks to investigation.",
          "proof": "Replay safe blocking fixtures and benign near-matches through primary/failover/IPv6 paths; verify drop/reset, service continuity, logs and analyst response.",
          "boundary": "Coverage count alone cannot prove packets traverse the device or rules block."
        },
        "zh": {
          "scope": "覆盖适合 Inline/服务商控制安全阻断已知利用、协议或政策违规的边界/路径，含云网关和内部高价值区；位置必须声明故障模式、加密可见性和可用后果。",
          "build": "用 Detect-to-block 分阶段部署 NIPS/NGFW/云控制，保持签名/引擎当前，按本地流量调优，HA/回滚，并把阻断送调查；只对能可靠解析的协议/路径启用规则。",
          "proof": "在主、备、IPv6 路径回放安全阻断 Fixture 和相似正常流，验证 Drop/Reset、业务连续和告警；模拟设备/服务故障与过载，确认 Fail-open/closed 符合声明。",
          "boundary": "覆盖数不能证明流量经过或规则执行。"
        }
      },
      "category_counts": {
        "outcome": 8,
        "scope": 8,
        "ownership": 8,
        "data": 8,
        "integration": 8,
        "control": 8,
        "timing": 8,
        "exception": 8,
        "evidence": 8,
        "security": 8,
        "testing": 8,
        "operations": 8
      },
      "requirement_count": 96,
      "requirements": [
        {
          "code": "CIS-13.8-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "13.8",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Deploy a Network Intrusion Prevention Solution; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“网络入侵防御”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-13.8-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "13.8",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 13.8, official Asset Class Network, Security Function Protect, and IG3 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 13.8、官方资产类别“网络”、安全功能“保护”和首次出现的 IG3，并保存来源抓取日期。"
        },
        {
          "code": "CIS-13.8-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "13.8",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Scope boundaries and paths where inline or provider controls can safely block known exploit, protocol or policy violations, including cloud gateways and internal high-value zones.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“覆盖适合 Inline/服务商控制安全阻断已知利用、协议或政策违规的边界/路径，含云网关和内部高价值区；位置必须声明故障模式、加密可见性和可用后果。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-13.8-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "13.8",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-13.8-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "13.8",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Deploy a Network Intrusion Prevention Solution to its operating object—host, network, cloud, identity, application, and provider security signals, detections, prevention decisions, traffic boundaries, and response handoffs—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“网络入侵防御”连接到其运营对象——主机、网络、云、身份、应用和提供商安全信号、检测、阻断决策、流量边界和响应交接——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-13.8-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "13.8",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "For Deploy a Network Intrusion Prevention Solution, express success as an observable decision over complete, attributable, timely, protected, searchable, and actionable security telemetry plus source health; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“网络入侵防御”，以 完整、可归因、及时、受保护、可检索、可行动的安全遥测及来源健康 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-13.8-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "13.8",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "For Deploy a Network Intrusion Prevention Solution, express success as an observable decision over intended connectivity, trust zone, route, protocol, identity, management path, traffic decision, and observed outcome; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“网络入侵防御”，以 预期连接、信任区、路由、协议、身份、管理路径、流量决策和观察结果 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-13.8-OUT-08",
          "local_code": "OUT-08",
          "display_code": "O08",
          "safeguard_id": "13.8",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "For Deploy a Network Intrusion Prevention Solution, express success as an observable decision over an enforceable allow, deny, contain, quarantine, require, remove, or transform decision at the closest reliable control point; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“网络入侵防御”，以 在最近可靠控制点执行允许、拒绝、遏制、隔离、强制、移除或转换决策 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-13.8-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "13.8",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-13.8-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "13.8",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-13.8-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "13.8",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-13.8-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "13.8",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-13.8-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "13.8",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across encrypted traffic, east-west and overlay paths, sensor blind spots, duplicate alerts, stale rules, threshold drift, provider outages, bypass protocols, and unsafe prevention; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 加密流量、东西向与覆盖路径、传感器盲区、重复告警、陈旧规则、阈值漂移、提供商中断、绕过协议和不安全阻断 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-13.8-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "13.8",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Include clock skew, actor loss, field truncation, parser drift, dropped or duplicate events, privacy redaction, provider gaps, encrypted paths, quota, and archive failure in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 时钟偏移、行为者丢失、字段截断、解析漂移、事件丢失或重复、隐私脱敏、提供商缺口、加密路径、配额和归档故障 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-13.8-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "13.8",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Include IPv6, overlays, east-west paths, remote and roaming devices, direct egress, alternate resolvers, QUIC, asymmetric routes, provider abstraction, and emergency consoles in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 IPv6、覆盖网络、东西向路径、远程与漫游设备、直接出口、替代解析器、QUIC、非对称路由、提供商抽象和紧急控制台 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-13.8-SCP-08",
          "local_code": "SCP-08",
          "display_code": "P08",
          "safeguard_id": "13.8",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Include audit-only mode, unsupported platforms, local overrides, race conditions, cached state, alternate paths, fail-open behavior, and emergency bypass in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 仅审计模式、不支持平台、本地覆盖、竞态、缓存状态、替代路径、故障开放和紧急绕过 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-13.8-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "13.8",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-13.8-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "13.8",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-13.8-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "13.8",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-13.8-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "13.8",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-13.8-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "13.8",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind detection and security operations, endpoint/network/cloud engineering, threat intelligence, incident response, service owners, and risk owners to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 检测与安全运营、终端/网络/云工程、威胁情报、事件响应、服务责任人和风险责任人 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-13.8-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "13.8",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Name who may transition event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-13.8-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "13.8",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Name who may transition requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-13.8-OWN-08",
          "local_code": "OWN-08",
          "display_code": "W08",
          "safeguard_id": "13.8",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Name who may transition observe → evaluate → decide → enforce → verify outcome → rollback/close, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-13.8-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "13.8",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-13.8-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "13.8",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-13.8-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "13.8",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV35, GV40, M1, M2, M3) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV35, GV40, M1, M2, M3）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-13.8-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "13.8",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-13.8-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "13.8",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the monitored-surface inventory, detection content, threshold, and alert-case authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把受监测面清单、检测内容、阈值与告警案件权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-13.8-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "13.8",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired.",
          "zh": "对生命周期“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-13.8-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "13.8",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired.",
          "zh": "对生命周期“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-13.8-DAT-08",
          "local_code": "DAT-08",
          "display_code": "D08",
          "safeguard_id": "13.8",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle observe → evaluate → decide → enforce → verify outcome → rollback/close.",
          "zh": "对生命周期“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-13.8-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "13.8",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 1.1, Safeguard 12.4; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 1.1、Safeguard 12.4 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-13.8-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "13.8",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-13.8-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "13.8",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-13.8-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "13.8",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-13.8-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "13.8",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile EDR/NDR/IDS/IPS, network and cloud flow, firewalls, NAC, identity, applications, providers, threat intelligence, SIEM, and case management and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 EDR/NDR/IDS/IPS、网络与云流量、防火墙、NAC、身份、应用、提供商、威胁情报、SIEM 和案件管理，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-13.8-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "13.8",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Require every connector carrying complete, attributable, timely, protected, searchable, and actionable security telemetry plus source health to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 完整、可归因、及时、受保护、可检索、可行动的安全遥测及来源健康 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-13.8-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "13.8",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Require every connector carrying intended connectivity, trust zone, route, protocol, identity, management path, traffic decision, and observed outcome to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 预期连接、信任区、路由、协议、身份、管理路径、流量决策和观察结果 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-13.8-INT-08",
          "local_code": "INT-08",
          "display_code": "I08",
          "safeguard_id": "13.8",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Require every connector carrying an enforceable allow, deny, contain, quarantine, require, remove, or transform decision at the closest reliable control point to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 在最近可靠控制点执行允许、拒绝、遏制、隔离、强制、移除或转换决策 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-13.8-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "13.8",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Deploy NIPS/NGFW/cloud controls in staged detect-to-block modes, keep signatures/engines current, tune with local traffic, use HA and rollback, and route blocks to investigation.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“用 Detect-to-block 分阶段部署 NIPS/NGFW/云控制，保持签名/引擎当前，按本地流量调优，HA/回滚，并把阻断送调查；只对能可靠解析的协议/路径启用规则。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-13.8-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "13.8",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-13.8-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "13.8",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-13.8-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "13.8",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-13.8-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "13.8",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the monitored-surface inventory, detection content, threshold, and alert-case authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在受监测面清单、检测内容、阈值与告警案件权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-13.8-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "13.8",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Implement the explicit state machine event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-13.8-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "13.8",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Implement the explicit state machine requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-13.8-CTL-08",
          "local_code": "CTL-08",
          "display_code": "C08",
          "safeguard_id": "13.8",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Implement the explicit state machine observe → evaluate → decide → enforce → verify outcome → rollback/close; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-13.8-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "13.8",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-13.8-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "13.8",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-13.8-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "13.8",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-13.8-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "13.8",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-13.8-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "13.8",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in host, network, cloud, identity, application, and provider security signals, detections, prevention decisions, traffic boundaries, and response handoffs; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 主机、网络、云、身份、应用和提供商安全信号、检测、阻断决策、流量边界和响应交接 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-13.8-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "13.8",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired; alert before each deadline becomes overdue.",
          "zh": "为“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-13.8-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "13.8",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; alert before each deadline becomes overdue.",
          "zh": "为“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-13.8-TIM-08",
          "local_code": "TIM-08",
          "display_code": "T08",
          "safeguard_id": "13.8",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for observe → evaluate → decide → enforce → verify outcome → rollback/close; alert before each deadline becomes overdue.",
          "zh": "为“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-13.8-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "13.8",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “Coverage count alone cannot prove packets traverse the device or rules block.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“覆盖数不能证明流量经过或规则执行。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-13.8-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "13.8",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-13.8-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "13.8",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-13.8-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "13.8",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-13.8-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "13.8",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat encrypted traffic, east-west and overlay paths, sensor blind spots, duplicate alerts, stale rules, threshold drift, provider outages, bypass protocols, and unsafe prevention as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 加密流量、东西向与覆盖路径、传感器盲区、重复告警、陈旧规则、阈值漂移、提供商中断、绕过协议和不安全阻断 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-13.8-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "13.8",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Treat clock skew, actor loss, field truncation, parser drift, dropped or duplicate events, privacy redaction, provider gaps, encrypted paths, quota, and archive failure as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 时钟偏移、行为者丢失、字段截断、解析漂移、事件丢失或重复、隐私脱敏、提供商缺口、加密路径、配额和归档故障 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-13.8-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "13.8",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Treat IPv6, overlays, east-west paths, remote and roaming devices, direct egress, alternate resolvers, QUIC, asymmetric routes, provider abstraction, and emergency consoles as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 IPv6、覆盖网络、东西向路径、远程与漫游设备、直接出口、替代解析器、QUIC、非对称路由、提供商抽象和紧急控制台 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-13.8-EXC-08",
          "local_code": "EXC-08",
          "display_code": "X08",
          "safeguard_id": "13.8",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Treat audit-only mode, unsupported platforms, local overrides, race conditions, cached state, alternate paths, fail-open behavior, and emergency bypass as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 仅审计模式、不支持平台、本地覆盖、竞态、缓存状态、替代路径、故障开放和紧急绕过 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-13.8-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "13.8",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Replay safe blocking fixtures and benign near-matches through primary/failover/IPv6 paths; verify drop/reset, service continuity, logs and analyst response.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“在主、备、IPv6 路径回放安全阻断 Fixture 和相似正常流，验证 Drop/Reset、业务连续和告警；模拟设备/服务故障与过载，确认 Fail-open/closed 符合声明。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-13.8-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "13.8",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-13.8-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "13.8",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 5 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、5 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-13.8-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "13.8",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-13.8-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "13.8",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the monitored-surface inventory, detection content, threshold, and alert-case authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以受监测面清单、检测内容、阈值与告警案件权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-13.8-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "13.8",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Publish healthy, silent, partial, late, malformed, duplicate, unowned, unreviewed, alerted, investigated, and archived sources or events with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 健康、静默、部分、迟到、畸形、重复、无责任人、未审阅、已告警、已调查和已归档来源或事件，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-13.8-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "13.8",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Publish known, unknown, allowed, denied, shadow, bypassed, asymmetric, stale-rule, exception, and unobserved paths with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已知、未知、允许、拒绝、影子、绕过、非对称、陈旧规则、例外和未观测路径，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-13.8-EVD-08",
          "local_code": "EVD-08",
          "display_code": "E08",
          "safeguard_id": "13.8",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Publish eligible, enforcing, audit-only, failed, bypassed, excepted, rolled-back, and outcome-verified populations with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 适用、已执行、仅审计、失败、被绕过、例外、已回滚和结果已验证总体，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-13.8-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "13.8",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-13.8-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "13.8",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-13.8-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "13.8",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-13.8-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "13.8",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-13.8-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "13.8",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the monitored-surface inventory, detection content, threshold, and alert-case authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护受监测面清单、检测内容、阈值与告警案件权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-13.8-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "13.8",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Restrict authority to change event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-13.8-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "13.8",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Restrict authority to change requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-13.8-SEC-08",
          "local_code": "SEC-08",
          "display_code": "S08",
          "safeguard_id": "13.8",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Restrict authority to change observe → evaluate → decide → enforce → verify outcome → rollback/close; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-13.8-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "13.8",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-13.8-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "13.8",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-13.8-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "13.8",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-13.8-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "13.8",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-13.8-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "13.8",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise benign and malicious-like canaries, sensor and collector loss, threshold boundaries, segmentation bypass, fail-open/closed behavior, rule rollback, and response escalation through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 安全与恶意特征金丝雀、传感器与采集器丢失、阈值边界、分段绕过、故障开闭、规则回滚和响应升级，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-13.8-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "13.8",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Run the positive control an allowed and denied canary event traced from source through review; exercise negative, stale, duplicate, bypass, and outage controls including source loss, parser/schema change, time skew, queue overflow, duplicate delivery, provider export outage, missed alert, and unreadable archive.",
          "zh": "运行正向控制“一项允许与拒绝金丝雀事件从来源贯穿到审阅”，并执行包含“来源丢失、解析器/模式变化、时钟偏移、队列溢出、重复投递、提供商导出中断、漏报和归档不可读”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-13.8-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "13.8",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Run the positive control an approved flow over the required secure management or business path; exercise negative, stale, duplicate, bypass, and outage controls including an unapproved route, protocol downgrade, direct egress, alternate DNS/QUIC path, segmentation bypass, AAA loss, stale rule, and rollback failure.",
          "zh": "运行正向控制“通过规定安全管理或业务路径的一项获批流量”，并执行包含“未批准路由、协议降级、直接出口、替代 DNS/QUIC 路径、分段绕过、AAA 丢失、陈旧规则和回滚失败”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-13.8-TST-08",
          "local_code": "TST-08",
          "display_code": "V08",
          "safeguard_id": "13.8",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Run the positive control an approved business action that completes through the enforced path; exercise negative, stale, duplicate, bypass, and outage controls including a prohibited action, alternate path, local override, stale policy, control outage, emergency bypass, and rollback failure.",
          "zh": "运行正向控制“通过受控路径完成的一项获批业务动作”，并执行包含“禁止动作、替代路径、本地覆盖、陈旧策略、控制中断、紧急绕过和回滚失败”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-13.8-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "13.8",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-13.8-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "13.8",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-13.8-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "13.8",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-13.8-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "13.8",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-13.8-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "13.8",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever EDR/NDR/IDS/IPS, network and cloud flow, firewalls, NAC, identity, applications, providers, threat intelligence, SIEM, and case management change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 EDR/NDR/IDS/IPS、网络与云流量、防火墙、NAC、身份、应用、提供商、威胁情报、SIEM 和案件管理 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-13.8-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "13.8",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Use healthy, silent, partial, late, malformed, duplicate, unowned, unreviewed, alerted, investigated, and archived sources or events to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 健康、静默、部分、迟到、畸形、重复、无责任人、未审阅、已告警、已调查和已归档来源或事件 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-13.8-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "13.8",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Use known, unknown, allowed, denied, shadow, bypassed, asymmetric, stale-rule, exception, and unobserved paths to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已知、未知、允许、拒绝、影子、绕过、非对称、陈旧规则、例外和未观测路径 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-13.8-OPS-08",
          "local_code": "OPS-08",
          "display_code": "R08",
          "safeguard_id": "13.8",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Use eligible, enforcing, audit-only, failed, bypassed, excepted, rolled-back, and outcome-verified populations to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 适用、已执行、仅审计、失败、被绕过、例外、已回滚和结果已验证总体 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "13.9",
      "control": 13,
      "title_en": "Deploy Port-Level Access Control",
      "title_zh": "端口级网络准入",
      "first_ig": 3,
      "implementation_groups": [
        3
      ],
      "asset_class": "Network",
      "security_function": "Protect",
      "patterns": [
        "telemetry",
        "identity",
        "enforcement"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "1.1"
        ],
        "variables": [
          "GV5",
          "GV35",
          "GV37",
          "GV38",
          "GV41",
          "M1",
          "M2",
          "M3",
          "M4",
          "M5",
          "M6",
          "M7",
          "M8",
          "M9"
        ],
        "metric_branches": 3,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "Port-level access control covers wired, wireless and equivalent access edges before ordinary network reachability, using 802.1X, certificates or comparable user/device authentication.",
          "build": "Deploy resilient supplicant, authenticator and AAA/PKI, assign dynamic least-privilege segments/roles, disable unused ports and tightly govern MAB or guest fallback.",
          "proof": "Connect authorized, revoked, unknown, non-supplicant and spoofed-MAC devices to representative ports/APs; verify placement, denial/quarantine, accounting and failover.",
          "boundary": "MAB authenticates an identifier that can be copied and is a compatibility exception."
        },
        "zh": {
          "scope": "在普通网络可达前，用 802.1X、证书或等效用户/设备认证控制有线、无线及等效接入边缘；覆盖交换端口、AP、Dock、虚拟接入、回退网，闲置物理端口也在范围。",
          "build": "部署有弹性的 Supplicant、Authenticator、AAA/PKI，动态分配最小区/角色，关闭闲置端口，严格治理 MAB/Guest 回退；保护证书注册/撤销，并同步身份/设备台账。",
          "proof": "在代表端口/AP 接入批准、已撤销、未知、不支持 Supplicant 和伪造 MAC 的设备，验证放置、拒绝/隔离、Accounting 和 Failover；测试证书到期、AAA 故障与端口改配，以实际边缘强制为指标。",
          "boundary": "MAB 只认易复制标识，是兼容例外。"
        }
      },
      "category_counts": {
        "outcome": 8,
        "scope": 8,
        "ownership": 8,
        "data": 8,
        "integration": 8,
        "control": 8,
        "timing": 8,
        "exception": 8,
        "evidence": 8,
        "security": 8,
        "testing": 8,
        "operations": 8
      },
      "requirement_count": 96,
      "requirements": [
        {
          "code": "CIS-13.9-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "13.9",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Deploy Port-Level Access Control; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“端口级网络准入”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-13.9-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "13.9",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 13.9, official Asset Class Network, Security Function Protect, and IG3 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 13.9、官方资产类别“网络”、安全功能“保护”和首次出现的 IG3，并保存来源抓取日期。"
        },
        {
          "code": "CIS-13.9-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "13.9",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Port-level access control covers wired, wireless and equivalent access edges before ordinary network reachability, using 802.1X, certificates or comparable user/device authentication.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“在普通网络可达前，用 802.1X、证书或等效用户/设备认证控制有线、无线及等效接入边缘；覆盖交换端口、AP、Dock、虚拟接入、回退网，闲置物理端口也在范围。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-13.9-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "13.9",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-13.9-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "13.9",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Deploy Port-Level Access Control to its operating object—host, network, cloud, identity, application, and provider security signals, detections, prevention decisions, traffic boundaries, and response handoffs—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“端口级网络准入”连接到其运营对象——主机、网络、云、身份、应用和提供商安全信号、检测、阻断决策、流量边界和响应交接——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-13.9-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "13.9",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "For Deploy Port-Level Access Control, express success as an observable decision over complete, attributable, timely, protected, searchable, and actionable security telemetry plus source health; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“端口级网络准入”，以 完整、可归因、及时、受保护、可检索、可行动的安全遥测及来源健康 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-13.9-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "13.9",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "For Deploy Port-Level Access Control, express success as an observable decision over effective identity, authentication, authorization, privilege, session, and revocation state across every access path; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“端口级网络准入”，以 所有访问路径上的实际身份、认证、授权、权限、会话和撤销状态 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-13.9-OUT-08",
          "local_code": "OUT-08",
          "display_code": "O08",
          "safeguard_id": "13.9",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "For Deploy Port-Level Access Control, express success as an observable decision over an enforceable allow, deny, contain, quarantine, require, remove, or transform decision at the closest reliable control point; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“端口级网络准入”，以 在最近可靠控制点执行允许、拒绝、遏制、隔离、强制、移除或转换决策 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-13.9-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "13.9",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-13.9-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "13.9",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-13.9-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "13.9",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-13.9-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "13.9",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-13.9-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "13.9",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across encrypted traffic, east-west and overlay paths, sensor blind spots, duplicate alerts, stale rules, threshold drift, provider outages, bypass protocols, and unsafe prevention; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 加密流量、东西向与覆盖路径、传感器盲区、重复告警、陈旧规则、阈值漂移、提供商中断、绕过协议和不安全阻断 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-13.9-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "13.9",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Include clock skew, actor loss, field truncation, parser drift, dropped or duplicate events, privacy redaction, provider gaps, encrypted paths, quota, and archive failure in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 时钟偏移、行为者丢失、字段截断、解析漂移、事件丢失或重复、隐私脱敏、提供商缺口、加密路径、配额和归档故障 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-13.9-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "13.9",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Include shared and service identities, nested groups, direct grants, cached sessions, federation gaps, recovery channels, API keys, emergency access, and provider support in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 共享与服务身份、嵌套组、直接授权、缓存会话、联邦缺口、恢复通道、API 密钥、紧急访问和提供商支持 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-13.9-SCP-08",
          "local_code": "SCP-08",
          "display_code": "P08",
          "safeguard_id": "13.9",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Include audit-only mode, unsupported platforms, local overrides, race conditions, cached state, alternate paths, fail-open behavior, and emergency bypass in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 仅审计模式、不支持平台、本地覆盖、竞态、缓存状态、替代路径、故障开放和紧急绕过 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-13.9-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "13.9",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-13.9-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "13.9",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-13.9-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "13.9",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-13.9-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "13.9",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-13.9-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "13.9",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind detection and security operations, endpoint/network/cloud engineering, threat intelligence, incident response, service owners, and risk owners to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 检测与安全运营、终端/网络/云工程、威胁情报、事件响应、服务责任人和风险责任人 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-13.9-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "13.9",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Name who may transition event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-13.9-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "13.9",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Name who may transition requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-13.9-OWN-08",
          "local_code": "OWN-08",
          "display_code": "W08",
          "safeguard_id": "13.9",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Name who may transition observe → evaluate → decide → enforce → verify outcome → rollback/close, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-13.9-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "13.9",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-13.9-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "13.9",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-13.9-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "13.9",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV5, GV35, GV37, GV38, GV41, M1, M2, M3, M4, M5, M6, M7, and 2 more) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV5, GV35, GV37, GV38, GV41, M1, M2, M3, M4, M5, M6, M7, and 2 more）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-13.9-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "13.9",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-13.9-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "13.9",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the monitored-surface inventory, detection content, threshold, and alert-case authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把受监测面清单、检测内容、阈值与告警案件权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-13.9-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "13.9",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired.",
          "zh": "对生命周期“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-13.9-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "13.9",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated.",
          "zh": "对生命周期“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-13.9-DAT-08",
          "local_code": "DAT-08",
          "display_code": "D08",
          "safeguard_id": "13.9",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle observe → evaluate → decide → enforce → verify outcome → rollback/close.",
          "zh": "对生命周期“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-13.9-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "13.9",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 1.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 1.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-13.9-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "13.9",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-13.9-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "13.9",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-13.9-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "13.9",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-13.9-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "13.9",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile EDR/NDR/IDS/IPS, network and cloud flow, firewalls, NAC, identity, applications, providers, threat intelligence, SIEM, and case management and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 EDR/NDR/IDS/IPS、网络与云流量、防火墙、NAC、身份、应用、提供商、威胁情报、SIEM 和案件管理，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-13.9-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "13.9",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Require every connector carrying complete, attributable, timely, protected, searchable, and actionable security telemetry plus source health to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 完整、可归因、及时、受保护、可检索、可行动的安全遥测及来源健康 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-13.9-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "13.9",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Require every connector carrying effective identity, authentication, authorization, privilege, session, and revocation state across every access path to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 所有访问路径上的实际身份、认证、授权、权限、会话和撤销状态 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-13.9-INT-08",
          "local_code": "INT-08",
          "display_code": "I08",
          "safeguard_id": "13.9",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Require every connector carrying an enforceable allow, deny, contain, quarantine, require, remove, or transform decision at the closest reliable control point to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 在最近可靠控制点执行允许、拒绝、遏制、隔离、强制、移除或转换决策 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-13.9-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "13.9",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Deploy resilient supplicant, authenticator and AAA/PKI, assign dynamic least-privilege segments/roles, disable unused ports and tightly govern MAB or guest fallback.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“部署有弹性的 Supplicant、Authenticator、AAA/PKI，动态分配最小区/角色，关闭闲置端口，严格治理 MAB/Guest 回退；保护证书注册/撤销，并同步身份/设备台账。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-13.9-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "13.9",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-13.9-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "13.9",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-13.9-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "13.9",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-13.9-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "13.9",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the monitored-surface inventory, detection content, threshold, and alert-case authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在受监测面清单、检测内容、阈值与告警案件权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-13.9-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "13.9",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Implement the explicit state machine event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-13.9-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "13.9",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Implement the explicit state machine requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-13.9-CTL-08",
          "local_code": "CTL-08",
          "display_code": "C08",
          "safeguard_id": "13.9",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Implement the explicit state machine observe → evaluate → decide → enforce → verify outcome → rollback/close; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-13.9-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "13.9",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-13.9-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "13.9",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-13.9-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "13.9",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-13.9-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "13.9",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-13.9-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "13.9",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in host, network, cloud, identity, application, and provider security signals, detections, prevention decisions, traffic boundaries, and response handoffs; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 主机、网络、云、身份、应用和提供商安全信号、检测、阻断决策、流量边界和响应交接 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-13.9-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "13.9",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired; alert before each deadline becomes overdue.",
          "zh": "为“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-13.9-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "13.9",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated; alert before each deadline becomes overdue.",
          "zh": "为“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-13.9-TIM-08",
          "local_code": "TIM-08",
          "display_code": "T08",
          "safeguard_id": "13.9",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for observe → evaluate → decide → enforce → verify outcome → rollback/close; alert before each deadline becomes overdue.",
          "zh": "为“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-13.9-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "13.9",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “MAB authenticates an identifier that can be copied and is a compatibility exception.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“MAB 只认易复制标识，是兼容例外。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-13.9-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "13.9",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-13.9-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "13.9",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-13.9-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "13.9",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-13.9-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "13.9",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat encrypted traffic, east-west and overlay paths, sensor blind spots, duplicate alerts, stale rules, threshold drift, provider outages, bypass protocols, and unsafe prevention as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 加密流量、东西向与覆盖路径、传感器盲区、重复告警、陈旧规则、阈值漂移、提供商中断、绕过协议和不安全阻断 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-13.9-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "13.9",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Treat clock skew, actor loss, field truncation, parser drift, dropped or duplicate events, privacy redaction, provider gaps, encrypted paths, quota, and archive failure as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 时钟偏移、行为者丢失、字段截断、解析漂移、事件丢失或重复、隐私脱敏、提供商缺口、加密路径、配额和归档故障 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-13.9-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "13.9",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Treat shared and service identities, nested groups, direct grants, cached sessions, federation gaps, recovery channels, API keys, emergency access, and provider support as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 共享与服务身份、嵌套组、直接授权、缓存会话、联邦缺口、恢复通道、API 密钥、紧急访问和提供商支持 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-13.9-EXC-08",
          "local_code": "EXC-08",
          "display_code": "X08",
          "safeguard_id": "13.9",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Treat audit-only mode, unsupported platforms, local overrides, race conditions, cached state, alternate paths, fail-open behavior, and emergency bypass as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 仅审计模式、不支持平台、本地覆盖、竞态、缓存状态、替代路径、故障开放和紧急绕过 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-13.9-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "13.9",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Connect authorized, revoked, unknown, non-supplicant and spoofed-MAC devices to representative ports/APs; verify placement, denial/quarantine, accounting and failover.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“在代表端口/AP 接入批准、已撤销、未知、不支持 Supplicant 和伪造 MAC 的设备，验证放置、拒绝/隔离、Accounting 和 Failover；测试证书到期、AAA 故障与端口改配，以实际边缘强制为指标。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-13.9-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "13.9",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-13.9-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "13.9",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 3 pinned CAS metric branch(es), 14 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 3 个指标分支、14 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-13.9-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "13.9",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-13.9-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "13.9",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the monitored-surface inventory, detection content, threshold, and alert-case authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以受监测面清单、检测内容、阈值与告警案件权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-13.9-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "13.9",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Publish healthy, silent, partial, late, malformed, duplicate, unowned, unreviewed, alerted, investigated, and archived sources or events with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 健康、静默、部分、迟到、畸形、重复、无责任人、未审阅、已告警、已调查和已归档来源或事件，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-13.9-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "13.9",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Publish requested, approved, effective, excessive, orphaned, stale, emergency, revoked-but-active, and independently reviewed rights with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 申请、批准、实际、过度、孤儿、陈旧、紧急、已撤销仍活跃及独立复核权限，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-13.9-EVD-08",
          "local_code": "EVD-08",
          "display_code": "E08",
          "safeguard_id": "13.9",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Publish eligible, enforcing, audit-only, failed, bypassed, excepted, rolled-back, and outcome-verified populations with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 适用、已执行、仅审计、失败、被绕过、例外、已回滚和结果已验证总体，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-13.9-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "13.9",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-13.9-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "13.9",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-13.9-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "13.9",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-13.9-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "13.9",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-13.9-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "13.9",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the monitored-surface inventory, detection content, threshold, and alert-case authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护受监测面清单、检测内容、阈值与告警案件权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-13.9-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "13.9",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Restrict authority to change event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-13.9-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "13.9",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Restrict authority to change requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-13.9-SEC-08",
          "local_code": "SEC-08",
          "display_code": "S08",
          "safeguard_id": "13.9",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Restrict authority to change observe → evaluate → decide → enforce → verify outcome → rollback/close; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-13.9-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "13.9",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-13.9-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "13.9",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-13.9-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "13.9",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-13.9-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "13.9",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-13.9-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "13.9",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise benign and malicious-like canaries, sensor and collector loss, threshold boundaries, segmentation bypass, fail-open/closed behavior, rule rollback, and response escalation through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 安全与恶意特征金丝雀、传感器与采集器丢失、阈值边界、分段绕过、故障开闭、规则回滚和响应升级，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-13.9-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "13.9",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Run the positive control an allowed and denied canary event traced from source through review; exercise negative, stale, duplicate, bypass, and outage controls including source loss, parser/schema change, time skew, queue overflow, duplicate delivery, provider export outage, missed alert, and unreadable archive.",
          "zh": "运行正向控制“一项允许与拒绝金丝雀事件从来源贯穿到审阅”，并执行包含“来源丢失、解析器/模式变化、时钟偏移、队列溢出、重复投递、提供商导出中断、漏报和归档不可读”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-13.9-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "13.9",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Run the positive control an authorized identity using the required assurance and least privilege; exercise negative, stale, duplicate, bypass, and outage controls including an unauthorized identity, missing factor, stale session, direct grant, inherited excess, revoked token, and recovery bypass.",
          "zh": "运行正向控制“使用所需保证级别和最小权限的授权身份”，并执行包含“未授权身份、缺失认证因子、陈旧会话、直接授权、继承过权、已撤销令牌和恢复绕过”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-13.9-TST-08",
          "local_code": "TST-08",
          "display_code": "V08",
          "safeguard_id": "13.9",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Run the positive control an approved business action that completes through the enforced path; exercise negative, stale, duplicate, bypass, and outage controls including a prohibited action, alternate path, local override, stale policy, control outage, emergency bypass, and rollback failure.",
          "zh": "运行正向控制“通过受控路径完成的一项获批业务动作”，并执行包含“禁止动作、替代路径、本地覆盖、陈旧策略、控制中断、紧急绕过和回滚失败”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-13.9-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "13.9",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-13.9-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "13.9",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-13.9-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "13.9",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-13.9-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "13.9",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-13.9-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "13.9",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever EDR/NDR/IDS/IPS, network and cloud flow, firewalls, NAC, identity, applications, providers, threat intelligence, SIEM, and case management change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 EDR/NDR/IDS/IPS、网络与云流量、防火墙、NAC、身份、应用、提供商、威胁情报、SIEM 和案件管理 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-13.9-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "13.9",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Use healthy, silent, partial, late, malformed, duplicate, unowned, unreviewed, alerted, investigated, and archived sources or events to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 健康、静默、部分、迟到、畸形、重复、无责任人、未审阅、已告警、已调查和已归档来源或事件 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-13.9-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "13.9",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Use requested, approved, effective, excessive, orphaned, stale, emergency, revoked-but-active, and independently reviewed rights to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 申请、批准、实际、过度、孤儿、陈旧、紧急、已撤销仍活跃及独立复核权限 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-13.9-OPS-08",
          "local_code": "OPS-08",
          "display_code": "R08",
          "safeguard_id": "13.9",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Use eligible, enforcing, audit-only, failed, bypassed, excepted, rolled-back, and outcome-verified populations to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 适用、已执行、仅审计、失败、被绕过、例外、已回滚和结果已验证总体 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "13.10",
      "control": 13,
      "title_en": "Perform Application Layer Filtering",
      "title_zh": "应用层过滤",
      "first_ig": 3,
      "implementation_groups": [
        3
      ],
      "asset_class": "Network",
      "security_function": "Protect",
      "patterns": [
        "telemetry",
        "software_dev"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "1.1",
          "2.1"
        ],
        "variables": [
          "GV5",
          "GV35",
          "M1",
          "M2",
          "M3"
        ],
        "metric_branches": 0,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "The population is application protocols and requests crossing exposed or sensitive boundaries, including web/API, DNS, email and selected industrial/business protocols.",
          "build": "Use reverse/forward proxies, WAF/API gateways, application firewalls or cloud services with positive schemas, authentication context, rate limits and protocol validation.",
          "proof": "Send valid, malformed, oversized, unauthorized-method, encoded and direct-origin requests plus legitimate edge cases; verify intended permit/block, application health and logs.",
          "boundary": "The current CAS has no metric and only asks whether network assets are “covered,” which cannot assess applications."
        },
        "zh": {
          "scope": "范围是跨外部或敏感边界的 Web/API、DNS、邮件和选定工业/业务应用协议；声明方向、应用、路由、方法，以及能否解密内容还是只看元数据。",
          "build": "用正向/反向代理、WAF/API Gateway、应用防火墙或云服务执行正 Schema、认证上下文、限速和协议验证；策略随应用版本化，先观察后阻断，保护 Origin/旁路并监测引擎。",
          "proof": "发送有效、畸形、超大、未授权方法、编码和直连 Origin 请求及正常边界样本，验证 Permit/Block、应用健康和日志；测试替代端口/协议版本和服务商旁路，按受保护应用路径计覆盖。",
          "boundary": "CAS 没有指标，只问网络设备是否“覆盖”，评不了应用。"
        }
      },
      "category_counts": {
        "outcome": 7,
        "scope": 7,
        "ownership": 7,
        "data": 7,
        "integration": 7,
        "control": 7,
        "timing": 7,
        "exception": 7,
        "evidence": 7,
        "security": 7,
        "testing": 7,
        "operations": 7
      },
      "requirement_count": 84,
      "requirements": [
        {
          "code": "CIS-13.10-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "13.10",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Perform Application Layer Filtering; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“应用层过滤”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-13.10-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "13.10",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 13.10, official Asset Class Network, Security Function Protect, and IG3 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 13.10、官方资产类别“网络”、安全功能“保护”和首次出现的 IG3，并保存来源抓取日期。"
        },
        {
          "code": "CIS-13.10-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "13.10",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “The population is application protocols and requests crossing exposed or sensitive boundaries, including web/API, DNS, email and selected industrial/business protocols.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“范围是跨外部或敏感边界的 Web/API、DNS、邮件和选定工业/业务应用协议；声明方向、应用、路由、方法，以及能否解密内容还是只看元数据。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-13.10-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "13.10",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-13.10-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "13.10",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Perform Application Layer Filtering to its operating object—host, network, cloud, identity, application, and provider security signals, detections, prevention decisions, traffic boundaries, and response handoffs—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“应用层过滤”连接到其运营对象——主机、网络、云、身份、应用和提供商安全信号、检测、阻断决策、流量边界和响应交接——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-13.10-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "13.10",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "For Perform Application Layer Filtering, express success as an observable decision over complete, attributable, timely, protected, searchable, and actionable security telemetry plus source health; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“应用层过滤”，以 完整、可归因、及时、受保护、可检索、可行动的安全遥测及来源健康 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-13.10-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "13.10",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "For Perform Application Layer Filtering, express success as an observable decision over source-to-production software identity, design invariant, component trust, build provenance, test result, deployment state, runtime outcome, and vulnerability response; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“应用层过滤”，以 从源码到生产的软件身份、设计不变量、组件信任、构建来源、测试结果、部署状态、运行结果和漏洞响应 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-13.10-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "13.10",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-13.10-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "13.10",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-13.10-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "13.10",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-13.10-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "13.10",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-13.10-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "13.10",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across encrypted traffic, east-west and overlay paths, sensor blind spots, duplicate alerts, stale rules, threshold drift, provider outages, bypass protocols, and unsafe prevention; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 加密流量、东西向与覆盖路径、传感器盲区、重复告警、陈旧规则、阈值漂移、提供商中断、绕过协议和不安全阻断 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-13.10-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "13.10",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Include clock skew, actor loss, field truncation, parser drift, dropped or duplicate events, privacy redaction, provider gaps, encrypted paths, quota, and archive failure in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 时钟偏移、行为者丢失、字段截断、解析漂移、事件丢失或重复、隐私脱敏、提供商缺口、加密路径、配额和归档故障 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-13.10-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "13.10",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Include generated and copied code, forks, vendoring, transitive dependencies, mutable tags, build plugins, feature flags, tenant logic, secrets, emergency release, and provider components in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 生成与复制代码、分叉、vendoring、传递依赖、可变标签、构建插件、功能开关、租户逻辑、秘密、紧急发布和提供商组件 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-13.10-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "13.10",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-13.10-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "13.10",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-13.10-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "13.10",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-13.10-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "13.10",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-13.10-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "13.10",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind detection and security operations, endpoint/network/cloud engineering, threat intelligence, incident response, service owners, and risk owners to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 检测与安全运营、终端/网络/云工程、威胁情报、事件响应、服务责任人和风险责任人 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-13.10-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "13.10",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Name who may transition event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-13.10-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "13.10",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Name who may transition designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-13.10-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "13.10",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-13.10-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "13.10",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-13.10-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "13.10",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV5, GV35, M1, M2, M3) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV5, GV35, M1, M2, M3）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-13.10-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "13.10",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-13.10-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "13.10",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the monitored-surface inventory, detection content, threshold, and alert-case authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把受监测面清单、检测内容、阈值与告警案件权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-13.10-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "13.10",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired.",
          "zh": "对生命周期“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-13.10-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "13.10",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired.",
          "zh": "对生命周期“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-13.10-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "13.10",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 1.1, Safeguard 2.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 1.1、Safeguard 2.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-13.10-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "13.10",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-13.10-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "13.10",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-13.10-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "13.10",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-13.10-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "13.10",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile EDR/NDR/IDS/IPS, network and cloud flow, firewalls, NAC, identity, applications, providers, threat intelligence, SIEM, and case management and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 EDR/NDR/IDS/IPS、网络与云流量、防火墙、NAC、身份、应用、提供商、威胁情报、SIEM 和案件管理，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-13.10-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "13.10",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Require every connector carrying complete, attributable, timely, protected, searchable, and actionable security telemetry plus source health to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 完整、可归因、及时、受保护、可检索、可行动的安全遥测及来源健康 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-13.10-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "13.10",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Require every connector carrying source-to-production software identity, design invariant, component trust, build provenance, test result, deployment state, runtime outcome, and vulnerability response to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 从源码到生产的软件身份、设计不变量、组件信任、构建来源、测试结果、部署状态、运行结果和漏洞响应 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-13.10-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "13.10",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Use reverse/forward proxies, WAF/API gateways, application firewalls or cloud services with positive schemas, authentication context, rate limits and protocol validation.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“用正向/反向代理、WAF/API Gateway、应用防火墙或云服务执行正 Schema、认证上下文、限速和协议验证；策略随应用版本化，先观察后阻断，保护 Origin/旁路并监测引擎。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-13.10-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "13.10",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-13.10-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "13.10",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-13.10-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "13.10",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-13.10-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "13.10",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the monitored-surface inventory, detection content, threshold, and alert-case authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在受监测面清单、检测内容、阈值与告警案件权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-13.10-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "13.10",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Implement the explicit state machine event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-13.10-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "13.10",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Implement the explicit state machine designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-13.10-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "13.10",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-13.10-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "13.10",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-13.10-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "13.10",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-13.10-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "13.10",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-13.10-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "13.10",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in host, network, cloud, identity, application, and provider security signals, detections, prevention decisions, traffic boundaries, and response handoffs; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 主机、网络、云、身份、应用和提供商安全信号、检测、阻断决策、流量边界和响应交接 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-13.10-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "13.10",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired; alert before each deadline becomes overdue.",
          "zh": "为“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-13.10-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "13.10",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; alert before each deadline becomes overdue.",
          "zh": "为“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-13.10-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "13.10",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “The current CAS has no metric and only asks whether network assets are “covered,” which cannot assess applications.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“CAS 没有指标，只问网络设备是否“覆盖”，评不了应用。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-13.10-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "13.10",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-13.10-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "13.10",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-13.10-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "13.10",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-13.10-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "13.10",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat encrypted traffic, east-west and overlay paths, sensor blind spots, duplicate alerts, stale rules, threshold drift, provider outages, bypass protocols, and unsafe prevention as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 加密流量、东西向与覆盖路径、传感器盲区、重复告警、陈旧规则、阈值漂移、提供商中断、绕过协议和不安全阻断 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-13.10-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "13.10",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Treat clock skew, actor loss, field truncation, parser drift, dropped or duplicate events, privacy redaction, provider gaps, encrypted paths, quota, and archive failure as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 时钟偏移、行为者丢失、字段截断、解析漂移、事件丢失或重复、隐私脱敏、提供商缺口、加密路径、配额和归档故障 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-13.10-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "13.10",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Treat generated and copied code, forks, vendoring, transitive dependencies, mutable tags, build plugins, feature flags, tenant logic, secrets, emergency release, and provider components as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 生成与复制代码、分叉、vendoring、传递依赖、可变标签、构建插件、功能开关、租户逻辑、秘密、紧急发布和提供商组件 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-13.10-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "13.10",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Send valid, malformed, oversized, unauthorized-method, encoded and direct-origin requests plus legitimate edge cases; verify intended permit/block, application health and logs.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“发送有效、畸形、超大、未授权方法、编码和直连 Origin 请求及正常边界样本，验证 Permit/Block、应用健康和日志；测试替代端口/协议版本和服务商旁路，按受保护应用路径计覆盖。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-13.10-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "13.10",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-13.10-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "13.10",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 0 pinned CAS metric branch(es), 5 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 0 个指标分支、5 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-13.10-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "13.10",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-13.10-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "13.10",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the monitored-surface inventory, detection content, threshold, and alert-case authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以受监测面清单、检测内容、阈值与告警案件权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-13.10-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "13.10",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Publish healthy, silent, partial, late, malformed, duplicate, unowned, unreviewed, alerted, investigated, and archived sources or events with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 健康、静默、部分、迟到、畸形、重复、无责任人、未审阅、已告警、已调查和已归档来源或事件，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-13.10-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "13.10",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Publish reviewed, unreviewed, reproducible, provenance-bound, vulnerable, test-failed, exception, deployed-unverified, drifted, rolled-back, and regression-protected releases with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已评审、未评审、可复现、来源绑定、存在漏洞、测试失败、例外、已部署未验证、漂移、已回滚和受回归保护发布物，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-13.10-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "13.10",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-13.10-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "13.10",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-13.10-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "13.10",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-13.10-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "13.10",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-13.10-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "13.10",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the monitored-surface inventory, detection content, threshold, and alert-case authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护受监测面清单、检测内容、阈值与告警案件权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-13.10-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "13.10",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Restrict authority to change event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-13.10-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "13.10",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Restrict authority to change designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-13.10-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "13.10",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-13.10-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "13.10",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-13.10-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "13.10",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-13.10-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "13.10",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-13.10-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "13.10",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise benign and malicious-like canaries, sensor and collector loss, threshold boundaries, segmentation bypass, fail-open/closed behavior, rule rollback, and response escalation through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 安全与恶意特征金丝雀、传感器与采集器丢失、阈值边界、分段绕过、故障开闭、规则回滚和响应升级，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-13.10-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "13.10",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Run the positive control an allowed and denied canary event traced from source through review; exercise negative, stale, duplicate, bypass, and outage controls including source loss, parser/schema change, time skew, queue overflow, duplicate delivery, provider export outage, missed alert, and unreadable archive.",
          "zh": "运行正向控制“一项允许与拒绝金丝雀事件从来源贯穿到审阅”，并执行包含“来源丢失、解析器/模式变化、时钟偏移、队列溢出、重复投递、提供商导出中断、漏报和归档不可读”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-13.10-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "13.10",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Run the positive control a trusted build that preserves the security invariant through deployment and runtime; exercise negative, stale, duplicate, bypass, and outage controls including a substituted dependency, unreviewed change, poisoned build input, failed security test, bypass path, vulnerable release, rollback, and regression.",
          "zh": "运行正向控制“一个把安全不变量贯穿部署与运行的可信构建”，并执行包含“依赖替换、未评审变更、构建输入污染、安全测试失败、绕过路径、漏洞发布、回滚和回归”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-13.10-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "13.10",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-13.10-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "13.10",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-13.10-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "13.10",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-13.10-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "13.10",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-13.10-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "13.10",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever EDR/NDR/IDS/IPS, network and cloud flow, firewalls, NAC, identity, applications, providers, threat intelligence, SIEM, and case management change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 EDR/NDR/IDS/IPS、网络与云流量、防火墙、NAC、身份、应用、提供商、威胁情报、SIEM 和案件管理 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-13.10-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "13.10",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Use healthy, silent, partial, late, malformed, duplicate, unowned, unreviewed, alerted, investigated, and archived sources or events to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 健康、静默、部分、迟到、畸形、重复、无责任人、未审阅、已告警、已调查和已归档来源或事件 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-13.10-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "13.10",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Use reviewed, unreviewed, reproducible, provenance-bound, vulnerable, test-failed, exception, deployed-unverified, drifted, rolled-back, and regression-protected releases to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已评审、未评审、可复现、来源绑定、存在漏洞、测试失败、例外、已部署未验证、漂移、已回滚和受回归保护发布物 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "13.11",
      "control": 13,
      "title_en": "Tune Security Event Alerting Thresholds",
      "title_zh": "告警阈值调优",
      "first_ig": 3,
      "implementation_groups": [
        3
      ],
      "asset_class": "Network",
      "security_function": "Detect",
      "patterns": [
        "telemetry"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "13.1"
        ],
        "variables": [
          "GV42",
          "M1"
        ],
        "metric_branches": 0,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [
        "monthly"
      ],
      "implementation_contract": {
        "en": {
          "scope": "Tuning applies to rules, thresholds, baselines, suppressions, correlations and severity/routing across centralized security alerting, at least monthly.",
          "build": "Use adjudicated cases, threat/architecture changes, source health and analyst feedback to propose versioned changes; test against historical and synthetic positive/negative controls, peer-review, deploy gradually and retain rollback.",
          "proof": "Replay known true/false cases before and after each change and compare precision, recall on the controlled set, latency, volume and missed high-consequence scenarios.",
          "boundary": "CAS tests only the date of last tuning, so arbitrary monthly edits can pass while degrading coverage."
        },
        "zh": {
          "scope": "至少每月调优集中告警里的规则、阈值、基线、抑制、关联和严重度/路由；目标是可控地提升信号和覆盖，不是单纯降量。",
          "build": "根据已裁决案件、威胁/架构变化、源健康和分析反馈提出版本化变更；用历史与合成正负控测试，同行评审、渐进发布、可回滚，抑制到期，并监测检测漂移。",
          "proof": "变更前后回放已知真/假样本，比较受控集上的精度/召回、时延、量和漏高后果场景；验证一个 Canary 始终触发，即使本月无需改阈值也记录评估决定。",
          "boundary": "CAS 只看上次调优日期，任意月改也可过且可能劣化。"
        }
      },
      "category_counts": {
        "outcome": 6,
        "scope": 6,
        "ownership": 6,
        "data": 6,
        "integration": 6,
        "control": 6,
        "timing": 6,
        "exception": 6,
        "evidence": 6,
        "security": 6,
        "testing": 6,
        "operations": 6
      },
      "requirement_count": 72,
      "requirements": [
        {
          "code": "CIS-13.11-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "13.11",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Tune Security Event Alerting Thresholds; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“告警阈值调优”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-13.11-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "13.11",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 13.11, official Asset Class Network, Security Function Detect, and IG3 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 13.11、官方资产类别“网络”、安全功能“检测”和首次出现的 IG3，并保存来源抓取日期。"
        },
        {
          "code": "CIS-13.11-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "13.11",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Tuning applies to rules, thresholds, baselines, suppressions, correlations and severity/routing across centralized security alerting, at least monthly.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“至少每月调优集中告警里的规则、阈值、基线、抑制、关联和严重度/路由；目标是可控地提升信号和覆盖，不是单纯降量。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-13.11-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "13.11",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-13.11-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "13.11",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Tune Security Event Alerting Thresholds to its operating object—host, network, cloud, identity, application, and provider security signals, detections, prevention decisions, traffic boundaries, and response handoffs—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“告警阈值调优”连接到其运营对象——主机、网络、云、身份、应用和提供商安全信号、检测、阻断决策、流量边界和响应交接——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-13.11-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "13.11",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "For Tune Security Event Alerting Thresholds, express success as an observable decision over complete, attributable, timely, protected, searchable, and actionable security telemetry plus source health; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“告警阈值调优”，以 完整、可归因、及时、受保护、可检索、可行动的安全遥测及来源健康 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-13.11-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "13.11",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-13.11-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "13.11",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-13.11-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "13.11",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-13.11-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "13.11",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-13.11-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "13.11",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across encrypted traffic, east-west and overlay paths, sensor blind spots, duplicate alerts, stale rules, threshold drift, provider outages, bypass protocols, and unsafe prevention; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 加密流量、东西向与覆盖路径、传感器盲区、重复告警、陈旧规则、阈值漂移、提供商中断、绕过协议和不安全阻断 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-13.11-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "13.11",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Include clock skew, actor loss, field truncation, parser drift, dropped or duplicate events, privacy redaction, provider gaps, encrypted paths, quota, and archive failure in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 时钟偏移、行为者丢失、字段截断、解析漂移、事件丢失或重复、隐私脱敏、提供商缺口、加密路径、配额和归档故障 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-13.11-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "13.11",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-13.11-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "13.11",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-13.11-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "13.11",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-13.11-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "13.11",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-13.11-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "13.11",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind detection and security operations, endpoint/network/cloud engineering, threat intelligence, incident response, service owners, and risk owners to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 检测与安全运营、终端/网络/云工程、威胁情报、事件响应、服务责任人和风险责任人 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-13.11-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "13.11",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Name who may transition event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-13.11-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "13.11",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-13.11-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "13.11",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-13.11-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "13.11",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV42, M1) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV42, M1）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-13.11-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "13.11",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-13.11-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "13.11",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the monitored-surface inventory, detection content, threshold, and alert-case authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把受监测面清单、检测内容、阈值与告警案件权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-13.11-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "13.11",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired.",
          "zh": "对生命周期“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-13.11-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "13.11",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 13.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 13.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-13.11-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "13.11",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-13.11-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "13.11",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-13.11-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "13.11",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-13.11-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "13.11",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile EDR/NDR/IDS/IPS, network and cloud flow, firewalls, NAC, identity, applications, providers, threat intelligence, SIEM, and case management and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 EDR/NDR/IDS/IPS、网络与云流量、防火墙、NAC、身份、应用、提供商、威胁情报、SIEM 和案件管理，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-13.11-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "13.11",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Require every connector carrying complete, attributable, timely, protected, searchable, and actionable security telemetry plus source health to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 完整、可归因、及时、受保护、可检索、可行动的安全遥测及来源健康 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-13.11-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "13.11",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Use adjudicated cases, threat/architecture changes, source health and analyst feedback to propose versioned changes; test against historical and synthetic positive/negative controls, peer-review, deploy gradually and retain rollback.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“根据已裁决案件、威胁/架构变化、源健康和分析反馈提出版本化变更；用历史与合成正负控测试，同行评审、渐进发布、可回滚，抑制到期，并监测检测漂移。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-13.11-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "13.11",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-13.11-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "13.11",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-13.11-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "13.11",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-13.11-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "13.11",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the monitored-surface inventory, detection content, threshold, and alert-case authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在受监测面清单、检测内容、阈值与告警案件权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-13.11-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "13.11",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Implement the explicit state machine event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-13.11-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "13.11",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (monthly); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（monthly）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-13.11-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "13.11",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-13.11-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "13.11",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-13.11-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "13.11",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-13.11-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "13.11",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in host, network, cloud, identity, application, and provider security signals, detections, prevention decisions, traffic boundaries, and response handoffs; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 主机、网络、云、身份、应用和提供商安全信号、检测、阻断决策、流量边界和响应交接 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-13.11-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "13.11",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired; alert before each deadline becomes overdue.",
          "zh": "为“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-13.11-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "13.11",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “CAS tests only the date of last tuning, so arbitrary monthly edits can pass while degrading coverage.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“CAS 只看上次调优日期，任意月改也可过且可能劣化。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-13.11-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "13.11",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-13.11-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "13.11",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-13.11-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "13.11",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-13.11-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "13.11",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat encrypted traffic, east-west and overlay paths, sensor blind spots, duplicate alerts, stale rules, threshold drift, provider outages, bypass protocols, and unsafe prevention as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 加密流量、东西向与覆盖路径、传感器盲区、重复告警、陈旧规则、阈值漂移、提供商中断、绕过协议和不安全阻断 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-13.11-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "13.11",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Treat clock skew, actor loss, field truncation, parser drift, dropped or duplicate events, privacy redaction, provider gaps, encrypted paths, quota, and archive failure as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 时钟偏移、行为者丢失、字段截断、解析漂移、事件丢失或重复、隐私脱敏、提供商缺口、加密路径、配额和归档故障 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-13.11-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "13.11",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Replay known true/false cases before and after each change and compare precision, recall on the controlled set, latency, volume and missed high-consequence scenarios.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“变更前后回放已知真/假样本，比较受控集上的精度/召回、时延、量和漏高后果场景；验证一个 Canary 始终触发，即使本月无需改阈值也记录评估决定。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-13.11-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "13.11",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-13.11-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "13.11",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 0 pinned CAS metric branch(es), 2 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 0 个指标分支、2 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-13.11-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "13.11",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-13.11-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "13.11",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the monitored-surface inventory, detection content, threshold, and alert-case authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以受监测面清单、检测内容、阈值与告警案件权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-13.11-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "13.11",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Publish healthy, silent, partial, late, malformed, duplicate, unowned, unreviewed, alerted, investigated, and archived sources or events with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 健康、静默、部分、迟到、畸形、重复、无责任人、未审阅、已告警、已调查和已归档来源或事件，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-13.11-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "13.11",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-13.11-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "13.11",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-13.11-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "13.11",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-13.11-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "13.11",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-13.11-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "13.11",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the monitored-surface inventory, detection content, threshold, and alert-case authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护受监测面清单、检测内容、阈值与告警案件权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-13.11-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "13.11",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Restrict authority to change event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-13.11-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "13.11",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-13.11-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "13.11",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-13.11-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "13.11",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-13.11-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "13.11",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-13.11-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "13.11",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise benign and malicious-like canaries, sensor and collector loss, threshold boundaries, segmentation bypass, fail-open/closed behavior, rule rollback, and response escalation through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 安全与恶意特征金丝雀、传感器与采集器丢失、阈值边界、分段绕过、故障开闭、规则回滚和响应升级，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-13.11-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "13.11",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Run the positive control an allowed and denied canary event traced from source through review; exercise negative, stale, duplicate, bypass, and outage controls including source loss, parser/schema change, time skew, queue overflow, duplicate delivery, provider export outage, missed alert, and unreadable archive.",
          "zh": "运行正向控制“一项允许与拒绝金丝雀事件从来源贯穿到审阅”，并执行包含“来源丢失、解析器/模式变化、时钟偏移、队列溢出、重复投递、提供商导出中断、漏报和归档不可读”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-13.11-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "13.11",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-13.11-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "13.11",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-13.11-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "13.11",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-13.11-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "13.11",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-13.11-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "13.11",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever EDR/NDR/IDS/IPS, network and cloud flow, firewalls, NAC, identity, applications, providers, threat intelligence, SIEM, and case management change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 EDR/NDR/IDS/IPS、网络与云流量、防火墙、NAC、身份、应用、提供商、威胁情报、SIEM 和案件管理 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-13.11-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "13.11",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Use healthy, silent, partial, late, malformed, duplicate, unowned, unreviewed, alerted, investigated, and archived sources or events to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 健康、静默、部分、迟到、畸形、重复、无责任人、未审阅、已告警、已调查和已归档来源或事件 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "14.1",
      "control": 14,
      "title_en": "Establish and Maintain a Security Awareness Program",
      "title_zh": "安全意识计划",
      "first_ig": 1,
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Documentation",
      "security_function": "Govern",
      "patterns": [
        "training",
        "governance"
      ],
      "expanded_complexity": true,
      "cas_context": {
        "dependencies": [],
        "variables": [
          "GV43",
          "M1",
          "M2",
          "M3",
          "M4",
          "M5",
          "M6",
          "M7"
        ],
        "metric_branches": 2,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [
        "annually"
      ],
      "implementation_contract": {
        "en": {
          "scope": "The workforce population includes employees, contractors, temporary staff, interns, executives and other people using enterprise assets or data, with language, accessibility, role, location and start-date considerations.",
          "build": "Train at hire and at least annually, update content annually and after meaningful threat/business change, provide accessible/localized channels, safe reporting and role-based reinforcement.",
          "proof": "Reconcile authoritative workforce rosters to completion, test new-hire timing and content comprehension with scenario decisions, then measure reporting, repeat-risk and intervention outcomes over time.",
          "boundary": "Completion records attendance; separate tests establish understanding and behavior."
        },
        "zh": {
          "scope": "总体包括员工、承包商、临时工、实习、管理层及其他使用企业资产/数据的人，并考虑语言、无障碍、角色、地点和入职时间。",
          "build": "入职及至少每年培训，内容每年和威胁/业务重大变化后更新，提供可访问、本地化、无障碍与安全报告；HR 管总体/时间，安全管风险/内容，经理闭环未完成，不用羞辱性演练。",
          "proof": "用权威人员名册对账完成，测试入职时点和场景理解，再长期看报告、重复风险和干预结果；抽查承包商与无障碍人群，单列逾期/无法触达。",
          "boundary": "完成不证明理解或行为。"
        }
      },
      "category_counts": {
        "outcome": 8,
        "scope": 8,
        "ownership": 8,
        "data": 8,
        "integration": 8,
        "control": 8,
        "timing": 8,
        "exception": 8,
        "evidence": 8,
        "security": 8,
        "testing": 8,
        "operations": 8
      },
      "requirement_count": 96,
      "requirements": [
        {
          "code": "CIS-14.1-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "14.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Establish and Maintain a Security Awareness Program; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“安全意识计划”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-14.1-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "14.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 14.1, official Asset Class Documentation, Security Function Govern, and IG1 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 14.1、官方资产类别“文档与治理”、安全功能“治理”和首次出现的 IG1，并保存来源抓取日期。"
        },
        {
          "code": "CIS-14.1-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "14.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “The workforce population includes employees, contractors, temporary staff, interns, executives and other people using enterprise assets or data, with language, accessibility, role, location and start-date considerations.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“总体包括员工、承包商、临时工、实习、管理层及其他使用企业资产/数据的人，并考虑语言、无障碍、角色、地点和入职时间。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-14.1-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "14.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-14.1-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "14.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Establish and Maintain a Security Awareness Program to its operating object—workforce roles, required security decisions and skills, training content, participation, comprehension, behavior, reporting, and retraining—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“安全意识计划”连接到其运营对象——人员角色、必需安全决策与技能、培训内容、参与、理解、行为、报告和再培训——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-14.1-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "14.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "For Establish and Maintain a Security Awareness Program, express success as an observable decision over role-specific knowledge, practiced decision, reporting behavior, measurable comprehension, and retraining outcome; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“安全意识计划”，以 岗位相关知识、练习过的决策、报告行为、可测理解和再培训结果 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-14.1-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "14.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "For Establish and Maintain a Security Awareness Program, express success as an observable decision over a documented decision system with policy, process, procedure, accountable owner, approval, and review; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“安全意识计划”，以 包含策略、流程、程序、责任人、审批和复核的文档化决策系统 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-14.1-OUT-08",
          "local_code": "OUT-08",
          "display_code": "O08",
          "safeguard_id": "14.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "For the expanded Establish and Maintain a Security Awareness Program scope, resolve conflicts among security, safety, privacy, legal, availability, customer, and operational objectives through an explicit risk decision.",
          "zh": "对“安全意识计划”的扩展范围，通过显式风险决策解决安全、安全生产、隐私、法律、可用性、客户和运营目标冲突。"
        },
        {
          "code": "CIS-14.1-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "14.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-14.1-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "14.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-14.1-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "14.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-14.1-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "14.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-14.1-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "14.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across contractors, temporary and privileged roles, accessibility and language needs, absence, role changes, remote work, simulated-test harm, completion without comprehension, and AI-assisted work; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 承包商、临时与特权角色、无障碍和语言需求、缺席、角色变化、远程工作、模拟伤害、完成却未理解以及 AI 辅助工作 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-14.1-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "14.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Include new hires, contractors, temporary and privileged roles, role changes, accessibility and language needs, absence, remote work, simulation harm, and completion without comprehension in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 新员工、承包商、临时与特权角色、角色变化、无障碍和语言需求、缺席、远程工作、模拟伤害及完成却未理解 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-14.1-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "14.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Include missing policy clauses, conflicting authorities, local deviations, obsolete documentation, and decisions made outside the governed workflow in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 策略条款缺失、权限冲突、本地偏离、文档过期及绕过治理流程的决策 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-14.1-SCP-08",
          "local_code": "SCP-08",
          "display_code": "P08",
          "safeguard_id": "14.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Define nested scope at enterprise, business service, tenant, environment, platform, object, identity, data set, and transaction levels; prohibit a parent result from hiding a failing child.",
          "zh": "按企业、业务服务、租户、环境、平台、对象、身份、数据集和交易定义嵌套范围，禁止父级结果遮蔽失败子级。"
        },
        {
          "code": "CIS-14.1-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "14.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-14.1-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "14.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-14.1-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "14.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-14.1-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "14.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-14.1-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "14.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind security awareness owners, HR, managers, role experts, legal/privacy, incident response, and workforce members to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 安全意识责任人、HR、直属经理、岗位专家、法务/隐私、事件响应和人员成员 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-14.1-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "14.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Name who may transition need identified → objective and scenario designed → assigned → practiced/assessed → remediated → behavior reviewed → content renewed, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 识别需要 → 设计目标与情境 → 分配 → 练习/评估 → 补救 → 复核行为 → 更新内容，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-14.1-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "14.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Name who may transition draft → reviewed → approved → effective → exception/withdrawn → superseded, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-14.1-OWN-08",
          "local_code": "OWN-08",
          "display_code": "W08",
          "safeguard_id": "14.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Model delegated authority, quorum or dual approval where warranted, escalation deadlines, provider handoffs, conflict resolution, and executive risk acceptance.",
          "zh": "建模委派权限、必要时的双人或法定人数审批、升级期限、提供商交接、冲突解决和管理层风险接受。"
        },
        {
          "code": "CIS-14.1-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "14.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-14.1-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "14.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-14.1-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "14.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV43, M1, M2, M3, M4, M5, M6, M7) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV43, M1, M2, M3, M4, M5, M6, M7）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-14.1-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "14.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-14.1-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "14.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the role-to-learning-objective, assignment, completion, and observed-behavior authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把角色—学习目标—分配—完成—行为结果权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-14.1-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "14.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle need identified → objective and scenario designed → assigned → practiced/assessed → remediated → behavior reviewed → content renewed.",
          "zh": "对生命周期“识别需要 → 设计目标与情境 → 分配 → 练习/评估 → 补救 → 复核行为 → 更新内容”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-14.1-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "14.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle draft → reviewed → approved → effective → exception/withdrawn → superseded.",
          "zh": "对生命周期“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-14.1-DAT-08",
          "local_code": "DAT-08",
          "display_code": "D08",
          "safeguard_id": "14.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Version schemas and state transitions with migration, backfill, deduplication, lineage, historical denominator, deletion, and rollback semantics.",
          "zh": "对模式和状态转换做版本管理，定义迁移、回填、去重、血缘、历史分母、删除和回滚语义。"
        },
        {
          "code": "CIS-14.1-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "14.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for no explicit predecessor in the pinned CAS page; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 固定 CAS 页面没有列出显式前置项 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-14.1-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "14.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-14.1-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "14.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-14.1-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "14.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-14.1-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "14.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile HR and role data, learning platforms, policy and threat changes, simulations, helpdesk and incident reports, assessments, and manager attestations and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 HR 与角色数据、学习平台、策略与威胁变化、模拟、服务台与事件报告、评估和经理确认，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-14.1-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "14.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Require every connector carrying role-specific knowledge, practiced decision, reporting behavior, measurable comprehension, and retraining outcome to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 岗位相关知识、练习过的决策、报告行为、可测理解和再培训结果 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-14.1-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "14.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Require every connector carrying a documented decision system with policy, process, procedure, accountable owner, approval, and review to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 包含策略、流程、程序、责任人、审批和复核的文档化决策系统 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-14.1-INT-08",
          "local_code": "INT-08",
          "display_code": "I08",
          "safeguard_id": "14.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Define consistency rules across disagreeing sources, source precedence, confidence, reconciliation queues, dead-letter handling, reprocessing, and end-to-end trace identity.",
          "zh": "定义冲突来源的一致性、优先级、置信度、对账队列、死信、重处理和端到端追踪身份。"
        },
        {
          "code": "CIS-14.1-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "14.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Train at hire and at least annually, update content annually and after meaningful threat/business change, provide accessible/localized channels, safe reporting and role-based reinforcement.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“入职及至少每年培训，内容每年和威胁/业务重大变化后更新，提供可访问、本地化、无障碍与安全报告；HR 管总体/时间，安全管风险/内容，经理闭环未完成，不用羞辱性演练。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-14.1-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "14.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-14.1-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "14.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-14.1-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "14.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-14.1-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "14.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the role-to-learning-objective, assignment, completion, and observed-behavior authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在角色—学习目标—分配—完成—行为结果权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-14.1-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "14.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Implement the explicit state machine need identified → objective and scenario designed → assigned → practiced/assessed → remediated → behavior reviewed → content renewed; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“识别需要 → 设计目标与情境 → 分配 → 练习/评估 → 补救 → 复核行为 → 更新内容”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-14.1-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "14.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Implement the explicit state machine draft → reviewed → approved → effective → exception/withdrawn → superseded; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-14.1-CTL-08",
          "local_code": "CTL-08",
          "display_code": "C08",
          "safeguard_id": "14.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Specify concurrent decisions, partial success, compensating transactions, repeated requests, stale policy, dependency outage, and recovery from an interrupted state transition.",
          "zh": "定义并发决策、部分成功、补偿事务、重复请求、陈旧策略、依赖中断和中途状态转换恢复。"
        },
        {
          "code": "CIS-14.1-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "14.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (annually); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（annually）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-14.1-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "14.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-14.1-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "14.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-14.1-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "14.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-14.1-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "14.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in workforce roles, required security decisions and skills, training content, participation, comprehension, behavior, reporting, and retraining; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 人员角色、必需安全决策与技能、培训内容、参与、理解、行为、报告和再培训 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-14.1-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "14.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for need identified → objective and scenario designed → assigned → practiced/assessed → remediated → behavior reviewed → content renewed; alert before each deadline becomes overdue.",
          "zh": "为“识别需要 → 设计目标与情境 → 分配 → 练习/评估 → 补救 → 复核行为 → 更新内容”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-14.1-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "14.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for draft → reviewed → approved → effective → exception/withdrawn → superseded; alert before each deadline becomes overdue.",
          "zh": "为“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-14.1-TIM-08",
          "local_code": "TIM-08",
          "display_code": "T08",
          "safeguard_id": "14.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Allocate an end-to-end SLO budget across discovery, collection, processing, approval, enforcement, verification, and closure; prioritize overdue work by consequence and exposure.",
          "zh": "把端到端 SLO 预算分配到发现、采集、处理、审批、执行、验证和关闭，并按后果与暴露排列逾期工作。"
        },
        {
          "code": "CIS-14.1-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "14.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “Completion records attendance; separate tests establish understanding and behavior.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“完成不证明理解或行为。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-14.1-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "14.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-14.1-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "14.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-14.1-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "14.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-14.1-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "14.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat contractors, temporary and privileged roles, accessibility and language needs, absence, role changes, remote work, simulated-test harm, completion without comprehension, and AI-assisted work as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 承包商、临时与特权角色、无障碍和语言需求、缺席、角色变化、远程工作、模拟伤害、完成却未理解以及 AI 辅助工作 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-14.1-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "14.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Treat new hires, contractors, temporary and privileged roles, role changes, accessibility and language needs, absence, remote work, simulation harm, and completion without comprehension as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 新员工、承包商、临时与特权角色、角色变化、无障碍和语言需求、缺席、远程工作、模拟伤害及完成却未理解 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-14.1-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "14.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Treat missing policy clauses, conflicting authorities, local deviations, obsolete documentation, and decisions made outside the governed workflow as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 策略条款缺失、权限冲突、本地偏离、文档过期及绕过治理流程的决策 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-14.1-EXC-08",
          "local_code": "EXC-08",
          "display_code": "X08",
          "safeguard_id": "14.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Exercise compound failures where an exception, stale source, provider outage, unavailable owner, and degraded control overlap; define one safe command and one accountable decision.",
          "zh": "演练例外、陈旧来源、提供商中断、责任人不可用和控制降级同时出现的复合故障，明确一条安全指令和一个责任决策。"
        },
        {
          "code": "CIS-14.1-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "14.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Reconcile authoritative workforce rosters to completion, test new-hire timing and content comprehension with scenario decisions, then measure reporting, repeat-risk and intervention outcomes over time.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“用权威人员名册对账完成，测试入职时点和场景理解，再长期看报告、重复风险和干预结果；抽查承包商与无障碍人群，单列逾期/无法触达。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-14.1-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "14.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-14.1-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "14.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 2 pinned CAS metric branch(es), 8 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 2 个指标分支、8 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-14.1-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "14.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-14.1-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "14.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the role-to-learning-objective, assignment, completion, and observed-behavior authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以角色—学习目标—分配—完成—行为结果权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-14.1-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "14.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Publish assigned, started, completed, passed, failed, overdue, exempted, role-mismatched, retrained, reported, and behavior-improved learners with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已分配、已开始、已完成、通过、失败、逾期、豁免、岗位不匹配、再培训、已报告和行为改善人员，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-14.1-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "14.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Publish clause coverage, owner and reviewer completeness, approval age, triggered reviews, deviations, overdue actions, and superseded versions still in use with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 条款覆盖、责任人与复核人完整性、批准年龄、触发式复核、偏离、逾期行动及仍在使用的旧版本，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-14.1-EVD-08",
          "local_code": "EVD-08",
          "display_code": "E08",
          "safeguard_id": "14.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Require an independent party to reconstruct the decision from source receipts and reproduce the population, state transition, calculation, test result, exception, and final closure.",
          "zh": "要求独立人员使用来源回执重建决策，并复现总体、状态转换、计算、测试结果、例外和最终关闭。"
        },
        {
          "code": "CIS-14.1-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "14.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-14.1-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "14.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-14.1-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "14.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-14.1-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "14.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-14.1-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "14.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the role-to-learning-objective, assignment, completion, and observed-behavior authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护角色—学习目标—分配—完成—行为结果权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-14.1-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "14.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Restrict authority to change need identified → objective and scenario designed → assigned → practiced/assessed → remediated → behavior reviewed → content renewed; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“识别需要 → 设计目标与情境 → 分配 → 练习/评估 → 补救 → 复核行为 → 更新内容”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-14.1-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "14.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Restrict authority to change draft → reviewed → approved → effective → exception/withdrawn → superseded; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-14.1-SEC-08",
          "local_code": "SEC-08",
          "display_code": "S08",
          "safeguard_id": "14.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Threat-model the implementation system itself: forged evidence, poisoned inventory, privilege abuse, cross-tenant confusion, policy rollback, audit deletion, denial of service, and recovery compromise.",
          "zh": "威胁建模实施系统自身：伪造证据、污染清单、权限滥用、跨租户混淆、策略回滚、审计删除、拒绝服务和恢复失陷。"
        },
        {
          "code": "CIS-14.1-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "14.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-14.1-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "14.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-14.1-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "14.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-14.1-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "14.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-14.1-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "14.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise knowledge and scenario checks, correct and incorrect decisions, report-channel use, role change, simulated social engineering, missed training, and retraining effectiveness through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 知识与情境检查、正确与错误决策、报告通道使用、角色变化、社会工程模拟、漏训和再培训效果，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-14.1-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "14.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Run the positive control a representative learner making and reporting the secure decision in a realistic scenario; exercise negative, stale, duplicate, bypass, and outage controls including a missed assignment, incorrect decision, inaccessible content, stale scenario, role mismatch, failed report channel, and ineffective retraining.",
          "zh": "运行正向控制“代表性人员在真实情境中作出并报告安全决策”，并执行包含“漏分配、错误决策、内容不可访问、情境陈旧、岗位不匹配、报告通道失败和再培训无效”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-14.1-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "14.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Run the positive control an approved current process used for a representative decision; exercise negative, stale, duplicate, bypass, and outage controls including an obsolete version, missing approver, undocumented deviation, overdue review, and bypassed workflow.",
          "zh": "运行正向控制“使用当前获批流程完成一项代表性决策”，并执行包含“旧版本、审批人缺失、未记录偏离、逾期复核和绕过流程”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-14.1-TST-08",
          "local_code": "TST-08",
          "display_code": "V08",
          "safeguard_id": "14.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Build a pairwise platform-and-failure matrix, then add high-consequence multi-factor cases, historical regression, source substitution, red-team challenge, and assessor replay.",
          "zh": "建立平台—故障两两组合矩阵，再加入高后果多因素案例、历史回归、来源替换、红队挑战和评估方重放。"
        },
        {
          "code": "CIS-14.1-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "14.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-14.1-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "14.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-14.1-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "14.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-14.1-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "14.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-14.1-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "14.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever HR and role data, learning platforms, policy and threat changes, simulations, helpdesk and incident reports, assessments, and manager attestations change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 HR 与角色数据、学习平台、策略与威胁变化、模拟、服务台与事件报告、评估和经理确认 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-14.1-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "14.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Use assigned, started, completed, passed, failed, overdue, exempted, role-mismatched, retrained, reported, and behavior-improved learners to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已分配、已开始、已完成、通过、失败、逾期、豁免、岗位不匹配、再培训、已报告和行为改善人员 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-14.1-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "14.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Use clause coverage, owner and reviewer completeness, approval age, triggered reviews, deviations, overdue actions, and superseded versions still in use to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 条款覆盖、责任人与复核人完整性、批准年龄、触发式复核、偏离、逾期行动及仍在使用的旧版本 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-14.1-OPS-08",
          "local_code": "OPS-08",
          "display_code": "R08",
          "safeguard_id": "14.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Use canary deployment, kill criteria, rollback, backlog burn-down, exception reduction, source-quality targets, quarterly design review, and a measurable retirement plan.",
          "zh": "采用金丝雀、停止标准、回滚、积压燃尽、例外缩减、来源质量目标、季度设计复核和可量化退役计划。"
        }
      ]
    },
    {
      "id": "14.2",
      "control": 14,
      "title_en": "Train Workforce Members to Recognize Social Engineering Attacks",
      "title_zh": "社会工程识别",
      "first_ig": 1,
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Users",
      "security_function": "Protect",
      "patterns": [
        "training"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [],
        "variables": [
          "GV43",
          "M1",
          "M2",
          "M3",
          "M4",
          "M5",
          "M6"
        ],
        "metric_branches": 2,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "Training covers phishing, business email compromise, voice/video impersonation, QR codes, messaging, support scams, tailgating and AI-enabled pretexting across work and personal channels used for business.",
          "build": "Teach observable cues, independent verification of money/credential/data requests, no-blame reporting and what to do after interaction.",
          "proof": "Use varied, ethical simulations and tabletop scenarios with positive and ambiguous controls; measure timely reporting, correct verification and response, not clicks alone.",
          "boundary": "Highly convincing attacks may lack visible cues, so technical controls and dual authorization remain necessary."
        },
        "zh": {
          "scope": "覆盖钓鱼、BEC、语音/视频冒充、二维码、即时消息、支持诈骗、尾随和 AI 预设，横跨工作与用于工作的个人渠道；识别必须连接立即可用的报告路径。",
          "build": "讲可观察线索、独立核验资金/凭据/数据请求、无责报告和事后动作；按真实角色/语言给例子，结合当前活动强化，同时让 Helpdesk/财务流程能抵抗冒充，不能把责任全推给用户。",
          "proof": "用多样、合乎伦理的模拟和桌演，带正常/模糊对照；衡量及时报告、正确核验和响应，不只点击。",
          "boundary": "高度逼真攻击可能没有明显线索，所以仍需技术与双人授权。"
        }
      },
      "category_counts": {
        "outcome": 6,
        "scope": 6,
        "ownership": 6,
        "data": 6,
        "integration": 6,
        "control": 6,
        "timing": 6,
        "exception": 6,
        "evidence": 6,
        "security": 6,
        "testing": 6,
        "operations": 6
      },
      "requirement_count": 72,
      "requirements": [
        {
          "code": "CIS-14.2-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "14.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Train Workforce Members to Recognize Social Engineering Attacks; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“社会工程识别”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-14.2-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "14.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 14.2, official Asset Class Users, Security Function Protect, and IG1 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 14.2、官方资产类别“用户与身份”、安全功能“保护”和首次出现的 IG1，并保存来源抓取日期。"
        },
        {
          "code": "CIS-14.2-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "14.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Training covers phishing, business email compromise, voice/video impersonation, QR codes, messaging, support scams, tailgating and AI-enabled pretexting across work and personal channels used for business.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“覆盖钓鱼、BEC、语音/视频冒充、二维码、即时消息、支持诈骗、尾随和 AI 预设，横跨工作与用于工作的个人渠道；识别必须连接立即可用的报告路径。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-14.2-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "14.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-14.2-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "14.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Train Workforce Members to Recognize Social Engineering Attacks to its operating object—workforce roles, required security decisions and skills, training content, participation, comprehension, behavior, reporting, and retraining—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“社会工程识别”连接到其运营对象——人员角色、必需安全决策与技能、培训内容、参与、理解、行为、报告和再培训——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-14.2-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "14.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "For Train Workforce Members to Recognize Social Engineering Attacks, express success as an observable decision over role-specific knowledge, practiced decision, reporting behavior, measurable comprehension, and retraining outcome; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“社会工程识别”，以 岗位相关知识、练习过的决策、报告行为、可测理解和再培训结果 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-14.2-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "14.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-14.2-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "14.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-14.2-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "14.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-14.2-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "14.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-14.2-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "14.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across contractors, temporary and privileged roles, accessibility and language needs, absence, role changes, remote work, simulated-test harm, completion without comprehension, and AI-assisted work; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 承包商、临时与特权角色、无障碍和语言需求、缺席、角色变化、远程工作、模拟伤害、完成却未理解以及 AI 辅助工作 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-14.2-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "14.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Include new hires, contractors, temporary and privileged roles, role changes, accessibility and language needs, absence, remote work, simulation harm, and completion without comprehension in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 新员工、承包商、临时与特权角色、角色变化、无障碍和语言需求、缺席、远程工作、模拟伤害及完成却未理解 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-14.2-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "14.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-14.2-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "14.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-14.2-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "14.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-14.2-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "14.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-14.2-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "14.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind security awareness owners, HR, managers, role experts, legal/privacy, incident response, and workforce members to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 安全意识责任人、HR、直属经理、岗位专家、法务/隐私、事件响应和人员成员 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-14.2-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "14.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Name who may transition need identified → objective and scenario designed → assigned → practiced/assessed → remediated → behavior reviewed → content renewed, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 识别需要 → 设计目标与情境 → 分配 → 练习/评估 → 补救 → 复核行为 → 更新内容，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-14.2-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "14.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-14.2-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "14.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-14.2-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "14.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV43, M1, M2, M3, M4, M5, M6) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV43, M1, M2, M3, M4, M5, M6）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-14.2-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "14.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-14.2-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "14.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the role-to-learning-objective, assignment, completion, and observed-behavior authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把角色—学习目标—分配—完成—行为结果权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-14.2-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "14.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle need identified → objective and scenario designed → assigned → practiced/assessed → remediated → behavior reviewed → content renewed.",
          "zh": "对生命周期“识别需要 → 设计目标与情境 → 分配 → 练习/评估 → 补救 → 复核行为 → 更新内容”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-14.2-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "14.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for no explicit predecessor in the pinned CAS page; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 固定 CAS 页面没有列出显式前置项 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-14.2-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "14.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-14.2-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "14.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-14.2-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "14.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-14.2-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "14.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile HR and role data, learning platforms, policy and threat changes, simulations, helpdesk and incident reports, assessments, and manager attestations and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 HR 与角色数据、学习平台、策略与威胁变化、模拟、服务台与事件报告、评估和经理确认，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-14.2-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "14.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Require every connector carrying role-specific knowledge, practiced decision, reporting behavior, measurable comprehension, and retraining outcome to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 岗位相关知识、练习过的决策、报告行为、可测理解和再培训结果 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-14.2-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "14.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Teach observable cues, independent verification of money/credential/data requests, no-blame reporting and what to do after interaction.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“讲可观察线索、独立核验资金/凭据/数据请求、无责报告和事后动作；按真实角色/语言给例子，结合当前活动强化，同时让 Helpdesk/财务流程能抵抗冒充，不能把责任全推给用户。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-14.2-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "14.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-14.2-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "14.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-14.2-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "14.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-14.2-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "14.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the role-to-learning-objective, assignment, completion, and observed-behavior authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在角色—学习目标—分配—完成—行为结果权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-14.2-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "14.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Implement the explicit state machine need identified → objective and scenario designed → assigned → practiced/assessed → remediated → behavior reviewed → content renewed; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“识别需要 → 设计目标与情境 → 分配 → 练习/评估 → 补救 → 复核行为 → 更新内容”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-14.2-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "14.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-14.2-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "14.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-14.2-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "14.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-14.2-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "14.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-14.2-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "14.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in workforce roles, required security decisions and skills, training content, participation, comprehension, behavior, reporting, and retraining; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 人员角色、必需安全决策与技能、培训内容、参与、理解、行为、报告和再培训 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-14.2-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "14.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for need identified → objective and scenario designed → assigned → practiced/assessed → remediated → behavior reviewed → content renewed; alert before each deadline becomes overdue.",
          "zh": "为“识别需要 → 设计目标与情境 → 分配 → 练习/评估 → 补救 → 复核行为 → 更新内容”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-14.2-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "14.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “Highly convincing attacks may lack visible cues, so technical controls and dual authorization remain necessary.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“高度逼真攻击可能没有明显线索，所以仍需技术与双人授权。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-14.2-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "14.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-14.2-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "14.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-14.2-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "14.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-14.2-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "14.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat contractors, temporary and privileged roles, accessibility and language needs, absence, role changes, remote work, simulated-test harm, completion without comprehension, and AI-assisted work as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 承包商、临时与特权角色、无障碍和语言需求、缺席、角色变化、远程工作、模拟伤害、完成却未理解以及 AI 辅助工作 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-14.2-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "14.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Treat new hires, contractors, temporary and privileged roles, role changes, accessibility and language needs, absence, remote work, simulation harm, and completion without comprehension as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 新员工、承包商、临时与特权角色、角色变化、无障碍和语言需求、缺席、远程工作、模拟伤害及完成却未理解 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-14.2-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "14.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Use varied, ethical simulations and tabletop scenarios with positive and ambiguous controls; measure timely reporting, correct verification and response, not clicks alone.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“用多样、合乎伦理的模拟和桌演，带正常/模糊对照；衡量及时报告、正确核验和响应，不只点击。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-14.2-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "14.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-14.2-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "14.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 2 pinned CAS metric branch(es), 7 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 2 个指标分支、7 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-14.2-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "14.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-14.2-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "14.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the role-to-learning-objective, assignment, completion, and observed-behavior authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以角色—学习目标—分配—完成—行为结果权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-14.2-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "14.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Publish assigned, started, completed, passed, failed, overdue, exempted, role-mismatched, retrained, reported, and behavior-improved learners with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已分配、已开始、已完成、通过、失败、逾期、豁免、岗位不匹配、再培训、已报告和行为改善人员，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-14.2-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "14.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-14.2-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "14.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-14.2-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "14.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-14.2-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "14.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-14.2-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "14.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the role-to-learning-objective, assignment, completion, and observed-behavior authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护角色—学习目标—分配—完成—行为结果权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-14.2-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "14.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Restrict authority to change need identified → objective and scenario designed → assigned → practiced/assessed → remediated → behavior reviewed → content renewed; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“识别需要 → 设计目标与情境 → 分配 → 练习/评估 → 补救 → 复核行为 → 更新内容”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-14.2-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "14.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-14.2-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "14.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-14.2-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "14.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-14.2-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "14.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-14.2-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "14.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise knowledge and scenario checks, correct and incorrect decisions, report-channel use, role change, simulated social engineering, missed training, and retraining effectiveness through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 知识与情境检查、正确与错误决策、报告通道使用、角色变化、社会工程模拟、漏训和再培训效果，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-14.2-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "14.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Run the positive control a representative learner making and reporting the secure decision in a realistic scenario; exercise negative, stale, duplicate, bypass, and outage controls including a missed assignment, incorrect decision, inaccessible content, stale scenario, role mismatch, failed report channel, and ineffective retraining.",
          "zh": "运行正向控制“代表性人员在真实情境中作出并报告安全决策”，并执行包含“漏分配、错误决策、内容不可访问、情境陈旧、岗位不匹配、报告通道失败和再培训无效”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-14.2-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "14.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-14.2-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "14.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-14.2-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "14.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-14.2-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "14.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-14.2-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "14.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever HR and role data, learning platforms, policy and threat changes, simulations, helpdesk and incident reports, assessments, and manager attestations change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 HR 与角色数据、学习平台、策略与威胁变化、模拟、服务台与事件报告、评估和经理确认 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-14.2-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "14.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Use assigned, started, completed, passed, failed, overdue, exempted, role-mismatched, retrained, reported, and behavior-improved learners to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已分配、已开始、已完成、通过、失败、逾期、豁免、岗位不匹配、再培训、已报告和行为改善人员 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "14.3",
      "control": 14,
      "title_en": "Train Workforce Members on Authentication Best Practices",
      "title_zh": "认证最佳实践",
      "first_ig": 1,
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Users",
      "security_function": "Protect",
      "patterns": [
        "training",
        "identity"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [],
        "variables": [
          "GV43",
          "M1",
          "M2",
          "M3",
          "M4",
          "M5",
          "M6"
        ],
        "metric_branches": 2,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "Scope passwords, MFA, passkeys, recovery, device prompts, password managers, service-desk identity proofing and credential handling for every workforce account type.",
          "build": "Teach unique managed passwords, phishing-resistant MFA, prompt verification, no credential sharing, secure recovery and immediate reporting.",
          "proof": "Run scenario questions and safe unexpected-prompt/recovery exercises, then measure correct rejection/reporting and password-manager/MFA adoption without collecting secrets.",
          "boundary": "Training cannot fix legacy shared accounts, MFA fatigue or a weak reset process."
        },
        "zh": {
          "scope": "覆盖所有人员账户的口令、MFA、Passkey、恢复、设备 Prompt、密码管理器与 Helpdesk 核验。",
          "build": "讲唯一受管口令、抗钓鱼 MFA、Prompt 核验、不共享凭据、安全恢复和立即报告；同时提供好用的批准工具，移除会逼人绕过的政策，认证方法/攻击变化时刷新。",
          "proof": "用场景和安全的意外 Prompt/恢复演练，测拒绝/报告与密码管理器/MFA 采用，绝不收集秘密；检查 Support 是否也执行教给用户的身份核验。",
          "boundary": "培训修不好共享旧账户、MFA Fatigue 和弱重置。"
        }
      },
      "category_counts": {
        "outcome": 7,
        "scope": 7,
        "ownership": 7,
        "data": 7,
        "integration": 7,
        "control": 7,
        "timing": 7,
        "exception": 7,
        "evidence": 7,
        "security": 7,
        "testing": 7,
        "operations": 7
      },
      "requirement_count": 84,
      "requirements": [
        {
          "code": "CIS-14.3-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "14.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Train Workforce Members on Authentication Best Practices; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“认证最佳实践”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-14.3-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "14.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 14.3, official Asset Class Users, Security Function Protect, and IG1 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 14.3、官方资产类别“用户与身份”、安全功能“保护”和首次出现的 IG1，并保存来源抓取日期。"
        },
        {
          "code": "CIS-14.3-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "14.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Scope passwords, MFA, passkeys, recovery, device prompts, password managers, service-desk identity proofing and credential handling for every workforce account type.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“覆盖所有人员账户的口令、MFA、Passkey、恢复、设备 Prompt、密码管理器与 Helpdesk 核验。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-14.3-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "14.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-14.3-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "14.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Train Workforce Members on Authentication Best Practices to its operating object—workforce roles, required security decisions and skills, training content, participation, comprehension, behavior, reporting, and retraining—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“认证最佳实践”连接到其运营对象——人员角色、必需安全决策与技能、培训内容、参与、理解、行为、报告和再培训——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-14.3-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "14.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "For Train Workforce Members on Authentication Best Practices, express success as an observable decision over role-specific knowledge, practiced decision, reporting behavior, measurable comprehension, and retraining outcome; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“认证最佳实践”，以 岗位相关知识、练习过的决策、报告行为、可测理解和再培训结果 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-14.3-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "14.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "For Train Workforce Members on Authentication Best Practices, express success as an observable decision over effective identity, authentication, authorization, privilege, session, and revocation state across every access path; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“认证最佳实践”，以 所有访问路径上的实际身份、认证、授权、权限、会话和撤销状态 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-14.3-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "14.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-14.3-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "14.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-14.3-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "14.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-14.3-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "14.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-14.3-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "14.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across contractors, temporary and privileged roles, accessibility and language needs, absence, role changes, remote work, simulated-test harm, completion without comprehension, and AI-assisted work; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 承包商、临时与特权角色、无障碍和语言需求、缺席、角色变化、远程工作、模拟伤害、完成却未理解以及 AI 辅助工作 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-14.3-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "14.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Include new hires, contractors, temporary and privileged roles, role changes, accessibility and language needs, absence, remote work, simulation harm, and completion without comprehension in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 新员工、承包商、临时与特权角色、角色变化、无障碍和语言需求、缺席、远程工作、模拟伤害及完成却未理解 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-14.3-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "14.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Include shared and service identities, nested groups, direct grants, cached sessions, federation gaps, recovery channels, API keys, emergency access, and provider support in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 共享与服务身份、嵌套组、直接授权、缓存会话、联邦缺口、恢复通道、API 密钥、紧急访问和提供商支持 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-14.3-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "14.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-14.3-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "14.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-14.3-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "14.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-14.3-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "14.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-14.3-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "14.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind security awareness owners, HR, managers, role experts, legal/privacy, incident response, and workforce members to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 安全意识责任人、HR、直属经理、岗位专家、法务/隐私、事件响应和人员成员 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-14.3-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "14.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Name who may transition need identified → objective and scenario designed → assigned → practiced/assessed → remediated → behavior reviewed → content renewed, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 识别需要 → 设计目标与情境 → 分配 → 练习/评估 → 补救 → 复核行为 → 更新内容，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-14.3-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "14.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Name who may transition requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-14.3-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "14.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-14.3-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "14.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-14.3-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "14.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV43, M1, M2, M3, M4, M5, M6) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV43, M1, M2, M3, M4, M5, M6）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-14.3-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "14.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-14.3-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "14.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the role-to-learning-objective, assignment, completion, and observed-behavior authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把角色—学习目标—分配—完成—行为结果权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-14.3-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "14.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle need identified → objective and scenario designed → assigned → practiced/assessed → remediated → behavior reviewed → content renewed.",
          "zh": "对生命周期“识别需要 → 设计目标与情境 → 分配 → 练习/评估 → 补救 → 复核行为 → 更新内容”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-14.3-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "14.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated.",
          "zh": "对生命周期“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-14.3-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "14.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for no explicit predecessor in the pinned CAS page; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 固定 CAS 页面没有列出显式前置项 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-14.3-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "14.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-14.3-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "14.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-14.3-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "14.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-14.3-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "14.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile HR and role data, learning platforms, policy and threat changes, simulations, helpdesk and incident reports, assessments, and manager attestations and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 HR 与角色数据、学习平台、策略与威胁变化、模拟、服务台与事件报告、评估和经理确认，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-14.3-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "14.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Require every connector carrying role-specific knowledge, practiced decision, reporting behavior, measurable comprehension, and retraining outcome to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 岗位相关知识、练习过的决策、报告行为、可测理解和再培训结果 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-14.3-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "14.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Require every connector carrying effective identity, authentication, authorization, privilege, session, and revocation state across every access path to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 所有访问路径上的实际身份、认证、授权、权限、会话和撤销状态 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-14.3-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "14.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Teach unique managed passwords, phishing-resistant MFA, prompt verification, no credential sharing, secure recovery and immediate reporting.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“讲唯一受管口令、抗钓鱼 MFA、Prompt 核验、不共享凭据、安全恢复和立即报告；同时提供好用的批准工具，移除会逼人绕过的政策，认证方法/攻击变化时刷新。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-14.3-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "14.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-14.3-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "14.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-14.3-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "14.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-14.3-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "14.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the role-to-learning-objective, assignment, completion, and observed-behavior authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在角色—学习目标—分配—完成—行为结果权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-14.3-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "14.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Implement the explicit state machine need identified → objective and scenario designed → assigned → practiced/assessed → remediated → behavior reviewed → content renewed; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“识别需要 → 设计目标与情境 → 分配 → 练习/评估 → 补救 → 复核行为 → 更新内容”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-14.3-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "14.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Implement the explicit state machine requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-14.3-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "14.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-14.3-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "14.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-14.3-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "14.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-14.3-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "14.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-14.3-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "14.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in workforce roles, required security decisions and skills, training content, participation, comprehension, behavior, reporting, and retraining; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 人员角色、必需安全决策与技能、培训内容、参与、理解、行为、报告和再培训 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-14.3-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "14.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for need identified → objective and scenario designed → assigned → practiced/assessed → remediated → behavior reviewed → content renewed; alert before each deadline becomes overdue.",
          "zh": "为“识别需要 → 设计目标与情境 → 分配 → 练习/评估 → 补救 → 复核行为 → 更新内容”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-14.3-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "14.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated; alert before each deadline becomes overdue.",
          "zh": "为“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-14.3-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "14.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “Training cannot fix legacy shared accounts, MFA fatigue or a weak reset process.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“培训修不好共享旧账户、MFA Fatigue 和弱重置。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-14.3-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "14.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-14.3-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "14.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-14.3-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "14.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-14.3-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "14.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat contractors, temporary and privileged roles, accessibility and language needs, absence, role changes, remote work, simulated-test harm, completion without comprehension, and AI-assisted work as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 承包商、临时与特权角色、无障碍和语言需求、缺席、角色变化、远程工作、模拟伤害、完成却未理解以及 AI 辅助工作 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-14.3-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "14.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Treat new hires, contractors, temporary and privileged roles, role changes, accessibility and language needs, absence, remote work, simulation harm, and completion without comprehension as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 新员工、承包商、临时与特权角色、角色变化、无障碍和语言需求、缺席、远程工作、模拟伤害及完成却未理解 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-14.3-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "14.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Treat shared and service identities, nested groups, direct grants, cached sessions, federation gaps, recovery channels, API keys, emergency access, and provider support as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 共享与服务身份、嵌套组、直接授权、缓存会话、联邦缺口、恢复通道、API 密钥、紧急访问和提供商支持 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-14.3-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "14.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Run scenario questions and safe unexpected-prompt/recovery exercises, then measure correct rejection/reporting and password-manager/MFA adoption without collecting secrets.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“用场景和安全的意外 Prompt/恢复演练，测拒绝/报告与密码管理器/MFA 采用，绝不收集秘密；检查 Support 是否也执行教给用户的身份核验。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-14.3-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "14.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-14.3-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "14.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 2 pinned CAS metric branch(es), 7 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 2 个指标分支、7 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-14.3-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "14.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-14.3-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "14.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the role-to-learning-objective, assignment, completion, and observed-behavior authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以角色—学习目标—分配—完成—行为结果权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-14.3-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "14.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Publish assigned, started, completed, passed, failed, overdue, exempted, role-mismatched, retrained, reported, and behavior-improved learners with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已分配、已开始、已完成、通过、失败、逾期、豁免、岗位不匹配、再培训、已报告和行为改善人员，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-14.3-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "14.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Publish requested, approved, effective, excessive, orphaned, stale, emergency, revoked-but-active, and independently reviewed rights with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 申请、批准、实际、过度、孤儿、陈旧、紧急、已撤销仍活跃及独立复核权限，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-14.3-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "14.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-14.3-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "14.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-14.3-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "14.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-14.3-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "14.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-14.3-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "14.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the role-to-learning-objective, assignment, completion, and observed-behavior authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护角色—学习目标—分配—完成—行为结果权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-14.3-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "14.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Restrict authority to change need identified → objective and scenario designed → assigned → practiced/assessed → remediated → behavior reviewed → content renewed; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“识别需要 → 设计目标与情境 → 分配 → 练习/评估 → 补救 → 复核行为 → 更新内容”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-14.3-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "14.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Restrict authority to change requested → approved → provisioned → exercised → reviewed → changed/revoked → session and token invalidated; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“申请 → 批准 → 开通 → 使用 → 复核 → 变更/撤销 → 会话与令牌失效”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-14.3-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "14.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-14.3-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "14.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-14.3-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "14.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-14.3-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "14.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-14.3-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "14.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise knowledge and scenario checks, correct and incorrect decisions, report-channel use, role change, simulated social engineering, missed training, and retraining effectiveness through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 知识与情境检查、正确与错误决策、报告通道使用、角色变化、社会工程模拟、漏训和再培训效果，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-14.3-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "14.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Run the positive control a representative learner making and reporting the secure decision in a realistic scenario; exercise negative, stale, duplicate, bypass, and outage controls including a missed assignment, incorrect decision, inaccessible content, stale scenario, role mismatch, failed report channel, and ineffective retraining.",
          "zh": "运行正向控制“代表性人员在真实情境中作出并报告安全决策”，并执行包含“漏分配、错误决策、内容不可访问、情境陈旧、岗位不匹配、报告通道失败和再培训无效”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-14.3-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "14.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Run the positive control an authorized identity using the required assurance and least privilege; exercise negative, stale, duplicate, bypass, and outage controls including an unauthorized identity, missing factor, stale session, direct grant, inherited excess, revoked token, and recovery bypass.",
          "zh": "运行正向控制“使用所需保证级别和最小权限的授权身份”，并执行包含“未授权身份、缺失认证因子、陈旧会话、直接授权、继承过权、已撤销令牌和恢复绕过”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-14.3-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "14.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-14.3-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "14.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-14.3-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "14.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-14.3-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "14.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-14.3-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "14.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever HR and role data, learning platforms, policy and threat changes, simulations, helpdesk and incident reports, assessments, and manager attestations change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 HR 与角色数据、学习平台、策略与威胁变化、模拟、服务台与事件报告、评估和经理确认 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-14.3-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "14.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Use assigned, started, completed, passed, failed, overdue, exempted, role-mismatched, retrained, reported, and behavior-improved learners to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已分配、已开始、已完成、通过、失败、逾期、豁免、岗位不匹配、再培训、已报告和行为改善人员 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-14.3-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "14.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original identity pattern analysis",
          "basis_zh": "SOSEC 原创 identity 模式分析",
          "en": "Use requested, approved, effective, excessive, orphaned, stale, emergency, revoked-but-active, and independently reviewed rights to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 申请、批准、实际、过度、孤儿、陈旧、紧急、已撤销仍活跃及独立复核权限 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "14.4",
      "control": 14,
      "title_en": "Train Workforce on Data Handling Best Practices",
      "title_zh": "数据处理最佳实践",
      "first_ig": 1,
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Users",
      "security_function": "Protect",
      "patterns": [
        "training",
        "data_lifecycle"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [],
        "variables": [
          "GV43",
          "M1",
          "M2",
          "M3",
          "M4",
          "M5",
          "M6"
        ],
        "metric_branches": 2,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "Training follows the enterprise's actual classifications and workflows for collection, storage, access, sharing, transfer, retention and disposal across email, collaboration, cloud, removable media, printing, remote work and AI tools.",
          "build": "Give role-specific examples, approved destinations and transfer methods, labeling, recipient verification, minimal access, clean desk/media and incident/reporting steps.",
          "proof": "Use realistic decisions such as external sharing, misaddressed mail, public link, AI prompt and disposal; measure correct handling and reporting, then inspect whether approved tools support the answer.",
          "boundary": "People cannot determine sensitivity when inventories/labels are absent."
        },
        "zh": {
          "scope": "内容跟随真实数据分类和收集、存储、访问、共享、传输、保留、销毁流程，覆盖邮件、协作、云、介质、打印、远程和 AI；泛泛“保护机密”不可行动。",
          "build": "按角色给批准目的与方法、标签、收件核验、最小访问、桌面/介质和事件步骤；UI/工具与政策一致，让安全路径最容易，数据用途/服务商变化时更新。",
          "proof": "用外部分享、错发邮件、公开链接、AI Prompt 和销毁等真实决策，测正确处理/报告，并检查批准工具是否支持答案；用真实 Near miss 改流程但不暴露个人。",
          "boundary": "资产/标签缺失时，人无法判断敏感度。"
        }
      },
      "category_counts": {
        "outcome": 7,
        "scope": 7,
        "ownership": 7,
        "data": 7,
        "integration": 7,
        "control": 7,
        "timing": 7,
        "exception": 7,
        "evidence": 7,
        "security": 7,
        "testing": 7,
        "operations": 7
      },
      "requirement_count": 84,
      "requirements": [
        {
          "code": "CIS-14.4-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "14.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Train Workforce on Data Handling Best Practices; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“数据处理最佳实践”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-14.4-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "14.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 14.4, official Asset Class Users, Security Function Protect, and IG1 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 14.4、官方资产类别“用户与身份”、安全功能“保护”和首次出现的 IG1，并保存来源抓取日期。"
        },
        {
          "code": "CIS-14.4-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "14.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Training follows the enterprise's actual classifications and workflows for collection, storage, access, sharing, transfer, retention and disposal across email, collaboration, cloud, removable media, printing, remote work and AI tools.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“内容跟随真实数据分类和收集、存储、访问、共享、传输、保留、销毁流程，覆盖邮件、协作、云、介质、打印、远程和 AI；泛泛“保护机密”不可行动。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-14.4-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "14.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-14.4-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "14.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Train Workforce on Data Handling Best Practices to its operating object—workforce roles, required security decisions and skills, training content, participation, comprehension, behavior, reporting, and retraining—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“数据处理最佳实践”连接到其运营对象——人员角色、必需安全决策与技能、培训内容、参与、理解、行为、报告和再培训——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-14.4-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "14.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "For Train Workforce on Data Handling Best Practices, express success as an observable decision over role-specific knowledge, practiced decision, reporting behavior, measurable comprehension, and retraining outcome; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“数据处理最佳实践”，以 岗位相关知识、练习过的决策、报告行为、可测理解和再培训结果 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-14.4-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "14.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "For Train Workforce on Data Handling Best Practices, express success as an observable decision over data identity, sensitivity, owner, purpose, location, flow, access, retention, copy, derivation, and disposal state; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“数据处理最佳实践”，以 数据身份、敏感度、责任人、目的、位置、流向、访问、保留、副本、派生与销毁状态 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-14.4-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "14.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-14.4-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "14.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-14.4-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "14.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-14.4-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "14.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-14.4-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "14.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across contractors, temporary and privileged roles, accessibility and language needs, absence, role changes, remote work, simulated-test harm, completion without comprehension, and AI-assisted work; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 承包商、临时与特权角色、无障碍和语言需求、缺席、角色变化、远程工作、模拟伤害、完成却未理解以及 AI 辅助工作 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-14.4-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "14.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Include new hires, contractors, temporary and privileged roles, role changes, accessibility and language needs, absence, remote work, simulation harm, and completion without comprehension in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 新员工、承包商、临时与特权角色、角色变化、无障碍和语言需求、缺席、远程工作、模拟伤害及完成却未理解 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-14.4-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "14.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Include unstructured and derived data, logs, caches, backups, exports, client-side copies, cross-region processing, AI corpora, holds, and provider residues in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 非结构化与派生数据、日志、缓存、备份、导出、客户端副本、跨地域处理、AI 语料、保全和提供商残留 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-14.4-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "14.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-14.4-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "14.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-14.4-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "14.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-14.4-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "14.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-14.4-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "14.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind security awareness owners, HR, managers, role experts, legal/privacy, incident response, and workforce members to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 安全意识责任人、HR、直属经理、岗位专家、法务/隐私、事件响应和人员成员 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-14.4-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "14.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Name who may transition need identified → objective and scenario designed → assigned → practiced/assessed → remediated → behavior reviewed → content renewed, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 识别需要 → 设计目标与情境 → 分配 → 练习/评估 → 补救 → 复核行为 → 更新内容，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-14.4-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "14.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Name who may transition created/collected → classified → approved use and flow → retained/held → disposed with verification, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-14.4-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "14.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-14.4-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "14.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-14.4-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "14.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV43, M1, M2, M3, M4, M5, M6) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV43, M1, M2, M3, M4, M5, M6）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-14.4-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "14.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-14.4-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "14.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the role-to-learning-objective, assignment, completion, and observed-behavior authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把角色—学习目标—分配—完成—行为结果权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-14.4-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "14.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle need identified → objective and scenario designed → assigned → practiced/assessed → remediated → behavior reviewed → content renewed.",
          "zh": "对生命周期“识别需要 → 设计目标与情境 → 分配 → 练习/评估 → 补救 → 复核行为 → 更新内容”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-14.4-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "14.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle created/collected → classified → approved use and flow → retained/held → disposed with verification.",
          "zh": "对生命周期“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-14.4-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "14.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for no explicit predecessor in the pinned CAS page; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 固定 CAS 页面没有列出显式前置项 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-14.4-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "14.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-14.4-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "14.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-14.4-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "14.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-14.4-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "14.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile HR and role data, learning platforms, policy and threat changes, simulations, helpdesk and incident reports, assessments, and manager attestations and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 HR 与角色数据、学习平台、策略与威胁变化、模拟、服务台与事件报告、评估和经理确认，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-14.4-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "14.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Require every connector carrying role-specific knowledge, practiced decision, reporting behavior, measurable comprehension, and retraining outcome to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 岗位相关知识、练习过的决策、报告行为、可测理解和再培训结果 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-14.4-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "14.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Require every connector carrying data identity, sensitivity, owner, purpose, location, flow, access, retention, copy, derivation, and disposal state to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 数据身份、敏感度、责任人、目的、位置、流向、访问、保留、副本、派生与销毁状态 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-14.4-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "14.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Give role-specific examples, approved destinations and transfer methods, labeling, recipient verification, minimal access, clean desk/media and incident/reporting steps.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“按角色给批准目的与方法、标签、收件核验、最小访问、桌面/介质和事件步骤；UI/工具与政策一致，让安全路径最容易，数据用途/服务商变化时更新。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-14.4-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "14.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-14.4-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "14.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-14.4-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "14.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-14.4-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "14.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the role-to-learning-objective, assignment, completion, and observed-behavior authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在角色—学习目标—分配—完成—行为结果权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-14.4-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "14.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Implement the explicit state machine need identified → objective and scenario designed → assigned → practiced/assessed → remediated → behavior reviewed → content renewed; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“识别需要 → 设计目标与情境 → 分配 → 练习/评估 → 补救 → 复核行为 → 更新内容”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-14.4-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "14.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Implement the explicit state machine created/collected → classified → approved use and flow → retained/held → disposed with verification; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-14.4-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "14.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-14.4-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "14.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-14.4-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "14.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-14.4-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "14.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-14.4-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "14.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in workforce roles, required security decisions and skills, training content, participation, comprehension, behavior, reporting, and retraining; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 人员角色、必需安全决策与技能、培训内容、参与、理解、行为、报告和再培训 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-14.4-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "14.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for need identified → objective and scenario designed → assigned → practiced/assessed → remediated → behavior reviewed → content renewed; alert before each deadline becomes overdue.",
          "zh": "为“识别需要 → 设计目标与情境 → 分配 → 练习/评估 → 补救 → 复核行为 → 更新内容”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-14.4-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "14.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for created/collected → classified → approved use and flow → retained/held → disposed with verification; alert before each deadline becomes overdue.",
          "zh": "为“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-14.4-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "14.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “People cannot determine sensitivity when inventories/labels are absent.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“资产/标签缺失时，人无法判断敏感度。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-14.4-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "14.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-14.4-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "14.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-14.4-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "14.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-14.4-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "14.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat contractors, temporary and privileged roles, accessibility and language needs, absence, role changes, remote work, simulated-test harm, completion without comprehension, and AI-assisted work as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 承包商、临时与特权角色、无障碍和语言需求、缺席、角色变化、远程工作、模拟伤害、完成却未理解以及 AI 辅助工作 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-14.4-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "14.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Treat new hires, contractors, temporary and privileged roles, role changes, accessibility and language needs, absence, remote work, simulation harm, and completion without comprehension as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 新员工、承包商、临时与特权角色、角色变化、无障碍和语言需求、缺席、远程工作、模拟伤害及完成却未理解 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-14.4-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "14.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Treat unstructured and derived data, logs, caches, backups, exports, client-side copies, cross-region processing, AI corpora, holds, and provider residues as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 非结构化与派生数据、日志、缓存、备份、导出、客户端副本、跨地域处理、AI 语料、保全和提供商残留 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-14.4-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "14.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Use realistic decisions such as external sharing, misaddressed mail, public link, AI prompt and disposal; measure correct handling and reporting, then inspect whether approved tools support the answer.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“用外部分享、错发邮件、公开链接、AI Prompt 和销毁等真实决策，测正确处理/报告，并检查批准工具是否支持答案；用真实 Near miss 改流程但不暴露个人。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-14.4-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "14.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-14.4-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "14.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 2 pinned CAS metric branch(es), 7 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 2 个指标分支、7 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-14.4-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "14.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-14.4-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "14.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the role-to-learning-objective, assignment, completion, and observed-behavior authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以角色—学习目标—分配—完成—行为结果权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-14.4-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "14.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Publish assigned, started, completed, passed, failed, overdue, exempted, role-mismatched, retrained, reported, and behavior-improved learners with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已分配、已开始、已完成、通过、失败、逾期、豁免、岗位不匹配、再培训、已报告和行为改善人员，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-14.4-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "14.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Publish known, unknown, classified, ownerless, over-retained, prematurely deleted, unapproved copy, blocked flow, held, and disposal-verified data sets with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已知、未知、已分类、无责任人、超期保留、过早删除、未批准副本、被阻断流、保全及销毁已验证数据集，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-14.4-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "14.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-14.4-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "14.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-14.4-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "14.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-14.4-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "14.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-14.4-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "14.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the role-to-learning-objective, assignment, completion, and observed-behavior authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护角色—学习目标—分配—完成—行为结果权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-14.4-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "14.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Restrict authority to change need identified → objective and scenario designed → assigned → practiced/assessed → remediated → behavior reviewed → content renewed; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“识别需要 → 设计目标与情境 → 分配 → 练习/评估 → 补救 → 复核行为 → 更新内容”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-14.4-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "14.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Restrict authority to change created/collected → classified → approved use and flow → retained/held → disposed with verification; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-14.4-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "14.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-14.4-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "14.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-14.4-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "14.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-14.4-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "14.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-14.4-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "14.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise knowledge and scenario checks, correct and incorrect decisions, report-channel use, role change, simulated social engineering, missed training, and retraining effectiveness through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 知识与情境检查、正确与错误决策、报告通道使用、角色变化、社会工程模拟、漏训和再培训效果，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-14.4-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "14.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Run the positive control a representative learner making and reporting the secure decision in a realistic scenario; exercise negative, stale, duplicate, bypass, and outage controls including a missed assignment, incorrect decision, inaccessible content, stale scenario, role mismatch, failed report channel, and ineffective retraining.",
          "zh": "运行正向控制“代表性人员在真实情境中作出并报告安全决策”，并执行包含“漏分配、错误决策、内容不可访问、情境陈旧、岗位不匹配、报告通道失败和再培训无效”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-14.4-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "14.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Run the positive control an approved data set following its declared use, access, transfer, retention, and disposal path; exercise negative, stale, duplicate, bypass, and outage controls including an unknown or misclassified copy, forbidden reader or flow, early deletion, expired retention, failed disposal, and provider residue.",
          "zh": "运行正向控制“按声明用途、访问、传输、保留和销毁路径流转的获批数据集”，并执行包含“未知或误分类副本、禁止读取者或流向、过早删除、保留过期、销毁失败和提供商残留”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-14.4-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "14.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-14.4-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "14.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-14.4-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "14.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-14.4-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "14.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-14.4-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "14.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever HR and role data, learning platforms, policy and threat changes, simulations, helpdesk and incident reports, assessments, and manager attestations change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 HR 与角色数据、学习平台、策略与威胁变化、模拟、服务台与事件报告、评估和经理确认 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-14.4-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "14.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Use assigned, started, completed, passed, failed, overdue, exempted, role-mismatched, retrained, reported, and behavior-improved learners to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已分配、已开始、已完成、通过、失败、逾期、豁免、岗位不匹配、再培训、已报告和行为改善人员 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-14.4-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "14.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Use known, unknown, classified, ownerless, over-retained, prematurely deleted, unapproved copy, blocked flow, held, and disposal-verified data sets to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已知、未知、已分类、无责任人、超期保留、过早删除、未批准副本、被阻断流、保全及销毁已验证数据集 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "14.5",
      "control": 14,
      "title_en": "Train Workforce Members on Causes of Unintentional Data Exposure",
      "title_zh": "非故意数据暴露",
      "first_ig": 1,
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Users",
      "security_function": "Protect",
      "patterns": [
        "training",
        "data_lifecycle"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [],
        "variables": [
          "GV43",
          "M1",
          "M2",
          "M3",
          "M4",
          "M5",
          "M6"
        ],
        "metric_branches": 2,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "Cover common accidental causes: wrong recipient/autocomplete, public links, excessive permissions, lost devices, unsafe printing/disposal, screenshots, misconfigured cloud storage, code/log secrets and posting data to consumer/AI services.",
          "build": "Teach pause-and-verify steps, approved sharing defaults, recipient/permission checks, data minimization and rapid recall/revocation/reporting.",
          "proof": "Run scenario exercises and controlled sharing canaries, verify participants can identify exposure, revoke access and report with useful context.",
          "boundary": "Some “user errors” are predictable UI or process design failures."
        },
        "zh": {
          "scope": "覆盖错收件/自动补全、公开链接、过宽权限、丢设备、不安全打印/销毁、截图、云误配、代码/日志秘密和向消费/AI 服务发数据等意外暴露，强调立即遏制和报告。",
          "build": "教停一下再核验、批准分享默认、收件/权限检查、数据最小化和快速 Recall/Revoke/Report，并用更安全产品默认、DLP、访问控制强化；按开发、支持、销售、研究、远程角色调整。",
          "proof": "用场景和受控分享 Canary，验证识别、撤权和带上下文报告；跟踪真实暴露到报告的时间、恢复结果与重复系统根因，不能归罪个人。",
          "boundary": "许多“用户错误”是可预测 UI/流程缺陷。"
        }
      },
      "category_counts": {
        "outcome": 7,
        "scope": 7,
        "ownership": 7,
        "data": 7,
        "integration": 7,
        "control": 7,
        "timing": 7,
        "exception": 7,
        "evidence": 7,
        "security": 7,
        "testing": 7,
        "operations": 7
      },
      "requirement_count": 84,
      "requirements": [
        {
          "code": "CIS-14.5-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "14.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Train Workforce Members on Causes of Unintentional Data Exposure; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“非故意数据暴露”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-14.5-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "14.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 14.5, official Asset Class Users, Security Function Protect, and IG1 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 14.5、官方资产类别“用户与身份”、安全功能“保护”和首次出现的 IG1，并保存来源抓取日期。"
        },
        {
          "code": "CIS-14.5-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "14.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Cover common accidental causes: wrong recipient/autocomplete, public links, excessive permissions, lost devices, unsafe printing/disposal, screenshots, misconfigured cloud storage, code/log secrets and posting data to consumer/AI services.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“覆盖错收件/自动补全、公开链接、过宽权限、丢设备、不安全打印/销毁、截图、云误配、代码/日志秘密和向消费/AI 服务发数据等意外暴露，强调立即遏制和报告。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-14.5-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "14.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-14.5-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "14.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Train Workforce Members on Causes of Unintentional Data Exposure to its operating object—workforce roles, required security decisions and skills, training content, participation, comprehension, behavior, reporting, and retraining—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“非故意数据暴露”连接到其运营对象——人员角色、必需安全决策与技能、培训内容、参与、理解、行为、报告和再培训——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-14.5-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "14.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "For Train Workforce Members on Causes of Unintentional Data Exposure, express success as an observable decision over role-specific knowledge, practiced decision, reporting behavior, measurable comprehension, and retraining outcome; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“非故意数据暴露”，以 岗位相关知识、练习过的决策、报告行为、可测理解和再培训结果 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-14.5-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "14.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "For Train Workforce Members on Causes of Unintentional Data Exposure, express success as an observable decision over data identity, sensitivity, owner, purpose, location, flow, access, retention, copy, derivation, and disposal state; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“非故意数据暴露”，以 数据身份、敏感度、责任人、目的、位置、流向、访问、保留、副本、派生与销毁状态 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-14.5-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "14.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-14.5-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "14.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-14.5-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "14.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-14.5-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "14.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-14.5-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "14.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across contractors, temporary and privileged roles, accessibility and language needs, absence, role changes, remote work, simulated-test harm, completion without comprehension, and AI-assisted work; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 承包商、临时与特权角色、无障碍和语言需求、缺席、角色变化、远程工作、模拟伤害、完成却未理解以及 AI 辅助工作 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-14.5-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "14.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Include new hires, contractors, temporary and privileged roles, role changes, accessibility and language needs, absence, remote work, simulation harm, and completion without comprehension in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 新员工、承包商、临时与特权角色、角色变化、无障碍和语言需求、缺席、远程工作、模拟伤害及完成却未理解 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-14.5-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "14.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Include unstructured and derived data, logs, caches, backups, exports, client-side copies, cross-region processing, AI corpora, holds, and provider residues in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 非结构化与派生数据、日志、缓存、备份、导出、客户端副本、跨地域处理、AI 语料、保全和提供商残留 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-14.5-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "14.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-14.5-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "14.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-14.5-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "14.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-14.5-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "14.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-14.5-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "14.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind security awareness owners, HR, managers, role experts, legal/privacy, incident response, and workforce members to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 安全意识责任人、HR、直属经理、岗位专家、法务/隐私、事件响应和人员成员 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-14.5-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "14.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Name who may transition need identified → objective and scenario designed → assigned → practiced/assessed → remediated → behavior reviewed → content renewed, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 识别需要 → 设计目标与情境 → 分配 → 练习/评估 → 补救 → 复核行为 → 更新内容，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-14.5-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "14.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Name who may transition created/collected → classified → approved use and flow → retained/held → disposed with verification, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-14.5-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "14.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-14.5-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "14.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-14.5-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "14.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV43, M1, M2, M3, M4, M5, M6) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV43, M1, M2, M3, M4, M5, M6）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-14.5-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "14.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-14.5-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "14.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the role-to-learning-objective, assignment, completion, and observed-behavior authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把角色—学习目标—分配—完成—行为结果权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-14.5-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "14.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle need identified → objective and scenario designed → assigned → practiced/assessed → remediated → behavior reviewed → content renewed.",
          "zh": "对生命周期“识别需要 → 设计目标与情境 → 分配 → 练习/评估 → 补救 → 复核行为 → 更新内容”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-14.5-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "14.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle created/collected → classified → approved use and flow → retained/held → disposed with verification.",
          "zh": "对生命周期“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-14.5-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "14.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for no explicit predecessor in the pinned CAS page; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 固定 CAS 页面没有列出显式前置项 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-14.5-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "14.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-14.5-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "14.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-14.5-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "14.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-14.5-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "14.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile HR and role data, learning platforms, policy and threat changes, simulations, helpdesk and incident reports, assessments, and manager attestations and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 HR 与角色数据、学习平台、策略与威胁变化、模拟、服务台与事件报告、评估和经理确认，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-14.5-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "14.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Require every connector carrying role-specific knowledge, practiced decision, reporting behavior, measurable comprehension, and retraining outcome to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 岗位相关知识、练习过的决策、报告行为、可测理解和再培训结果 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-14.5-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "14.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Require every connector carrying data identity, sensitivity, owner, purpose, location, flow, access, retention, copy, derivation, and disposal state to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 数据身份、敏感度、责任人、目的、位置、流向、访问、保留、副本、派生与销毁状态 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-14.5-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "14.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Teach pause-and-verify steps, approved sharing defaults, recipient/permission checks, data minimization and rapid recall/revocation/reporting.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“教停一下再核验、批准分享默认、收件/权限检查、数据最小化和快速 Recall/Revoke/Report，并用更安全产品默认、DLP、访问控制强化；按开发、支持、销售、研究、远程角色调整。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-14.5-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "14.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-14.5-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "14.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-14.5-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "14.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-14.5-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "14.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the role-to-learning-objective, assignment, completion, and observed-behavior authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在角色—学习目标—分配—完成—行为结果权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-14.5-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "14.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Implement the explicit state machine need identified → objective and scenario designed → assigned → practiced/assessed → remediated → behavior reviewed → content renewed; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“识别需要 → 设计目标与情境 → 分配 → 练习/评估 → 补救 → 复核行为 → 更新内容”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-14.5-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "14.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Implement the explicit state machine created/collected → classified → approved use and flow → retained/held → disposed with verification; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-14.5-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "14.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-14.5-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "14.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-14.5-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "14.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-14.5-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "14.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-14.5-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "14.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in workforce roles, required security decisions and skills, training content, participation, comprehension, behavior, reporting, and retraining; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 人员角色、必需安全决策与技能、培训内容、参与、理解、行为、报告和再培训 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-14.5-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "14.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for need identified → objective and scenario designed → assigned → practiced/assessed → remediated → behavior reviewed → content renewed; alert before each deadline becomes overdue.",
          "zh": "为“识别需要 → 设计目标与情境 → 分配 → 练习/评估 → 补救 → 复核行为 → 更新内容”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-14.5-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "14.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for created/collected → classified → approved use and flow → retained/held → disposed with verification; alert before each deadline becomes overdue.",
          "zh": "为“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-14.5-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "14.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “Some “user errors” are predictable UI or process design failures.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“许多“用户错误”是可预测 UI/流程缺陷。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-14.5-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "14.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-14.5-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "14.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-14.5-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "14.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-14.5-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "14.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat contractors, temporary and privileged roles, accessibility and language needs, absence, role changes, remote work, simulated-test harm, completion without comprehension, and AI-assisted work as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 承包商、临时与特权角色、无障碍和语言需求、缺席、角色变化、远程工作、模拟伤害、完成却未理解以及 AI 辅助工作 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-14.5-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "14.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Treat new hires, contractors, temporary and privileged roles, role changes, accessibility and language needs, absence, remote work, simulation harm, and completion without comprehension as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 新员工、承包商、临时与特权角色、角色变化、无障碍和语言需求、缺席、远程工作、模拟伤害及完成却未理解 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-14.5-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "14.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Treat unstructured and derived data, logs, caches, backups, exports, client-side copies, cross-region processing, AI corpora, holds, and provider residues as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 非结构化与派生数据、日志、缓存、备份、导出、客户端副本、跨地域处理、AI 语料、保全和提供商残留 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-14.5-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "14.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Run scenario exercises and controlled sharing canaries, verify participants can identify exposure, revoke access and report with useful context.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“用场景和受控分享 Canary，验证识别、撤权和带上下文报告；跟踪真实暴露到报告的时间、恢复结果与重复系统根因，不能归罪个人。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-14.5-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "14.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-14.5-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "14.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 2 pinned CAS metric branch(es), 7 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 2 个指标分支、7 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-14.5-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "14.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-14.5-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "14.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the role-to-learning-objective, assignment, completion, and observed-behavior authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以角色—学习目标—分配—完成—行为结果权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-14.5-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "14.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Publish assigned, started, completed, passed, failed, overdue, exempted, role-mismatched, retrained, reported, and behavior-improved learners with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已分配、已开始、已完成、通过、失败、逾期、豁免、岗位不匹配、再培训、已报告和行为改善人员，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-14.5-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "14.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Publish known, unknown, classified, ownerless, over-retained, prematurely deleted, unapproved copy, blocked flow, held, and disposal-verified data sets with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已知、未知、已分类、无责任人、超期保留、过早删除、未批准副本、被阻断流、保全及销毁已验证数据集，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-14.5-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "14.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-14.5-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "14.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-14.5-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "14.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-14.5-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "14.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-14.5-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "14.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the role-to-learning-objective, assignment, completion, and observed-behavior authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护角色—学习目标—分配—完成—行为结果权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-14.5-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "14.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Restrict authority to change need identified → objective and scenario designed → assigned → practiced/assessed → remediated → behavior reviewed → content renewed; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“识别需要 → 设计目标与情境 → 分配 → 练习/评估 → 补救 → 复核行为 → 更新内容”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-14.5-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "14.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Restrict authority to change created/collected → classified → approved use and flow → retained/held → disposed with verification; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-14.5-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "14.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-14.5-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "14.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-14.5-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "14.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-14.5-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "14.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-14.5-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "14.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise knowledge and scenario checks, correct and incorrect decisions, report-channel use, role change, simulated social engineering, missed training, and retraining effectiveness through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 知识与情境检查、正确与错误决策、报告通道使用、角色变化、社会工程模拟、漏训和再培训效果，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-14.5-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "14.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Run the positive control a representative learner making and reporting the secure decision in a realistic scenario; exercise negative, stale, duplicate, bypass, and outage controls including a missed assignment, incorrect decision, inaccessible content, stale scenario, role mismatch, failed report channel, and ineffective retraining.",
          "zh": "运行正向控制“代表性人员在真实情境中作出并报告安全决策”，并执行包含“漏分配、错误决策、内容不可访问、情境陈旧、岗位不匹配、报告通道失败和再培训无效”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-14.5-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "14.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Run the positive control an approved data set following its declared use, access, transfer, retention, and disposal path; exercise negative, stale, duplicate, bypass, and outage controls including an unknown or misclassified copy, forbidden reader or flow, early deletion, expired retention, failed disposal, and provider residue.",
          "zh": "运行正向控制“按声明用途、访问、传输、保留和销毁路径流转的获批数据集”，并执行包含“未知或误分类副本、禁止读取者或流向、过早删除、保留过期、销毁失败和提供商残留”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-14.5-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "14.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-14.5-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "14.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-14.5-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "14.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-14.5-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "14.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-14.5-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "14.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever HR and role data, learning platforms, policy and threat changes, simulations, helpdesk and incident reports, assessments, and manager attestations change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 HR 与角色数据、学习平台、策略与威胁变化、模拟、服务台与事件报告、评估和经理确认 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-14.5-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "14.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Use assigned, started, completed, passed, failed, overdue, exempted, role-mismatched, retrained, reported, and behavior-improved learners to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已分配、已开始、已完成、通过、失败、逾期、豁免、岗位不匹配、再培训、已报告和行为改善人员 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-14.5-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "14.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Use known, unknown, classified, ownerless, over-retained, prematurely deleted, unapproved copy, blocked flow, held, and disposal-verified data sets to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已知、未知、已分类、无责任人、超期保留、过早删除、未批准副本、被阻断流、保全及销毁已验证数据集 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "14.6",
      "control": 14,
      "title_en": "Train Workforce Members on Recognizing and Reporting Security Incidents",
      "title_zh": "事件识别与报告",
      "first_ig": 1,
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Users",
      "security_function": "Protect",
      "patterns": [
        "training",
        "incident"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [],
        "variables": [
          "GV43",
          "M1",
          "M2",
          "M3",
          "M4",
          "M5",
          "M6"
        ],
        "metric_branches": 2,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "The workforce should recognize observable security events relevant to their role—unexpected MFA, malware warning, lost asset, account change, suspicious data access or system behavior—and know one simple, available reporting path plus urgent alternatives.",
          "build": "Teach what to report, how quickly, what evidence to preserve, what actions to avoid and where to report; provide 24/7 or risk-appropriate channels, acknowledgement and feedback.",
          "proof": "Submit test reports through email, portal, phone and after-hours paths; verify receipt, triage, correlation, escalation and feedback within SLO.",
          "boundary": "Training is useless if the queue is unstaffed or requires an inaccessible account."
        },
        "zh": {
          "scope": "员工应能识别与其角色相关的可观察事件，如意外 MFA、恶意软件告警、资产丢失、账户变化、可疑数据访问/系统行为，并知道一个简单常用的报告入口与紧急替代。",
          "build": "讲报告什么、多快、保留哪些证据、避免什么动作和去哪里；提供 24/7 或匹配风险的渠道、确认和反馈，接入事件流程并保护报告者。",
          "proof": "经邮件、Portal、电话和下班渠道提交测试报告，验证接收、分诊、关联、升级和反馈；场景测试保全/遏制选择，以有用报告的时延/质量为指标，不追求数量。",
          "boundary": "若队列无人值守或必须用已锁账号，培训无用。"
        }
      },
      "category_counts": {
        "outcome": 7,
        "scope": 7,
        "ownership": 7,
        "data": 7,
        "integration": 7,
        "control": 7,
        "timing": 7,
        "exception": 7,
        "evidence": 7,
        "security": 7,
        "testing": 7,
        "operations": 7
      },
      "requirement_count": 84,
      "requirements": [
        {
          "code": "CIS-14.6-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "14.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Train Workforce Members on Recognizing and Reporting Security Incidents; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“事件识别与报告”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-14.6-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "14.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 14.6, official Asset Class Users, Security Function Protect, and IG1 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 14.6、官方资产类别“用户与身份”、安全功能“保护”和首次出现的 IG1，并保存来源抓取日期。"
        },
        {
          "code": "CIS-14.6-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "14.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “The workforce should recognize observable security events relevant to their role—unexpected MFA, malware warning, lost asset, account change, suspicious data access or system behavior—and know one simple, available reporting path plus urgent alternatives.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“员工应能识别与其角色相关的可观察事件，如意外 MFA、恶意软件告警、资产丢失、账户变化、可疑数据访问/系统行为，并知道一个简单常用的报告入口与紧急替代。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-14.6-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "14.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-14.6-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "14.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Train Workforce Members on Recognizing and Reporting Security Incidents to its operating object—workforce roles, required security decisions and skills, training content, participation, comprehension, behavior, reporting, and retraining—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“事件识别与报告”连接到其运营对象——人员角色、必需安全决策与技能、培训内容、参与、理解、行为、报告和再培训——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-14.6-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "14.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "For Train Workforce Members on Recognizing and Reporting Security Incidents, express success as an observable decision over role-specific knowledge, practiced decision, reporting behavior, measurable comprehension, and retraining outcome; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“事件识别与报告”，以 岗位相关知识、练习过的决策、报告行为、可测理解和再培训结果 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-14.6-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "14.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "For Train Workforce Members on Recognizing and Reporting Security Incidents, express success as an observable decision over event-to-incident threshold, report, command, decision, communication, containment, evidence, recovery, review, and corrective action; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“事件识别与报告”，以 事件到事故阈值、报告、指挥、决策、通信、遏制、证据、恢复、复盘和纠正行动 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-14.6-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "14.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-14.6-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "14.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-14.6-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "14.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-14.6-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "14.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-14.6-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "14.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across contractors, temporary and privileged roles, accessibility and language needs, absence, role changes, remote work, simulated-test harm, completion without comprehension, and AI-assisted work; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 承包商、临时与特权角色、无障碍和语言需求、缺席、角色变化、远程工作、模拟伤害、完成却未理解以及 AI 辅助工作 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-14.6-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "14.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Include new hires, contractors, temporary and privileged roles, role changes, accessibility and language needs, absence, remote work, simulation harm, and completion without comprehension in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 新员工、承包商、临时与特权角色、角色变化、无障碍和语言需求、缺席、远程工作、模拟伤害及完成却未理解 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-14.6-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "14.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Include ambiguous classification, unavailable personnel, compromised primary channels, provider and cross-border incidents, insider and safety cases, evidence loss, prolonged recovery, and unresolved actions in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 分类歧义、人员不可用、主通道失陷、提供商与跨境事件、内部人与安全生产案件、证据丢失、长期恢复和未关闭行动 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-14.6-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "14.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-14.6-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "14.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-14.6-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "14.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-14.6-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "14.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-14.6-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "14.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind security awareness owners, HR, managers, role experts, legal/privacy, incident response, and workforce members to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 安全意识责任人、HR、直属经理、岗位专家、法务/隐私、事件响应和人员成员 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-14.6-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "14.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Name who may transition need identified → objective and scenario designed → assigned → practiced/assessed → remediated → behavior reviewed → content renewed, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 识别需要 → 设计目标与情境 → 分配 → 练习/评估 → 补救 → 复核行为 → 更新内容，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-14.6-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "14.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Name who may transition reported/detected → triaged → declared → commanded → contained → eradicated/recovered → reviewed → actions retested and closed, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 报告/检测 → 分流 → 宣告 → 指挥 → 遏制 → 根除/恢复 → 复盘 → 行动复测关闭，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-14.6-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "14.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-14.6-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "14.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-14.6-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "14.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV43, M1, M2, M3, M4, M5, M6) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV43, M1, M2, M3, M4, M5, M6）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-14.6-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "14.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-14.6-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "14.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the role-to-learning-objective, assignment, completion, and observed-behavior authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把角色—学习目标—分配—完成—行为结果权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-14.6-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "14.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle need identified → objective and scenario designed → assigned → practiced/assessed → remediated → behavior reviewed → content renewed.",
          "zh": "对生命周期“识别需要 → 设计目标与情境 → 分配 → 练习/评估 → 补救 → 复核行为 → 更新内容”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-14.6-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "14.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle reported/detected → triaged → declared → commanded → contained → eradicated/recovered → reviewed → actions retested and closed.",
          "zh": "对生命周期“报告/检测 → 分流 → 宣告 → 指挥 → 遏制 → 根除/恢复 → 复盘 → 行动复测关闭”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-14.6-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "14.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for no explicit predecessor in the pinned CAS page; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 固定 CAS 页面没有列出显式前置项 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-14.6-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "14.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-14.6-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "14.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-14.6-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "14.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-14.6-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "14.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile HR and role data, learning platforms, policy and threat changes, simulations, helpdesk and incident reports, assessments, and manager attestations and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 HR 与角色数据、学习平台、策略与威胁变化、模拟、服务台与事件报告、评估和经理确认，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-14.6-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "14.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Require every connector carrying role-specific knowledge, practiced decision, reporting behavior, measurable comprehension, and retraining outcome to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 岗位相关知识、练习过的决策、报告行为、可测理解和再培训结果 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-14.6-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "14.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Require every connector carrying event-to-incident threshold, report, command, decision, communication, containment, evidence, recovery, review, and corrective action to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 事件到事故阈值、报告、指挥、决策、通信、遏制、证据、恢复、复盘和纠正行动 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-14.6-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "14.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Teach what to report, how quickly, what evidence to preserve, what actions to avoid and where to report; provide 24/7 or risk-appropriate channels, acknowledgement and feedback.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“讲报告什么、多快、保留哪些证据、避免什么动作和去哪里；提供 24/7 或匹配风险的渠道、确认和反馈，接入事件流程并保护报告者。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-14.6-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "14.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-14.6-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "14.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-14.6-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "14.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-14.6-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "14.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the role-to-learning-objective, assignment, completion, and observed-behavior authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在角色—学习目标—分配—完成—行为结果权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-14.6-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "14.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Implement the explicit state machine need identified → objective and scenario designed → assigned → practiced/assessed → remediated → behavior reviewed → content renewed; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“识别需要 → 设计目标与情境 → 分配 → 练习/评估 → 补救 → 复核行为 → 更新内容”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-14.6-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "14.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Implement the explicit state machine reported/detected → triaged → declared → commanded → contained → eradicated/recovered → reviewed → actions retested and closed; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“报告/检测 → 分流 → 宣告 → 指挥 → 遏制 → 根除/恢复 → 复盘 → 行动复测关闭”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-14.6-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "14.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-14.6-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "14.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-14.6-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "14.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-14.6-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "14.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-14.6-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "14.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in workforce roles, required security decisions and skills, training content, participation, comprehension, behavior, reporting, and retraining; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 人员角色、必需安全决策与技能、培训内容、参与、理解、行为、报告和再培训 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-14.6-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "14.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for need identified → objective and scenario designed → assigned → practiced/assessed → remediated → behavior reviewed → content renewed; alert before each deadline becomes overdue.",
          "zh": "为“识别需要 → 设计目标与情境 → 分配 → 练习/评估 → 补救 → 复核行为 → 更新内容”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-14.6-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "14.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for reported/detected → triaged → declared → commanded → contained → eradicated/recovered → reviewed → actions retested and closed; alert before each deadline becomes overdue.",
          "zh": "为“报告/检测 → 分流 → 宣告 → 指挥 → 遏制 → 根除/恢复 → 复盘 → 行动复测关闭”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-14.6-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "14.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “Training is useless if the queue is unstaffed or requires an inaccessible account.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“若队列无人值守或必须用已锁账号，培训无用。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-14.6-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "14.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-14.6-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "14.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-14.6-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "14.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-14.6-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "14.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat contractors, temporary and privileged roles, accessibility and language needs, absence, role changes, remote work, simulated-test harm, completion without comprehension, and AI-assisted work as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 承包商、临时与特权角色、无障碍和语言需求、缺席、角色变化、远程工作、模拟伤害、完成却未理解以及 AI 辅助工作 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-14.6-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "14.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Treat new hires, contractors, temporary and privileged roles, role changes, accessibility and language needs, absence, remote work, simulation harm, and completion without comprehension as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 新员工、承包商、临时与特权角色、角色变化、无障碍和语言需求、缺席、远程工作、模拟伤害及完成却未理解 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-14.6-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "14.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Treat ambiguous classification, unavailable personnel, compromised primary channels, provider and cross-border incidents, insider and safety cases, evidence loss, prolonged recovery, and unresolved actions as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 分类歧义、人员不可用、主通道失陷、提供商与跨境事件、内部人与安全生产案件、证据丢失、长期恢复和未关闭行动 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-14.6-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "14.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Submit test reports through email, portal, phone and after-hours paths; verify receipt, triage, correlation, escalation and feedback within SLO.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“经邮件、Portal、电话和下班渠道提交测试报告，验证接收、分诊、关联、升级和反馈；场景测试保全/遏制选择，以有用报告的时延/质量为指标，不追求数量。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-14.6-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "14.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-14.6-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "14.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 2 pinned CAS metric branch(es), 7 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 2 个指标分支、7 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-14.6-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "14.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-14.6-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "14.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the role-to-learning-objective, assignment, completion, and observed-behavior authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以角色—学习目标—分配—完成—行为结果权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-14.6-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "14.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Publish assigned, started, completed, passed, failed, overdue, exempted, role-mismatched, retrained, reported, and behavior-improved learners with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已分配、已开始、已完成、通过、失败、逾期、豁免、岗位不匹配、再培训、已报告和行为改善人员，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-14.6-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "14.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Publish events, incidents, severity, ownership, acknowledgement, decision latency, communication success, containment, recovery, evidence gaps, and overdue corrective actions with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 事件、事故、严重度、责任、确认、决策延迟、通信成功、遏制、恢复、证据缺口和逾期纠正行动，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-14.6-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "14.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-14.6-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "14.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-14.6-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "14.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-14.6-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "14.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-14.6-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "14.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the role-to-learning-objective, assignment, completion, and observed-behavior authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护角色—学习目标—分配—完成—行为结果权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-14.6-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "14.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Restrict authority to change need identified → objective and scenario designed → assigned → practiced/assessed → remediated → behavior reviewed → content renewed; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“识别需要 → 设计目标与情境 → 分配 → 练习/评估 → 补救 → 复核行为 → 更新内容”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-14.6-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "14.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Restrict authority to change reported/detected → triaged → declared → commanded → contained → eradicated/recovered → reviewed → actions retested and closed; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“报告/检测 → 分流 → 宣告 → 指挥 → 遏制 → 根除/恢复 → 复盘 → 行动复测关闭”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-14.6-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "14.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-14.6-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "14.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-14.6-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "14.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-14.6-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "14.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-14.6-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "14.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise knowledge and scenario checks, correct and incorrect decisions, report-channel use, role change, simulated social engineering, missed training, and retraining effectiveness through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 知识与情境检查、正确与错误决策、报告通道使用、角色变化、社会工程模拟、漏训和再培训效果，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-14.6-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "14.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Run the positive control a representative learner making and reporting the secure decision in a realistic scenario; exercise negative, stale, duplicate, bypass, and outage controls including a missed assignment, incorrect decision, inaccessible content, stale scenario, role mismatch, failed report channel, and ineffective retraining.",
          "zh": "运行正向控制“代表性人员在真实情境中作出并报告安全决策”，并执行包含“漏分配、错误决策、内容不可访问、情境陈旧、岗位不匹配、报告通道失败和再培训无效”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-14.6-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "14.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Run the positive control a representative report that reaches command, coordinated response, recovery, review, and verified action closure; exercise negative, stale, duplicate, bypass, and outage controls including threshold ambiguity, primary-channel loss, absent role, provider delay, evidence gap, failed containment, recovery dependency, and action recurrence.",
          "zh": "运行正向控制“一项代表性报告进入指挥、协同响应、恢复、复盘并完成行动验证关闭”，并执行包含“阈值歧义、主通道丢失、角色缺席、提供商延迟、证据缺口、遏制失败、恢复依赖和行动复发”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-14.6-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "14.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-14.6-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "14.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-14.6-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "14.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-14.6-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "14.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-14.6-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "14.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever HR and role data, learning platforms, policy and threat changes, simulations, helpdesk and incident reports, assessments, and manager attestations change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 HR 与角色数据、学习平台、策略与威胁变化、模拟、服务台与事件报告、评估和经理确认 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-14.6-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "14.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Use assigned, started, completed, passed, failed, overdue, exempted, role-mismatched, retrained, reported, and behavior-improved learners to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已分配、已开始、已完成、通过、失败、逾期、豁免、岗位不匹配、再培训、已报告和行为改善人员 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-14.6-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "14.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Use events, incidents, severity, ownership, acknowledgement, decision latency, communication success, containment, recovery, evidence gaps, and overdue corrective actions to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 事件、事故、严重度、责任、确认、决策延迟、通信成功、遏制、恢复、证据缺口和逾期纠正行动 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "14.7",
      "control": 14,
      "title_en": "Train Workforce on How to Identify and Report if Their Enterprise Assets are Missing Security Updates",
      "title_zh": "缺失安全更新识别与报告",
      "first_ig": 1,
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Users",
      "security_function": "Protect",
      "patterns": [
        "training"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [],
        "variables": [
          "GV43",
          "M1",
          "M2",
          "M3",
          "M4",
          "M5",
          "M6"
        ],
        "metric_branches": 2,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "The audience covers users of managed and unmanaged enterprise devices who may see update prompts, unsupported warnings, failed restarts or application version problems.",
          "build": "Teach users not to bypass or indefinitely postpone updates, to keep devices powered/connected during maintenance, distinguish approved prompts and report missing/failed updates to IT.",
          "proof": "Present legitimate, failed, overdue and fake update scenarios and verify correct action/reporting; on a test device, confirm a report reaches asset/patch owners and closes after remediation.",
          "boundary": "Users cannot determine backend, firmware or silent application currency; engineering owns measurement."
        },
        "zh": {
          "scope": "面向可能看到更新 Prompt、不支持警告、重启失败或版本问题的受管/非受管设备用户；培训要说明真实企业更新体验和 IT 报告入口，也要防“假更新”钓鱼。",
          "build": "教用户不绕过或无限延期，维护窗保持开机/联网，识别批准 Prompt，并向 IT 报告缺失/失败；同时自动补丁、清晰通知和支持必须可用。",
          "proof": "给出正常、失败、逾期和假更新场景，验证动作/报告；在测试设备确认报告能到资产/补丁负责人并修复关闭，把重复可见故障回馈自动化/沟通。",
          "boundary": "用户无法判断后台、固件和静默应用版本，工程负责度量。"
        }
      },
      "category_counts": {
        "outcome": 6,
        "scope": 6,
        "ownership": 6,
        "data": 6,
        "integration": 6,
        "control": 6,
        "timing": 6,
        "exception": 6,
        "evidence": 6,
        "security": 6,
        "testing": 6,
        "operations": 6
      },
      "requirement_count": 72,
      "requirements": [
        {
          "code": "CIS-14.7-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "14.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Train Workforce on How to Identify and Report if Their Enterprise Assets are Missing Security Updates; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“缺失安全更新识别与报告”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-14.7-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "14.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 14.7, official Asset Class Users, Security Function Protect, and IG1 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 14.7、官方资产类别“用户与身份”、安全功能“保护”和首次出现的 IG1，并保存来源抓取日期。"
        },
        {
          "code": "CIS-14.7-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "14.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “The audience covers users of managed and unmanaged enterprise devices who may see update prompts, unsupported warnings, failed restarts or application version problems.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“面向可能看到更新 Prompt、不支持警告、重启失败或版本问题的受管/非受管设备用户；培训要说明真实企业更新体验和 IT 报告入口，也要防“假更新”钓鱼。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-14.7-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "14.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-14.7-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "14.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Train Workforce on How to Identify and Report if Their Enterprise Assets are Missing Security Updates to its operating object—workforce roles, required security decisions and skills, training content, participation, comprehension, behavior, reporting, and retraining—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“缺失安全更新识别与报告”连接到其运营对象——人员角色、必需安全决策与技能、培训内容、参与、理解、行为、报告和再培训——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-14.7-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "14.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "For Train Workforce on How to Identify and Report if Their Enterprise Assets are Missing Security Updates, express success as an observable decision over role-specific knowledge, practiced decision, reporting behavior, measurable comprehension, and retraining outcome; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“缺失安全更新识别与报告”，以 岗位相关知识、练习过的决策、报告行为、可测理解和再培训结果 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-14.7-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "14.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-14.7-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "14.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-14.7-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "14.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-14.7-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "14.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-14.7-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "14.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across contractors, temporary and privileged roles, accessibility and language needs, absence, role changes, remote work, simulated-test harm, completion without comprehension, and AI-assisted work; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 承包商、临时与特权角色、无障碍和语言需求、缺席、角色变化、远程工作、模拟伤害、完成却未理解以及 AI 辅助工作 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-14.7-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "14.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Include new hires, contractors, temporary and privileged roles, role changes, accessibility and language needs, absence, remote work, simulation harm, and completion without comprehension in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 新员工、承包商、临时与特权角色、角色变化、无障碍和语言需求、缺席、远程工作、模拟伤害及完成却未理解 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-14.7-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "14.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-14.7-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "14.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-14.7-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "14.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-14.7-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "14.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-14.7-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "14.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind security awareness owners, HR, managers, role experts, legal/privacy, incident response, and workforce members to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 安全意识责任人、HR、直属经理、岗位专家、法务/隐私、事件响应和人员成员 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-14.7-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "14.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Name who may transition need identified → objective and scenario designed → assigned → practiced/assessed → remediated → behavior reviewed → content renewed, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 识别需要 → 设计目标与情境 → 分配 → 练习/评估 → 补救 → 复核行为 → 更新内容，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-14.7-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "14.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-14.7-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "14.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-14.7-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "14.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV43, M1, M2, M3, M4, M5, M6) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV43, M1, M2, M3, M4, M5, M6）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-14.7-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "14.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-14.7-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "14.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the role-to-learning-objective, assignment, completion, and observed-behavior authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把角色—学习目标—分配—完成—行为结果权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-14.7-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "14.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle need identified → objective and scenario designed → assigned → practiced/assessed → remediated → behavior reviewed → content renewed.",
          "zh": "对生命周期“识别需要 → 设计目标与情境 → 分配 → 练习/评估 → 补救 → 复核行为 → 更新内容”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-14.7-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "14.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for no explicit predecessor in the pinned CAS page; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 固定 CAS 页面没有列出显式前置项 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-14.7-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "14.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-14.7-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "14.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-14.7-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "14.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-14.7-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "14.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile HR and role data, learning platforms, policy and threat changes, simulations, helpdesk and incident reports, assessments, and manager attestations and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 HR 与角色数据、学习平台、策略与威胁变化、模拟、服务台与事件报告、评估和经理确认，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-14.7-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "14.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Require every connector carrying role-specific knowledge, practiced decision, reporting behavior, measurable comprehension, and retraining outcome to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 岗位相关知识、练习过的决策、报告行为、可测理解和再培训结果 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-14.7-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "14.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Teach users not to bypass or indefinitely postpone updates, to keep devices powered/connected during maintenance, distinguish approved prompts and report missing/failed updates to IT.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“教用户不绕过或无限延期，维护窗保持开机/联网，识别批准 Prompt，并向 IT 报告缺失/失败；同时自动补丁、清晰通知和支持必须可用。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-14.7-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "14.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-14.7-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "14.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-14.7-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "14.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-14.7-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "14.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the role-to-learning-objective, assignment, completion, and observed-behavior authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在角色—学习目标—分配—完成—行为结果权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-14.7-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "14.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Implement the explicit state machine need identified → objective and scenario designed → assigned → practiced/assessed → remediated → behavior reviewed → content renewed; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“识别需要 → 设计目标与情境 → 分配 → 练习/评估 → 补救 → 复核行为 → 更新内容”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-14.7-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "14.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-14.7-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "14.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-14.7-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "14.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-14.7-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "14.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-14.7-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "14.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in workforce roles, required security decisions and skills, training content, participation, comprehension, behavior, reporting, and retraining; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 人员角色、必需安全决策与技能、培训内容、参与、理解、行为、报告和再培训 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-14.7-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "14.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for need identified → objective and scenario designed → assigned → practiced/assessed → remediated → behavior reviewed → content renewed; alert before each deadline becomes overdue.",
          "zh": "为“识别需要 → 设计目标与情境 → 分配 → 练习/评估 → 补救 → 复核行为 → 更新内容”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-14.7-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "14.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “Users cannot determine backend, firmware or silent application currency; engineering owns measurement.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“用户无法判断后台、固件和静默应用版本，工程负责度量。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-14.7-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "14.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-14.7-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "14.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-14.7-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "14.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-14.7-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "14.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat contractors, temporary and privileged roles, accessibility and language needs, absence, role changes, remote work, simulated-test harm, completion without comprehension, and AI-assisted work as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 承包商、临时与特权角色、无障碍和语言需求、缺席、角色变化、远程工作、模拟伤害、完成却未理解以及 AI 辅助工作 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-14.7-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "14.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Treat new hires, contractors, temporary and privileged roles, role changes, accessibility and language needs, absence, remote work, simulation harm, and completion without comprehension as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 新员工、承包商、临时与特权角色、角色变化、无障碍和语言需求、缺席、远程工作、模拟伤害及完成却未理解 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-14.7-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "14.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Present legitimate, failed, overdue and fake update scenarios and verify correct action/reporting; on a test device, confirm a report reaches asset/patch owners and closes after remediation.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“给出正常、失败、逾期和假更新场景，验证动作/报告；在测试设备确认报告能到资产/补丁负责人并修复关闭，把重复可见故障回馈自动化/沟通。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-14.7-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "14.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-14.7-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "14.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 2 pinned CAS metric branch(es), 7 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 2 个指标分支、7 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-14.7-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "14.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-14.7-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "14.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the role-to-learning-objective, assignment, completion, and observed-behavior authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以角色—学习目标—分配—完成—行为结果权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-14.7-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "14.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Publish assigned, started, completed, passed, failed, overdue, exempted, role-mismatched, retrained, reported, and behavior-improved learners with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已分配、已开始、已完成、通过、失败、逾期、豁免、岗位不匹配、再培训、已报告和行为改善人员，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-14.7-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "14.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-14.7-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "14.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-14.7-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "14.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-14.7-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "14.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-14.7-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "14.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the role-to-learning-objective, assignment, completion, and observed-behavior authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护角色—学习目标—分配—完成—行为结果权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-14.7-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "14.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Restrict authority to change need identified → objective and scenario designed → assigned → practiced/assessed → remediated → behavior reviewed → content renewed; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“识别需要 → 设计目标与情境 → 分配 → 练习/评估 → 补救 → 复核行为 → 更新内容”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-14.7-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "14.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-14.7-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "14.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-14.7-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "14.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-14.7-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "14.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-14.7-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "14.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise knowledge and scenario checks, correct and incorrect decisions, report-channel use, role change, simulated social engineering, missed training, and retraining effectiveness through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 知识与情境检查、正确与错误决策、报告通道使用、角色变化、社会工程模拟、漏训和再培训效果，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-14.7-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "14.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Run the positive control a representative learner making and reporting the secure decision in a realistic scenario; exercise negative, stale, duplicate, bypass, and outage controls including a missed assignment, incorrect decision, inaccessible content, stale scenario, role mismatch, failed report channel, and ineffective retraining.",
          "zh": "运行正向控制“代表性人员在真实情境中作出并报告安全决策”，并执行包含“漏分配、错误决策、内容不可访问、情境陈旧、岗位不匹配、报告通道失败和再培训无效”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-14.7-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "14.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-14.7-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "14.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-14.7-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "14.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-14.7-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "14.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-14.7-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "14.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever HR and role data, learning platforms, policy and threat changes, simulations, helpdesk and incident reports, assessments, and manager attestations change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 HR 与角色数据、学习平台、策略与威胁变化、模拟、服务台与事件报告、评估和经理确认 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-14.7-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "14.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Use assigned, started, completed, passed, failed, overdue, exempted, role-mismatched, retrained, reported, and behavior-improved learners to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已分配、已开始、已完成、通过、失败、逾期、豁免、岗位不匹配、再培训、已报告和行为改善人员 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "14.8",
      "control": 14,
      "title_en": "Train Workforce on the Dangers of Connecting to and Transmitting Enterprise Data Over Insecure Networks",
      "title_zh": "不安全网络风险",
      "first_ig": 1,
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Users",
      "security_function": "Protect",
      "patterns": [
        "training",
        "network",
        "data_lifecycle"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [],
        "variables": [
          "GV43",
          "M1",
          "M2",
          "M3",
          "M4",
          "M5",
          "M6"
        ],
        "metric_branches": 2,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "Cover home, public Wi-Fi, guest, cellular, hotel/captive portal, personal hotspot and other networks used for enterprise activity, including metadata exposure, rogue access points, insecure routers and unsafe sharing.",
          "build": "Teach network selection, home-router administration/update/encryption, avoiding shared credentials, use of enterprise protected access, disabling unnecessary sharing and what to do when only an untrusted network is available.",
          "proof": "Scenario-test a fake/ambiguous hotspot and remote-access failure; verify users choose the protected path and report issues.",
          "boundary": "Modern encrypted applications reduce but do not erase network risk; users should not infer a network is safe from a padlock."
        },
        "zh": {
          "scope": "覆盖家庭、公共 Wi-Fi、Guest、蜂窝、酒店/Captive Portal、热点等用于企业活动的网络，包括元数据、Rogue AP、弱家用路由和不安全共享；指导要匹配真实 VPN/ZTNA/设备控制。",
          "build": "教网络选择、家用路由管理/更新/加密、不共享凭据、使用企业保护接入、关不必要共享和无可信网时怎么办；提供受管工具/支持，不能要求人人成为路由专家。",
          "proof": "场景测试假/模糊热点与远程接入故障，验证选受保护路径和报告；确认受管设备在公共 Profile 自动强制防火墙、DNS、VPN/身份，并抽样家用指南可行/无障碍。",
          "boundary": "现代加密应用降低但未消除网络风险，不能把锁图标理解为网络安全。"
        }
      },
      "category_counts": {
        "outcome": 8,
        "scope": 8,
        "ownership": 8,
        "data": 8,
        "integration": 8,
        "control": 8,
        "timing": 8,
        "exception": 8,
        "evidence": 8,
        "security": 8,
        "testing": 8,
        "operations": 8
      },
      "requirement_count": 96,
      "requirements": [
        {
          "code": "CIS-14.8-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "14.8",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Train Workforce on the Dangers of Connecting to and Transmitting Enterprise Data Over Insecure Networks; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“不安全网络风险”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-14.8-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "14.8",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 14.8, official Asset Class Users, Security Function Protect, and IG1 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 14.8、官方资产类别“用户与身份”、安全功能“保护”和首次出现的 IG1，并保存来源抓取日期。"
        },
        {
          "code": "CIS-14.8-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "14.8",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Cover home, public Wi-Fi, guest, cellular, hotel/captive portal, personal hotspot and other networks used for enterprise activity, including metadata exposure, rogue access points, insecure routers and unsafe sharing.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“覆盖家庭、公共 Wi-Fi、Guest、蜂窝、酒店/Captive Portal、热点等用于企业活动的网络，包括元数据、Rogue AP、弱家用路由和不安全共享；指导要匹配真实 VPN/ZTNA/设备控制。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-14.8-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "14.8",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-14.8-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "14.8",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Train Workforce on the Dangers of Connecting to and Transmitting Enterprise Data Over Insecure Networks to its operating object—workforce roles, required security decisions and skills, training content, participation, comprehension, behavior, reporting, and retraining—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“不安全网络风险”连接到其运营对象——人员角色、必需安全决策与技能、培训内容、参与、理解、行为、报告和再培训——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-14.8-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "14.8",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "For Train Workforce on the Dangers of Connecting to and Transmitting Enterprise Data Over Insecure Networks, express success as an observable decision over role-specific knowledge, practiced decision, reporting behavior, measurable comprehension, and retraining outcome; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“不安全网络风险”，以 岗位相关知识、练习过的决策、报告行为、可测理解和再培训结果 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-14.8-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "14.8",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "For Train Workforce on the Dangers of Connecting to and Transmitting Enterprise Data Over Insecure Networks, express success as an observable decision over intended connectivity, trust zone, route, protocol, identity, management path, traffic decision, and observed outcome; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“不安全网络风险”，以 预期连接、信任区、路由、协议、身份、管理路径、流量决策和观察结果 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-14.8-OUT-08",
          "local_code": "OUT-08",
          "display_code": "O08",
          "safeguard_id": "14.8",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "For Train Workforce on the Dangers of Connecting to and Transmitting Enterprise Data Over Insecure Networks, express success as an observable decision over data identity, sensitivity, owner, purpose, location, flow, access, retention, copy, derivation, and disposal state; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“不安全网络风险”，以 数据身份、敏感度、责任人、目的、位置、流向、访问、保留、副本、派生与销毁状态 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-14.8-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "14.8",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-14.8-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "14.8",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-14.8-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "14.8",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-14.8-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "14.8",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-14.8-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "14.8",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across contractors, temporary and privileged roles, accessibility and language needs, absence, role changes, remote work, simulated-test harm, completion without comprehension, and AI-assisted work; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 承包商、临时与特权角色、无障碍和语言需求、缺席、角色变化、远程工作、模拟伤害、完成却未理解以及 AI 辅助工作 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-14.8-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "14.8",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Include new hires, contractors, temporary and privileged roles, role changes, accessibility and language needs, absence, remote work, simulation harm, and completion without comprehension in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 新员工、承包商、临时与特权角色、角色变化、无障碍和语言需求、缺席、远程工作、模拟伤害及完成却未理解 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-14.8-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "14.8",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Include IPv6, overlays, east-west paths, remote and roaming devices, direct egress, alternate resolvers, QUIC, asymmetric routes, provider abstraction, and emergency consoles in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 IPv6、覆盖网络、东西向路径、远程与漫游设备、直接出口、替代解析器、QUIC、非对称路由、提供商抽象和紧急控制台 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-14.8-SCP-08",
          "local_code": "SCP-08",
          "display_code": "P08",
          "safeguard_id": "14.8",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Include unstructured and derived data, logs, caches, backups, exports, client-side copies, cross-region processing, AI corpora, holds, and provider residues in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 非结构化与派生数据、日志、缓存、备份、导出、客户端副本、跨地域处理、AI 语料、保全和提供商残留 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-14.8-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "14.8",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-14.8-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "14.8",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-14.8-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "14.8",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-14.8-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "14.8",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-14.8-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "14.8",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind security awareness owners, HR, managers, role experts, legal/privacy, incident response, and workforce members to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 安全意识责任人、HR、直属经理、岗位专家、法务/隐私、事件响应和人员成员 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-14.8-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "14.8",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Name who may transition need identified → objective and scenario designed → assigned → practiced/assessed → remediated → behavior reviewed → content renewed, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 识别需要 → 设计目标与情境 → 分配 → 练习/评估 → 补救 → 复核行为 → 更新内容，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-14.8-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "14.8",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Name who may transition requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-14.8-OWN-08",
          "local_code": "OWN-08",
          "display_code": "W08",
          "safeguard_id": "14.8",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Name who may transition created/collected → classified → approved use and flow → retained/held → disposed with verification, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-14.8-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "14.8",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-14.8-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "14.8",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-14.8-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "14.8",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV43, M1, M2, M3, M4, M5, M6) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV43, M1, M2, M3, M4, M5, M6）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-14.8-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "14.8",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-14.8-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "14.8",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the role-to-learning-objective, assignment, completion, and observed-behavior authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把角色—学习目标—分配—完成—行为结果权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-14.8-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "14.8",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle need identified → objective and scenario designed → assigned → practiced/assessed → remediated → behavior reviewed → content renewed.",
          "zh": "对生命周期“识别需要 → 设计目标与情境 → 分配 → 练习/评估 → 补救 → 复核行为 → 更新内容”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-14.8-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "14.8",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired.",
          "zh": "对生命周期“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-14.8-DAT-08",
          "local_code": "DAT-08",
          "display_code": "D08",
          "safeguard_id": "14.8",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle created/collected → classified → approved use and flow → retained/held → disposed with verification.",
          "zh": "对生命周期“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-14.8-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "14.8",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for no explicit predecessor in the pinned CAS page; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 固定 CAS 页面没有列出显式前置项 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-14.8-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "14.8",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-14.8-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "14.8",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-14.8-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "14.8",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-14.8-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "14.8",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile HR and role data, learning platforms, policy and threat changes, simulations, helpdesk and incident reports, assessments, and manager attestations and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 HR 与角色数据、学习平台、策略与威胁变化、模拟、服务台与事件报告、评估和经理确认，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-14.8-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "14.8",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Require every connector carrying role-specific knowledge, practiced decision, reporting behavior, measurable comprehension, and retraining outcome to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 岗位相关知识、练习过的决策、报告行为、可测理解和再培训结果 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-14.8-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "14.8",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Require every connector carrying intended connectivity, trust zone, route, protocol, identity, management path, traffic decision, and observed outcome to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 预期连接、信任区、路由、协议、身份、管理路径、流量决策和观察结果 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-14.8-INT-08",
          "local_code": "INT-08",
          "display_code": "I08",
          "safeguard_id": "14.8",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Require every connector carrying data identity, sensitivity, owner, purpose, location, flow, access, retention, copy, derivation, and disposal state to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 数据身份、敏感度、责任人、目的、位置、流向、访问、保留、副本、派生与销毁状态 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-14.8-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "14.8",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Teach network selection, home-router administration/update/encryption, avoiding shared credentials, use of enterprise protected access, disabling unnecessary sharing and what to do when only an untrusted network is available.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“教网络选择、家用路由管理/更新/加密、不共享凭据、使用企业保护接入、关不必要共享和无可信网时怎么办；提供受管工具/支持，不能要求人人成为路由专家。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-14.8-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "14.8",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-14.8-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "14.8",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-14.8-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "14.8",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-14.8-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "14.8",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the role-to-learning-objective, assignment, completion, and observed-behavior authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在角色—学习目标—分配—完成—行为结果权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-14.8-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "14.8",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Implement the explicit state machine need identified → objective and scenario designed → assigned → practiced/assessed → remediated → behavior reviewed → content renewed; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“识别需要 → 设计目标与情境 → 分配 → 练习/评估 → 补救 → 复核行为 → 更新内容”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-14.8-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "14.8",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Implement the explicit state machine requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-14.8-CTL-08",
          "local_code": "CTL-08",
          "display_code": "C08",
          "safeguard_id": "14.8",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Implement the explicit state machine created/collected → classified → approved use and flow → retained/held → disposed with verification; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-14.8-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "14.8",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-14.8-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "14.8",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-14.8-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "14.8",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-14.8-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "14.8",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-14.8-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "14.8",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in workforce roles, required security decisions and skills, training content, participation, comprehension, behavior, reporting, and retraining; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 人员角色、必需安全决策与技能、培训内容、参与、理解、行为、报告和再培训 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-14.8-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "14.8",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for need identified → objective and scenario designed → assigned → practiced/assessed → remediated → behavior reviewed → content renewed; alert before each deadline becomes overdue.",
          "zh": "为“识别需要 → 设计目标与情境 → 分配 → 练习/评估 → 补救 → 复核行为 → 更新内容”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-14.8-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "14.8",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; alert before each deadline becomes overdue.",
          "zh": "为“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-14.8-TIM-08",
          "local_code": "TIM-08",
          "display_code": "T08",
          "safeguard_id": "14.8",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for created/collected → classified → approved use and flow → retained/held → disposed with verification; alert before each deadline becomes overdue.",
          "zh": "为“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-14.8-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "14.8",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “Modern encrypted applications reduce but do not erase network risk; users should not infer a network is safe from a padlock.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“现代加密应用降低但未消除网络风险，不能把锁图标理解为网络安全。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-14.8-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "14.8",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-14.8-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "14.8",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-14.8-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "14.8",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-14.8-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "14.8",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat contractors, temporary and privileged roles, accessibility and language needs, absence, role changes, remote work, simulated-test harm, completion without comprehension, and AI-assisted work as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 承包商、临时与特权角色、无障碍和语言需求、缺席、角色变化、远程工作、模拟伤害、完成却未理解以及 AI 辅助工作 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-14.8-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "14.8",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Treat new hires, contractors, temporary and privileged roles, role changes, accessibility and language needs, absence, remote work, simulation harm, and completion without comprehension as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 新员工、承包商、临时与特权角色、角色变化、无障碍和语言需求、缺席、远程工作、模拟伤害及完成却未理解 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-14.8-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "14.8",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Treat IPv6, overlays, east-west paths, remote and roaming devices, direct egress, alternate resolvers, QUIC, asymmetric routes, provider abstraction, and emergency consoles as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 IPv6、覆盖网络、东西向路径、远程与漫游设备、直接出口、替代解析器、QUIC、非对称路由、提供商抽象和紧急控制台 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-14.8-EXC-08",
          "local_code": "EXC-08",
          "display_code": "X08",
          "safeguard_id": "14.8",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Treat unstructured and derived data, logs, caches, backups, exports, client-side copies, cross-region processing, AI corpora, holds, and provider residues as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 非结构化与派生数据、日志、缓存、备份、导出、客户端副本、跨地域处理、AI 语料、保全和提供商残留 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-14.8-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "14.8",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Scenario-test a fake/ambiguous hotspot and remote-access failure; verify users choose the protected path and report issues.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“场景测试假/模糊热点与远程接入故障，验证选受保护路径和报告；确认受管设备在公共 Profile 自动强制防火墙、DNS、VPN/身份，并抽样家用指南可行/无障碍。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-14.8-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "14.8",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-14.8-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "14.8",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 2 pinned CAS metric branch(es), 7 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 2 个指标分支、7 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-14.8-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "14.8",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-14.8-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "14.8",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the role-to-learning-objective, assignment, completion, and observed-behavior authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以角色—学习目标—分配—完成—行为结果权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-14.8-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "14.8",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Publish assigned, started, completed, passed, failed, overdue, exempted, role-mismatched, retrained, reported, and behavior-improved learners with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已分配、已开始、已完成、通过、失败、逾期、豁免、岗位不匹配、再培训、已报告和行为改善人员，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-14.8-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "14.8",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Publish known, unknown, allowed, denied, shadow, bypassed, asymmetric, stale-rule, exception, and unobserved paths with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已知、未知、允许、拒绝、影子、绕过、非对称、陈旧规则、例外和未观测路径，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-14.8-EVD-08",
          "local_code": "EVD-08",
          "display_code": "E08",
          "safeguard_id": "14.8",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Publish known, unknown, classified, ownerless, over-retained, prematurely deleted, unapproved copy, blocked flow, held, and disposal-verified data sets with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已知、未知、已分类、无责任人、超期保留、过早删除、未批准副本、被阻断流、保全及销毁已验证数据集，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-14.8-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "14.8",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-14.8-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "14.8",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-14.8-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "14.8",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-14.8-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "14.8",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-14.8-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "14.8",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the role-to-learning-objective, assignment, completion, and observed-behavior authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护角色—学习目标—分配—完成—行为结果权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-14.8-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "14.8",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Restrict authority to change need identified → objective and scenario designed → assigned → practiced/assessed → remediated → behavior reviewed → content renewed; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“识别需要 → 设计目标与情境 → 分配 → 练习/评估 → 补救 → 复核行为 → 更新内容”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-14.8-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "14.8",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Restrict authority to change requested flow → identity/context resolved → policy evaluated → allowed/denied → logged → reviewed → rule retired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“申请流量 → 解析身份/上下文 → 评估策略 → 允许/拒绝 → 记录 → 复核 → 退役规则”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-14.8-SEC-08",
          "local_code": "SEC-08",
          "display_code": "S08",
          "safeguard_id": "14.8",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Restrict authority to change created/collected → classified → approved use and flow → retained/held → disposed with verification; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-14.8-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "14.8",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-14.8-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "14.8",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-14.8-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "14.8",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-14.8-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "14.8",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-14.8-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "14.8",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise knowledge and scenario checks, correct and incorrect decisions, report-channel use, role change, simulated social engineering, missed training, and retraining effectiveness through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 知识与情境检查、正确与错误决策、报告通道使用、角色变化、社会工程模拟、漏训和再培训效果，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-14.8-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "14.8",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Run the positive control a representative learner making and reporting the secure decision in a realistic scenario; exercise negative, stale, duplicate, bypass, and outage controls including a missed assignment, incorrect decision, inaccessible content, stale scenario, role mismatch, failed report channel, and ineffective retraining.",
          "zh": "运行正向控制“代表性人员在真实情境中作出并报告安全决策”，并执行包含“漏分配、错误决策、内容不可访问、情境陈旧、岗位不匹配、报告通道失败和再培训无效”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-14.8-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "14.8",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Run the positive control an approved flow over the required secure management or business path; exercise negative, stale, duplicate, bypass, and outage controls including an unapproved route, protocol downgrade, direct egress, alternate DNS/QUIC path, segmentation bypass, AAA loss, stale rule, and rollback failure.",
          "zh": "运行正向控制“通过规定安全管理或业务路径的一项获批流量”，并执行包含“未批准路由、协议降级、直接出口、替代 DNS/QUIC 路径、分段绕过、AAA 丢失、陈旧规则和回滚失败”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-14.8-TST-08",
          "local_code": "TST-08",
          "display_code": "V08",
          "safeguard_id": "14.8",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Run the positive control an approved data set following its declared use, access, transfer, retention, and disposal path; exercise negative, stale, duplicate, bypass, and outage controls including an unknown or misclassified copy, forbidden reader or flow, early deletion, expired retention, failed disposal, and provider residue.",
          "zh": "运行正向控制“按声明用途、访问、传输、保留和销毁路径流转的获批数据集”，并执行包含“未知或误分类副本、禁止读取者或流向、过早删除、保留过期、销毁失败和提供商残留”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-14.8-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "14.8",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-14.8-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "14.8",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-14.8-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "14.8",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-14.8-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "14.8",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-14.8-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "14.8",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever HR and role data, learning platforms, policy and threat changes, simulations, helpdesk and incident reports, assessments, and manager attestations change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 HR 与角色数据、学习平台、策略与威胁变化、模拟、服务台与事件报告、评估和经理确认 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-14.8-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "14.8",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Use assigned, started, completed, passed, failed, overdue, exempted, role-mismatched, retrained, reported, and behavior-improved learners to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已分配、已开始、已完成、通过、失败、逾期、豁免、岗位不匹配、再培训、已报告和行为改善人员 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-14.8-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "14.8",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original network pattern analysis",
          "basis_zh": "SOSEC 原创 network 模式分析",
          "en": "Use known, unknown, allowed, denied, shadow, bypassed, asymmetric, stale-rule, exception, and unobserved paths to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已知、未知、允许、拒绝、影子、绕过、非对称、陈旧规则、例外和未观测路径 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-14.8-OPS-08",
          "local_code": "OPS-08",
          "display_code": "R08",
          "safeguard_id": "14.8",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Use known, unknown, classified, ownerless, over-retained, prematurely deleted, unapproved copy, blocked flow, held, and disposal-verified data sets to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已知、未知、已分类、无责任人、超期保留、过早删除、未批准副本、被阻断流、保全及销毁已验证数据集 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "14.9",
      "control": 14,
      "title_en": "Conduct Role-Specific Security Awareness and Skills Training",
      "title_zh": "角色化安全技能",
      "first_ig": 2,
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Users",
      "security_function": "Protect",
      "patterns": [
        "training"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [],
        "variables": [
          "GV43",
          "M1",
          "M2",
          "M3",
          "M4",
          "M5",
          "M6"
        ],
        "metric_branches": 2,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "The population and curriculum derive from real duties and privileges: administrators, developers, help desk, SOC, finance, HR, executives, data owners, procurement, legal, facilities and high-risk operators.",
          "build": "Map critical tasks and failure modes to roles, assess prerequisites, provide hands-on labs and refresh after tool/threat changes.",
          "proof": "Use practical performance assessments—secure change, code review, identity proofing, incident triage, vendor assessment or payment verification—with positive/negative cases.",
          "boundary": "One role can span several risk domains, and contractors/providers may perform privileged tasks."
        },
        "zh": {
          "scope": "总体和课程来自真实职责与权限：管理员、开发、Helpdesk、SOC、财务、HR、高管、数据所有者、采购、法务、设施和高风险操作。",
          "build": "把关键任务/失败模式映射角色，评估前置能力，提供 Hands-on Lab，工具/威胁变化后刷新；经理负责参加与上岗应用，专家验内容，调岗触发新培训并移除旧权限/要求。",
          "proof": "用安全变更、代码审查、身份核验、事件分诊、供应商评估、付款确认等实操，带正负案例；测任务能力与运营结果并补缺，不能只数完成。",
          "boundary": "一人可跨多个风险域，承包商/服务商也可能做高权工作。"
        }
      },
      "category_counts": {
        "outcome": 6,
        "scope": 6,
        "ownership": 6,
        "data": 6,
        "integration": 6,
        "control": 6,
        "timing": 6,
        "exception": 6,
        "evidence": 6,
        "security": 6,
        "testing": 6,
        "operations": 6
      },
      "requirement_count": 72,
      "requirements": [
        {
          "code": "CIS-14.9-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "14.9",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Conduct Role-Specific Security Awareness and Skills Training; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“角色化安全技能”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-14.9-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "14.9",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 14.9, official Asset Class Users, Security Function Protect, and IG2 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 14.9、官方资产类别“用户与身份”、安全功能“保护”和首次出现的 IG2，并保存来源抓取日期。"
        },
        {
          "code": "CIS-14.9-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "14.9",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “The population and curriculum derive from real duties and privileges: administrators, developers, help desk, SOC, finance, HR, executives, data owners, procurement, legal, facilities and high-risk operators.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“总体和课程来自真实职责与权限：管理员、开发、Helpdesk、SOC、财务、HR、高管、数据所有者、采购、法务、设施和高风险操作。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-14.9-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "14.9",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-14.9-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "14.9",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Conduct Role-Specific Security Awareness and Skills Training to its operating object—workforce roles, required security decisions and skills, training content, participation, comprehension, behavior, reporting, and retraining—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“角色化安全技能”连接到其运营对象——人员角色、必需安全决策与技能、培训内容、参与、理解、行为、报告和再培训——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-14.9-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "14.9",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "For Conduct Role-Specific Security Awareness and Skills Training, express success as an observable decision over role-specific knowledge, practiced decision, reporting behavior, measurable comprehension, and retraining outcome; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“角色化安全技能”，以 岗位相关知识、练习过的决策、报告行为、可测理解和再培训结果 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-14.9-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "14.9",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-14.9-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "14.9",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-14.9-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "14.9",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-14.9-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "14.9",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-14.9-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "14.9",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across contractors, temporary and privileged roles, accessibility and language needs, absence, role changes, remote work, simulated-test harm, completion without comprehension, and AI-assisted work; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 承包商、临时与特权角色、无障碍和语言需求、缺席、角色变化、远程工作、模拟伤害、完成却未理解以及 AI 辅助工作 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-14.9-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "14.9",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Include new hires, contractors, temporary and privileged roles, role changes, accessibility and language needs, absence, remote work, simulation harm, and completion without comprehension in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 新员工、承包商、临时与特权角色、角色变化、无障碍和语言需求、缺席、远程工作、模拟伤害及完成却未理解 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-14.9-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "14.9",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-14.9-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "14.9",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-14.9-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "14.9",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-14.9-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "14.9",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-14.9-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "14.9",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind security awareness owners, HR, managers, role experts, legal/privacy, incident response, and workforce members to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 安全意识责任人、HR、直属经理、岗位专家、法务/隐私、事件响应和人员成员 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-14.9-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "14.9",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Name who may transition need identified → objective and scenario designed → assigned → practiced/assessed → remediated → behavior reviewed → content renewed, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 识别需要 → 设计目标与情境 → 分配 → 练习/评估 → 补救 → 复核行为 → 更新内容，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-14.9-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "14.9",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-14.9-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "14.9",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-14.9-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "14.9",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV43, M1, M2, M3, M4, M5, M6) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV43, M1, M2, M3, M4, M5, M6）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-14.9-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "14.9",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-14.9-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "14.9",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the role-to-learning-objective, assignment, completion, and observed-behavior authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把角色—学习目标—分配—完成—行为结果权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-14.9-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "14.9",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle need identified → objective and scenario designed → assigned → practiced/assessed → remediated → behavior reviewed → content renewed.",
          "zh": "对生命周期“识别需要 → 设计目标与情境 → 分配 → 练习/评估 → 补救 → 复核行为 → 更新内容”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-14.9-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "14.9",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for no explicit predecessor in the pinned CAS page; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 固定 CAS 页面没有列出显式前置项 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-14.9-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "14.9",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-14.9-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "14.9",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-14.9-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "14.9",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-14.9-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "14.9",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile HR and role data, learning platforms, policy and threat changes, simulations, helpdesk and incident reports, assessments, and manager attestations and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 HR 与角色数据、学习平台、策略与威胁变化、模拟、服务台与事件报告、评估和经理确认，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-14.9-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "14.9",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Require every connector carrying role-specific knowledge, practiced decision, reporting behavior, measurable comprehension, and retraining outcome to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 岗位相关知识、练习过的决策、报告行为、可测理解和再培训结果 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-14.9-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "14.9",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Map critical tasks and failure modes to roles, assess prerequisites, provide hands-on labs and refresh after tool/threat changes.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“把关键任务/失败模式映射角色，评估前置能力，提供 Hands-on Lab，工具/威胁变化后刷新；经理负责参加与上岗应用，专家验内容，调岗触发新培训并移除旧权限/要求。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-14.9-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "14.9",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-14.9-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "14.9",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-14.9-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "14.9",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-14.9-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "14.9",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the role-to-learning-objective, assignment, completion, and observed-behavior authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在角色—学习目标—分配—完成—行为结果权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-14.9-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "14.9",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Implement the explicit state machine need identified → objective and scenario designed → assigned → practiced/assessed → remediated → behavior reviewed → content renewed; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“识别需要 → 设计目标与情境 → 分配 → 练习/评估 → 补救 → 复核行为 → 更新内容”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-14.9-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "14.9",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-14.9-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "14.9",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-14.9-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "14.9",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-14.9-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "14.9",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-14.9-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "14.9",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in workforce roles, required security decisions and skills, training content, participation, comprehension, behavior, reporting, and retraining; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 人员角色、必需安全决策与技能、培训内容、参与、理解、行为、报告和再培训 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-14.9-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "14.9",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for need identified → objective and scenario designed → assigned → practiced/assessed → remediated → behavior reviewed → content renewed; alert before each deadline becomes overdue.",
          "zh": "为“识别需要 → 设计目标与情境 → 分配 → 练习/评估 → 补救 → 复核行为 → 更新内容”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-14.9-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "14.9",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “One role can span several risk domains, and contractors/providers may perform privileged tasks.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“一人可跨多个风险域，承包商/服务商也可能做高权工作。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-14.9-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "14.9",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-14.9-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "14.9",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-14.9-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "14.9",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-14.9-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "14.9",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat contractors, temporary and privileged roles, accessibility and language needs, absence, role changes, remote work, simulated-test harm, completion without comprehension, and AI-assisted work as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 承包商、临时与特权角色、无障碍和语言需求、缺席、角色变化、远程工作、模拟伤害、完成却未理解以及 AI 辅助工作 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-14.9-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "14.9",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Treat new hires, contractors, temporary and privileged roles, role changes, accessibility and language needs, absence, remote work, simulation harm, and completion without comprehension as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 新员工、承包商、临时与特权角色、角色变化、无障碍和语言需求、缺席、远程工作、模拟伤害及完成却未理解 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-14.9-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "14.9",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Use practical performance assessments—secure change, code review, identity proofing, incident triage, vendor assessment or payment verification—with positive/negative cases.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“用安全变更、代码审查、身份核验、事件分诊、供应商评估、付款确认等实操，带正负案例；测任务能力与运营结果并补缺，不能只数完成。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-14.9-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "14.9",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-14.9-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "14.9",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 2 pinned CAS metric branch(es), 7 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 2 个指标分支、7 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-14.9-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "14.9",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-14.9-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "14.9",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the role-to-learning-objective, assignment, completion, and observed-behavior authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以角色—学习目标—分配—完成—行为结果权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-14.9-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "14.9",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Publish assigned, started, completed, passed, failed, overdue, exempted, role-mismatched, retrained, reported, and behavior-improved learners with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已分配、已开始、已完成、通过、失败、逾期、豁免、岗位不匹配、再培训、已报告和行为改善人员，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-14.9-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "14.9",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-14.9-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "14.9",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-14.9-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "14.9",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-14.9-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "14.9",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-14.9-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "14.9",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the role-to-learning-objective, assignment, completion, and observed-behavior authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护角色—学习目标—分配—完成—行为结果权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-14.9-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "14.9",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Restrict authority to change need identified → objective and scenario designed → assigned → practiced/assessed → remediated → behavior reviewed → content renewed; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“识别需要 → 设计目标与情境 → 分配 → 练习/评估 → 补救 → 复核行为 → 更新内容”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-14.9-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "14.9",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-14.9-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "14.9",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-14.9-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "14.9",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-14.9-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "14.9",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-14.9-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "14.9",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise knowledge and scenario checks, correct and incorrect decisions, report-channel use, role change, simulated social engineering, missed training, and retraining effectiveness through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 知识与情境检查、正确与错误决策、报告通道使用、角色变化、社会工程模拟、漏训和再培训效果，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-14.9-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "14.9",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Run the positive control a representative learner making and reporting the secure decision in a realistic scenario; exercise negative, stale, duplicate, bypass, and outage controls including a missed assignment, incorrect decision, inaccessible content, stale scenario, role mismatch, failed report channel, and ineffective retraining.",
          "zh": "运行正向控制“代表性人员在真实情境中作出并报告安全决策”，并执行包含“漏分配、错误决策、内容不可访问、情境陈旧、岗位不匹配、报告通道失败和再培训无效”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-14.9-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "14.9",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-14.9-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "14.9",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-14.9-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "14.9",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-14.9-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "14.9",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-14.9-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "14.9",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever HR and role data, learning platforms, policy and threat changes, simulations, helpdesk and incident reports, assessments, and manager attestations change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 HR 与角色数据、学习平台、策略与威胁变化、模拟、服务台与事件报告、评估和经理确认 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-14.9-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "14.9",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Use assigned, started, completed, passed, failed, overdue, exempted, role-mismatched, retrained, reported, and behavior-improved learners to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已分配、已开始、已完成、通过、失败、逾期、豁免、岗位不匹配、再培训、已报告和行为改善人员 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "15.1",
      "control": 15,
      "title_en": "Establish and Maintain an Inventory of Service Providers",
      "title_zh": "服务提供商总账",
      "first_ig": 1,
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Users",
      "security_function": "Identify",
      "patterns": [
        "supplier",
        "inventory"
      ],
      "expanded_complexity": true,
      "cas_context": {
        "dependencies": [],
        "variables": [
          "GV44",
          "GV46",
          "M1",
          "M2",
          "M3",
          "M4",
          "M5",
          "M6",
          "M7"
        ],
        "metric_branches": 2,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [
        "annually"
      ],
      "implementation_contract": {
        "en": {
          "scope": "Include every external entity that stores/processes data, operates technology, supplies security/identity/software, provides infrastructure, has privileged access or materially supports availability—including cloud/SaaS, MSP, processors/subprocessors, contractors and critical open-source/commercial dependencies where a provider relationship exists.",
          "build": "Reconcile procurement, accounts payable, SSO/OAuth, network/API integrations, data flows, software inventory and business-owner attestations.",
          "proof": "Select providers from expense, OAuth, DNS/network, data-flow and application sources and trace both directions to the inventory.",
          "boundary": "A marketplace app or free SaaS can be a provider without a purchase order."
        },
        "zh": {
          "scope": "包括存储/处理数据、运营技术、提供安全/身份/软件、基础设施、高权接入或关键可用支持的外部实体：云/SaaS、MSP、处理者/分包、承包商，以及有服务关系的关键软件依赖。",
          "build": "对账采购、应付、SSO/OAuth、网络/API 集成、数据流、软件台账和业务责任人声明；记录服务、法律实体、责任人、分级、数据/访问、系统、地区、分包、合同/续约、退出与生命周期，每年及变化时更新。",
          "proof": "从费用、OAuth、DNS/网络、数据流和应用来源抽供应商，双向回台账；让测试供应商走新增/终止。",
          "boundary": "免费/市场 App 无 PO 也可能是服务商。"
        }
      },
      "category_counts": {
        "outcome": 8,
        "scope": 8,
        "ownership": 8,
        "data": 8,
        "integration": 8,
        "control": 8,
        "timing": 8,
        "exception": 8,
        "evidence": 8,
        "security": 8,
        "testing": 8,
        "operations": 8
      },
      "requirement_count": 96,
      "requirements": [
        {
          "code": "CIS-15.1-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "15.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Establish and Maintain an Inventory of Service Providers; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“服务提供商总账”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-15.1-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "15.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 15.1, official Asset Class Users, Security Function Identify, and IG1 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 15.1、官方资产类别“用户与身份”、安全功能“识别”和首次出现的 IG1，并保存来源抓取日期。"
        },
        {
          "code": "CIS-15.1-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "15.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Include every external entity that stores/processes data, operates technology, supplies security/identity/software, provides infrastructure, has privileged access or materially supports availability—including cloud/SaaS, MSP, processors/subprocessors, contractors and critical open-source/commercial dependencies where a provider relationship exists.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“包括存储/处理数据、运营技术、提供安全/身份/软件、基础设施、高权接入或关键可用支持的外部实体：云/SaaS、MSP、处理者/分包、承包商，以及有服务关系的关键软件依赖。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-15.1-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "15.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-15.1-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "15.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Establish and Maintain an Inventory of Service Providers to its operating object—service providers, subprocessors, supplied products, integrations, privileged support, data and dependency paths, contracts, evidence, monitoring, and exit—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“服务提供商总账”连接到其运营对象——服务提供商、分处理方、供应产品、集成、特权支持、数据与依赖路径、合同、证据、监测和退出——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-15.1-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "15.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "For Establish and Maintain an Inventory of Service Providers, express success as an observable decision over provider identity, supplied capability, data and privilege path, criticality, contract, assurance, tenant control, incident duty, dependency, and exit; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“服务提供商总账”，以 提供商身份、供应能力、数据与权限路径、关键度、合同、保证、租户控制、事件义务、依赖和退出 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-15.1-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "15.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "For Establish and Maintain an Inventory of Service Providers, express success as an observable decision over observed, approved, unapproved, ownerless, stale, duplicate, and retired object identity; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“服务提供商总账”，以 已观测、已批准、未批准、无责任人、陈旧、重复和已退役对象身份 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-15.1-OUT-08",
          "local_code": "OUT-08",
          "display_code": "O08",
          "safeguard_id": "15.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "For the expanded Establish and Maintain an Inventory of Service Providers scope, resolve conflicts among security, safety, privacy, legal, availability, customer, and operational objectives through an explicit risk decision.",
          "zh": "对“服务提供商总账”的扩展范围，通过显式风险决策解决安全、安全生产、隐私、法律、可用性、客户和运营目标冲突。"
        },
        {
          "code": "CIS-15.1-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "15.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-15.1-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "15.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-15.1-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "15.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-15.1-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "15.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-15.1-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "15.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across shadow vendors, nested subprocessors, click-through terms, provider plan limits, unavailable evidence, acquisitions, shared responsibility, concentration, emergency support, and incomplete deletion; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 影子供应商、嵌套分处理方、点击接受条款、提供商套餐限制、证据不可得、收购、共享责任、集中度、紧急支持和删除不完整 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-15.1-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "15.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Include shadow providers, subprocessors, acquisitions, click-through terms, plan limitations, shared responsibility, concentration, unavailable evidence, emergency support, and residual data in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 影子提供商、分处理方、收购、点击条款、套餐限制、共享责任、集中度、证据不可得、紧急支持和残余数据 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-15.1-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "15.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Include dormant, ephemeral, disconnected, externally managed, provider-held, aliased, cloned, and cross-tenant objects in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 休眠、短生、离线、外部托管、提供商持有、别名、克隆和跨租户对象 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-15.1-SCP-08",
          "local_code": "SCP-08",
          "display_code": "P08",
          "safeguard_id": "15.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Define nested scope at enterprise, business service, tenant, environment, platform, object, identity, data set, and transaction levels; prohibit a parent result from hiding a failing child.",
          "zh": "按企业、业务服务、租户、环境、平台、对象、身份、数据集和交易定义嵌套范围，禁止父级结果遮蔽失败子级。"
        },
        {
          "code": "CIS-15.1-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "15.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-15.1-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "15.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-15.1-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "15.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-15.1-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "15.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-15.1-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "15.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind business and service owners, procurement, legal/privacy, security, architecture, finance, provider management, and incident response to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 业务与服务责任人、采购、法务/隐私、安全、架构、财务、提供商管理和事件响应 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-15.1-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "15.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Name who may transition discovered → owned → classified → contracted → configured → evidenced/monitored → incident/exception → renewed or exited, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 发现 → 确认责任 → 分类 → 签约 → 配置 → 取证/监测 → 事件/例外 → 续约或退出，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-15.1-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "15.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Name who may transition discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-15.1-OWN-08",
          "local_code": "OWN-08",
          "display_code": "W08",
          "safeguard_id": "15.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Model delegated authority, quorum or dual approval where warranted, escalation deadlines, provider handoffs, conflict resolution, and executive risk acceptance.",
          "zh": "建模委派权限、必要时的双人或法定人数审批、升级期限、提供商交接、冲突解决和管理层风险接受。"
        },
        {
          "code": "CIS-15.1-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "15.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-15.1-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "15.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-15.1-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "15.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV44, GV46, M1, M2, M3, M4, M5, M6, M7) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV44, GV46, M1, M2, M3, M4, M5, M6, M7）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-15.1-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "15.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-15.1-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "15.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the service-provider inventory, classification, contract, assurance, and lifecycle authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把服务提供商清单、分类、合同、保证与生命周期权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-15.1-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "15.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle discovered → owned → classified → contracted → configured → evidenced/monitored → incident/exception → renewed or exited.",
          "zh": "对生命周期“发现 → 确认责任 → 分类 → 签约 → 配置 → 取证/监测 → 事件/例外 → 续约或退出”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-15.1-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "15.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence.",
          "zh": "对生命周期“发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-15.1-DAT-08",
          "local_code": "DAT-08",
          "display_code": "D08",
          "safeguard_id": "15.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Version schemas and state transitions with migration, backfill, deduplication, lineage, historical denominator, deletion, and rollback semantics.",
          "zh": "对模式和状态转换做版本管理，定义迁移、回填、去重、血缘、历史分母、删除和回滚语义。"
        },
        {
          "code": "CIS-15.1-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "15.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for no explicit predecessor in the pinned CAS page; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 固定 CAS 页面没有列出显式前置项 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-15.1-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "15.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-15.1-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "15.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-15.1-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "15.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-15.1-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "15.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile procurement and finance, SSO and egress, CMDB/service catalogs, contracts, architecture and data flows, attestations, tenant configuration, incidents, and offboarding records and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 采购与财务、SSO 与出口流量、CMDB/服务目录、合同、架构与数据流、证明、租户配置、事件和退出记录，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-15.1-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "15.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Require every connector carrying provider identity, supplied capability, data and privilege path, criticality, contract, assurance, tenant control, incident duty, dependency, and exit to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 提供商身份、供应能力、数据与权限路径、关键度、合同、保证、租户控制、事件义务、依赖和退出 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-15.1-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "15.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Require every connector carrying observed, approved, unapproved, ownerless, stale, duplicate, and retired object identity to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 已观测、已批准、未批准、无责任人、陈旧、重复和已退役对象身份 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-15.1-INT-08",
          "local_code": "INT-08",
          "display_code": "I08",
          "safeguard_id": "15.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Define consistency rules across disagreeing sources, source precedence, confidence, reconciliation queues, dead-letter handling, reprocessing, and end-to-end trace identity.",
          "zh": "定义冲突来源的一致性、优先级、置信度、对账队列、死信、重处理和端到端追踪身份。"
        },
        {
          "code": "CIS-15.1-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "15.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Reconcile procurement, accounts payable, SSO/OAuth, network/API integrations, data flows, software inventory and business-owner attestations.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“对账采购、应付、SSO/OAuth、网络/API 集成、数据流、软件台账和业务责任人声明；记录服务、法律实体、责任人、分级、数据/访问、系统、地区、分包、合同/续约、退出与生命周期，每年及变化时更新。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-15.1-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "15.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-15.1-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "15.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-15.1-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "15.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-15.1-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "15.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the service-provider inventory, classification, contract, assurance, and lifecycle authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在服务提供商清单、分类、合同、保证与生命周期权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-15.1-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "15.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Implement the explicit state machine discovered → owned → classified → contracted → configured → evidenced/monitored → incident/exception → renewed or exited; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“发现 → 确认责任 → 分类 → 签约 → 配置 → 取证/监测 → 事件/例外 → 续约或退出”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-15.1-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "15.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Implement the explicit state machine discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-15.1-CTL-08",
          "local_code": "CTL-08",
          "display_code": "C08",
          "safeguard_id": "15.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Specify concurrent decisions, partial success, compensating transactions, repeated requests, stale policy, dependency outage, and recovery from an interrupted state transition.",
          "zh": "定义并发决策、部分成功、补偿事务、重复请求、陈旧策略、依赖中断和中途状态转换恢复。"
        },
        {
          "code": "CIS-15.1-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "15.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (annually); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（annually）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-15.1-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "15.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-15.1-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "15.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-15.1-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "15.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-15.1-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "15.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in service providers, subprocessors, supplied products, integrations, privileged support, data and dependency paths, contracts, evidence, monitoring, and exit; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 服务提供商、分处理方、供应产品、集成、特权支持、数据与依赖路径、合同、证据、监测和退出 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-15.1-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "15.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for discovered → owned → classified → contracted → configured → evidenced/monitored → incident/exception → renewed or exited; alert before each deadline becomes overdue.",
          "zh": "为“发现 → 确认责任 → 分类 → 签约 → 配置 → 取证/监测 → 事件/例外 → 续约或退出”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-15.1-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "15.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence; alert before each deadline becomes overdue.",
          "zh": "为“发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-15.1-TIM-08",
          "local_code": "TIM-08",
          "display_code": "T08",
          "safeguard_id": "15.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Allocate an end-to-end SLO budget across discovery, collection, processing, approval, enforcement, verification, and closure; prioritize overdue work by consequence and exposure.",
          "zh": "把端到端 SLO 预算分配到发现、采集、处理、审批、执行、验证和关闭，并按后果与暴露排列逾期工作。"
        },
        {
          "code": "CIS-15.1-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "15.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “A marketplace app or free SaaS can be a provider without a purchase order.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“免费/市场 App 无 PO 也可能是服务商。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-15.1-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "15.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-15.1-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "15.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-15.1-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "15.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-15.1-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "15.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat shadow vendors, nested subprocessors, click-through terms, provider plan limits, unavailable evidence, acquisitions, shared responsibility, concentration, emergency support, and incomplete deletion as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 影子供应商、嵌套分处理方、点击接受条款、提供商套餐限制、证据不可得、收购、共享责任、集中度、紧急支持和删除不完整 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-15.1-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "15.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Treat shadow providers, subprocessors, acquisitions, click-through terms, plan limitations, shared responsibility, concentration, unavailable evidence, emergency support, and residual data as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 影子提供商、分处理方、收购、点击条款、套餐限制、共享责任、集中度、证据不可得、紧急支持和残余数据 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-15.1-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "15.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Treat dormant, ephemeral, disconnected, externally managed, provider-held, aliased, cloned, and cross-tenant objects as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 休眠、短生、离线、外部托管、提供商持有、别名、克隆和跨租户对象 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-15.1-EXC-08",
          "local_code": "EXC-08",
          "display_code": "X08",
          "safeguard_id": "15.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Exercise compound failures where an exception, stale source, provider outage, unavailable owner, and degraded control overlap; define one safe command and one accountable decision.",
          "zh": "演练例外、陈旧来源、提供商中断、责任人不可用和控制降级同时出现的复合故障，明确一条安全指令和一个责任决策。"
        },
        {
          "code": "CIS-15.1-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "15.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Select providers from expense, OAuth, DNS/network, data-flow and application sources and trace both directions to the inventory.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“从费用、OAuth、DNS/网络、数据流和应用来源抽供应商，双向回台账；让测试供应商走新增/终止。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-15.1-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "15.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-15.1-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "15.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 2 pinned CAS metric branch(es), 9 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 2 个指标分支、9 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-15.1-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "15.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-15.1-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "15.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the service-provider inventory, classification, contract, assurance, and lifecycle authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以服务提供商清单、分类、合同、保证与生命周期权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-15.1-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "15.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Publish known, unknown, critical, unclassified, contract-gap, evidence-current, evidence-stale, tenant-misconfigured, incident, concentrated, and exit-incomplete providers with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已知、未知、关键、未分类、合同缺口、证据当前、证据过期、租户误配、事件、集中和退出不完整提供商，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-15.1-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "15.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Publish matched, missing, duplicate, stale, ownerless, unapproved, unevaluable, and retired-without-proof counts with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 匹配、缺失、重复、陈旧、无责任人、未批准、不可评估及无证明退役数量，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-15.1-EVD-08",
          "local_code": "EVD-08",
          "display_code": "E08",
          "safeguard_id": "15.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Require an independent party to reconstruct the decision from source receipts and reproduce the population, state transition, calculation, test result, exception, and final closure.",
          "zh": "要求独立人员使用来源回执重建决策，并复现总体、状态转换、计算、测试结果、例外和最终关闭。"
        },
        {
          "code": "CIS-15.1-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "15.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-15.1-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "15.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-15.1-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "15.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-15.1-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "15.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-15.1-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "15.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the service-provider inventory, classification, contract, assurance, and lifecycle authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护服务提供商清单、分类、合同、保证与生命周期权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-15.1-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "15.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Restrict authority to change discovered → owned → classified → contracted → configured → evidenced/monitored → incident/exception → renewed or exited; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“发现 → 确认责任 → 分类 → 签约 → 配置 → 取证/监测 → 事件/例外 → 续约或退出”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-15.1-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "15.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Restrict authority to change discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-15.1-SEC-08",
          "local_code": "SEC-08",
          "display_code": "S08",
          "safeguard_id": "15.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Threat-model the implementation system itself: forged evidence, poisoned inventory, privilege abuse, cross-tenant confusion, policy rollback, audit deletion, denial of service, and recovery compromise.",
          "zh": "威胁建模实施系统自身：伪造证据、污染清单、权限滥用、跨租户混淆、策略回滚、审计删除、拒绝服务和恢复失陷。"
        },
        {
          "code": "CIS-15.1-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "15.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-15.1-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "15.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-15.1-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "15.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-15.1-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "15.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-15.1-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "15.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise approved and unknown providers, tenant configuration, evidence expiry, control exception, provider incident, API/export loss, privileged support, contract breach, and clean exit through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 获批与未知提供商、租户配置、证据过期、控制例外、提供商事件、API/导出丢失、特权支持、违约和完整退出，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-15.1-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "15.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Run the positive control an approved provider with tested tenant controls, current evidence, notification path, and exit artifact; exercise negative, stale, duplicate, bypass, and outage controls including a shadow provider, missing clause, stale attestation, misconfigured tenant, unavailable export, subprocessor change, provider incident, and residual data after exit.",
          "zh": "运行正向控制“一家具备已测试租户控制、当前证据、通知路径和退出制品的获批提供商”，并执行包含“影子提供商、条款缺失、证明过期、租户误配、导出不可用、分处理方变化、提供商事件和退出后残余数据”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-15.1-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "15.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Run the positive control a seeded approved object reconciled from two independent sources; exercise negative, stale, duplicate, bypass, and outage controls including an unknown object, duplicate identity, stale record, vanished object, failed source, and cross-tenant collision.",
          "zh": "运行正向控制“从两个独立来源对账的一项植入已批准对象”，并执行包含“未知对象、重复身份、陈旧记录、突然消失对象、失效来源和跨租户碰撞”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-15.1-TST-08",
          "local_code": "TST-08",
          "display_code": "V08",
          "safeguard_id": "15.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Build a pairwise platform-and-failure matrix, then add high-consequence multi-factor cases, historical regression, source substitution, red-team challenge, and assessor replay.",
          "zh": "建立平台—故障两两组合矩阵，再加入高后果多因素案例、历史回归、来源替换、红队挑战和评估方重放。"
        },
        {
          "code": "CIS-15.1-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "15.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-15.1-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "15.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-15.1-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "15.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-15.1-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "15.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-15.1-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "15.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever procurement and finance, SSO and egress, CMDB/service catalogs, contracts, architecture and data flows, attestations, tenant configuration, incidents, and offboarding records change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 采购与财务、SSO 与出口流量、CMDB/服务目录、合同、架构与数据流、证明、租户配置、事件和退出记录 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-15.1-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "15.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Use known, unknown, critical, unclassified, contract-gap, evidence-current, evidence-stale, tenant-misconfigured, incident, concentrated, and exit-incomplete providers to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已知、未知、关键、未分类、合同缺口、证据当前、证据过期、租户误配、事件、集中和退出不完整提供商 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-15.1-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "15.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Use matched, missing, duplicate, stale, ownerless, unapproved, unevaluable, and retired-without-proof counts to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 匹配、缺失、重复、陈旧、无责任人、未批准、不可评估及无证明退役数量 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-15.1-OPS-08",
          "local_code": "OPS-08",
          "display_code": "R08",
          "safeguard_id": "15.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Use canary deployment, kill criteria, rollback, backlog burn-down, exception reduction, source-quality targets, quarterly design review, and a measurable retirement plan.",
          "zh": "采用金丝雀、停止标准、回滚、积压燃尽、例外缩减、来源质量目标、季度设计复核和可量化退役计划。"
        }
      ]
    },
    {
      "id": "15.2",
      "control": 15,
      "title_en": "Establish and Maintain a Service Provider Management Policy",
      "title_zh": "服务提供商管理政策",
      "first_ig": 2,
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Documentation",
      "security_function": "Govern",
      "patterns": [
        "supplier",
        "governance"
      ],
      "expanded_complexity": true,
      "cas_context": {
        "dependencies": [],
        "variables": [
          "GV45",
          "M1",
          "M2",
          "M3"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [
        "annually"
      ],
      "implementation_contract": {
        "en": {
          "scope": "The policy governs provider discovery, classification, due diligence, contracting, onboarding, access/data flow, assessment, monitoring, incident/change, renewal and decommissioning.",
          "build": "Assign business, procurement, legal, privacy, security, data and technical responsibilities; define evidence standards, approval authority, exceptions, remediation, continuous monitoring and exit.",
          "proof": "Walk a low- and high-risk provider through request to exit and verify every gate, evidence and decision.",
          "boundary": "A five-topic document can pass CAS completeness while workflows ignore it."
        },
        "zh": {
          "scope": "政策覆盖发现、分级、尽调、合同、上线、访问/数据流、评估、监控、事件/变化、续约和退出；按固有/剩余风险缩放要求，并规定不可让步的最低控制。",
          "build": "分配业务、采购、法务、隐私、安全、数据和技术责任，定义证据标准、批准、例外、修复、持续监控和退出；每年及法规、威胁、供应商、业务模式变化时更新，并接采购/架构 Gate。",
          "proof": "让一低一高风险服务商从申请走到退出，验证每个 Gate、证据和决定；测试紧急采购/续约，检查例外、逾期评估和影子供应商进入治理。",
          "boundary": "五主题文档可过 CAS，但流程可能完全不执行。"
        }
      },
      "category_counts": {
        "outcome": 8,
        "scope": 8,
        "ownership": 8,
        "data": 8,
        "integration": 8,
        "control": 8,
        "timing": 8,
        "exception": 8,
        "evidence": 8,
        "security": 8,
        "testing": 8,
        "operations": 8
      },
      "requirement_count": 96,
      "requirements": [
        {
          "code": "CIS-15.2-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "15.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Establish and Maintain a Service Provider Management Policy; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“服务提供商管理政策”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-15.2-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "15.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 15.2, official Asset Class Documentation, Security Function Govern, and IG2 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 15.2、官方资产类别“文档与治理”、安全功能“治理”和首次出现的 IG2，并保存来源抓取日期。"
        },
        {
          "code": "CIS-15.2-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "15.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “The policy governs provider discovery, classification, due diligence, contracting, onboarding, access/data flow, assessment, monitoring, incident/change, renewal and decommissioning.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“政策覆盖发现、分级、尽调、合同、上线、访问/数据流、评估、监控、事件/变化、续约和退出；按固有/剩余风险缩放要求，并规定不可让步的最低控制。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-15.2-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "15.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-15.2-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "15.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Establish and Maintain a Service Provider Management Policy to its operating object—service providers, subprocessors, supplied products, integrations, privileged support, data and dependency paths, contracts, evidence, monitoring, and exit—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“服务提供商管理政策”连接到其运营对象——服务提供商、分处理方、供应产品、集成、特权支持、数据与依赖路径、合同、证据、监测和退出——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-15.2-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "15.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "For Establish and Maintain a Service Provider Management Policy, express success as an observable decision over provider identity, supplied capability, data and privilege path, criticality, contract, assurance, tenant control, incident duty, dependency, and exit; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“服务提供商管理政策”，以 提供商身份、供应能力、数据与权限路径、关键度、合同、保证、租户控制、事件义务、依赖和退出 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-15.2-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "15.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "For Establish and Maintain a Service Provider Management Policy, express success as an observable decision over a documented decision system with policy, process, procedure, accountable owner, approval, and review; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“服务提供商管理政策”，以 包含策略、流程、程序、责任人、审批和复核的文档化决策系统 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-15.2-OUT-08",
          "local_code": "OUT-08",
          "display_code": "O08",
          "safeguard_id": "15.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "For the expanded Establish and Maintain a Service Provider Management Policy scope, resolve conflicts among security, safety, privacy, legal, availability, customer, and operational objectives through an explicit risk decision.",
          "zh": "对“服务提供商管理政策”的扩展范围，通过显式风险决策解决安全、安全生产、隐私、法律、可用性、客户和运营目标冲突。"
        },
        {
          "code": "CIS-15.2-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "15.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-15.2-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "15.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-15.2-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "15.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-15.2-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "15.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-15.2-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "15.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across shadow vendors, nested subprocessors, click-through terms, provider plan limits, unavailable evidence, acquisitions, shared responsibility, concentration, emergency support, and incomplete deletion; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 影子供应商、嵌套分处理方、点击接受条款、提供商套餐限制、证据不可得、收购、共享责任、集中度、紧急支持和删除不完整 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-15.2-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "15.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Include shadow providers, subprocessors, acquisitions, click-through terms, plan limitations, shared responsibility, concentration, unavailable evidence, emergency support, and residual data in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 影子提供商、分处理方、收购、点击条款、套餐限制、共享责任、集中度、证据不可得、紧急支持和残余数据 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-15.2-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "15.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Include missing policy clauses, conflicting authorities, local deviations, obsolete documentation, and decisions made outside the governed workflow in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 策略条款缺失、权限冲突、本地偏离、文档过期及绕过治理流程的决策 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-15.2-SCP-08",
          "local_code": "SCP-08",
          "display_code": "P08",
          "safeguard_id": "15.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Define nested scope at enterprise, business service, tenant, environment, platform, object, identity, data set, and transaction levels; prohibit a parent result from hiding a failing child.",
          "zh": "按企业、业务服务、租户、环境、平台、对象、身份、数据集和交易定义嵌套范围，禁止父级结果遮蔽失败子级。"
        },
        {
          "code": "CIS-15.2-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "15.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-15.2-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "15.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-15.2-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "15.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-15.2-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "15.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-15.2-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "15.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind business and service owners, procurement, legal/privacy, security, architecture, finance, provider management, and incident response to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 业务与服务责任人、采购、法务/隐私、安全、架构、财务、提供商管理和事件响应 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-15.2-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "15.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Name who may transition discovered → owned → classified → contracted → configured → evidenced/monitored → incident/exception → renewed or exited, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 发现 → 确认责任 → 分类 → 签约 → 配置 → 取证/监测 → 事件/例外 → 续约或退出，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-15.2-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "15.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Name who may transition draft → reviewed → approved → effective → exception/withdrawn → superseded, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-15.2-OWN-08",
          "local_code": "OWN-08",
          "display_code": "W08",
          "safeguard_id": "15.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Model delegated authority, quorum or dual approval where warranted, escalation deadlines, provider handoffs, conflict resolution, and executive risk acceptance.",
          "zh": "建模委派权限、必要时的双人或法定人数审批、升级期限、提供商交接、冲突解决和管理层风险接受。"
        },
        {
          "code": "CIS-15.2-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "15.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-15.2-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "15.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-15.2-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "15.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV45, M1, M2, M3) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV45, M1, M2, M3）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-15.2-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "15.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-15.2-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "15.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the service-provider inventory, classification, contract, assurance, and lifecycle authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把服务提供商清单、分类、合同、保证与生命周期权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-15.2-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "15.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle discovered → owned → classified → contracted → configured → evidenced/monitored → incident/exception → renewed or exited.",
          "zh": "对生命周期“发现 → 确认责任 → 分类 → 签约 → 配置 → 取证/监测 → 事件/例外 → 续约或退出”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-15.2-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "15.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle draft → reviewed → approved → effective → exception/withdrawn → superseded.",
          "zh": "对生命周期“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-15.2-DAT-08",
          "local_code": "DAT-08",
          "display_code": "D08",
          "safeguard_id": "15.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Version schemas and state transitions with migration, backfill, deduplication, lineage, historical denominator, deletion, and rollback semantics.",
          "zh": "对模式和状态转换做版本管理，定义迁移、回填、去重、血缘、历史分母、删除和回滚语义。"
        },
        {
          "code": "CIS-15.2-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "15.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for no explicit predecessor in the pinned CAS page; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 固定 CAS 页面没有列出显式前置项 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-15.2-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "15.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-15.2-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "15.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-15.2-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "15.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-15.2-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "15.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile procurement and finance, SSO and egress, CMDB/service catalogs, contracts, architecture and data flows, attestations, tenant configuration, incidents, and offboarding records and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 采购与财务、SSO 与出口流量、CMDB/服务目录、合同、架构与数据流、证明、租户配置、事件和退出记录，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-15.2-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "15.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Require every connector carrying provider identity, supplied capability, data and privilege path, criticality, contract, assurance, tenant control, incident duty, dependency, and exit to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 提供商身份、供应能力、数据与权限路径、关键度、合同、保证、租户控制、事件义务、依赖和退出 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-15.2-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "15.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Require every connector carrying a documented decision system with policy, process, procedure, accountable owner, approval, and review to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 包含策略、流程、程序、责任人、审批和复核的文档化决策系统 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-15.2-INT-08",
          "local_code": "INT-08",
          "display_code": "I08",
          "safeguard_id": "15.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Define consistency rules across disagreeing sources, source precedence, confidence, reconciliation queues, dead-letter handling, reprocessing, and end-to-end trace identity.",
          "zh": "定义冲突来源的一致性、优先级、置信度、对账队列、死信、重处理和端到端追踪身份。"
        },
        {
          "code": "CIS-15.2-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "15.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Assign business, procurement, legal, privacy, security, data and technical responsibilities; define evidence standards, approval authority, exceptions, remediation, continuous monitoring and exit.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“分配业务、采购、法务、隐私、安全、数据和技术责任，定义证据标准、批准、例外、修复、持续监控和退出；每年及法规、威胁、供应商、业务模式变化时更新，并接采购/架构 Gate。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-15.2-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "15.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-15.2-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "15.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-15.2-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "15.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-15.2-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "15.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the service-provider inventory, classification, contract, assurance, and lifecycle authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在服务提供商清单、分类、合同、保证与生命周期权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-15.2-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "15.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Implement the explicit state machine discovered → owned → classified → contracted → configured → evidenced/monitored → incident/exception → renewed or exited; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“发现 → 确认责任 → 分类 → 签约 → 配置 → 取证/监测 → 事件/例外 → 续约或退出”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-15.2-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "15.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Implement the explicit state machine draft → reviewed → approved → effective → exception/withdrawn → superseded; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-15.2-CTL-08",
          "local_code": "CTL-08",
          "display_code": "C08",
          "safeguard_id": "15.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Specify concurrent decisions, partial success, compensating transactions, repeated requests, stale policy, dependency outage, and recovery from an interrupted state transition.",
          "zh": "定义并发决策、部分成功、补偿事务、重复请求、陈旧策略、依赖中断和中途状态转换恢复。"
        },
        {
          "code": "CIS-15.2-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "15.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (annually); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（annually）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-15.2-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "15.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-15.2-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "15.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-15.2-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "15.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-15.2-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "15.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in service providers, subprocessors, supplied products, integrations, privileged support, data and dependency paths, contracts, evidence, monitoring, and exit; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 服务提供商、分处理方、供应产品、集成、特权支持、数据与依赖路径、合同、证据、监测和退出 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-15.2-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "15.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for discovered → owned → classified → contracted → configured → evidenced/monitored → incident/exception → renewed or exited; alert before each deadline becomes overdue.",
          "zh": "为“发现 → 确认责任 → 分类 → 签约 → 配置 → 取证/监测 → 事件/例外 → 续约或退出”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-15.2-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "15.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for draft → reviewed → approved → effective → exception/withdrawn → superseded; alert before each deadline becomes overdue.",
          "zh": "为“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-15.2-TIM-08",
          "local_code": "TIM-08",
          "display_code": "T08",
          "safeguard_id": "15.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Allocate an end-to-end SLO budget across discovery, collection, processing, approval, enforcement, verification, and closure; prioritize overdue work by consequence and exposure.",
          "zh": "把端到端 SLO 预算分配到发现、采集、处理、审批、执行、验证和关闭，并按后果与暴露排列逾期工作。"
        },
        {
          "code": "CIS-15.2-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "15.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “A five-topic document can pass CAS completeness while workflows ignore it.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“五主题文档可过 CAS，但流程可能完全不执行。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-15.2-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "15.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-15.2-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "15.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-15.2-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "15.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-15.2-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "15.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat shadow vendors, nested subprocessors, click-through terms, provider plan limits, unavailable evidence, acquisitions, shared responsibility, concentration, emergency support, and incomplete deletion as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 影子供应商、嵌套分处理方、点击接受条款、提供商套餐限制、证据不可得、收购、共享责任、集中度、紧急支持和删除不完整 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-15.2-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "15.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Treat shadow providers, subprocessors, acquisitions, click-through terms, plan limitations, shared responsibility, concentration, unavailable evidence, emergency support, and residual data as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 影子提供商、分处理方、收购、点击条款、套餐限制、共享责任、集中度、证据不可得、紧急支持和残余数据 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-15.2-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "15.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Treat missing policy clauses, conflicting authorities, local deviations, obsolete documentation, and decisions made outside the governed workflow as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 策略条款缺失、权限冲突、本地偏离、文档过期及绕过治理流程的决策 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-15.2-EXC-08",
          "local_code": "EXC-08",
          "display_code": "X08",
          "safeguard_id": "15.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Exercise compound failures where an exception, stale source, provider outage, unavailable owner, and degraded control overlap; define one safe command and one accountable decision.",
          "zh": "演练例外、陈旧来源、提供商中断、责任人不可用和控制降级同时出现的复合故障，明确一条安全指令和一个责任决策。"
        },
        {
          "code": "CIS-15.2-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "15.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Walk a low- and high-risk provider through request to exit and verify every gate, evidence and decision.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“让一低一高风险服务商从申请走到退出，验证每个 Gate、证据和决定；测试紧急采购/续约，检查例外、逾期评估和影子供应商进入治理。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-15.2-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "15.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-15.2-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "15.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 4 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、4 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-15.2-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "15.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-15.2-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "15.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the service-provider inventory, classification, contract, assurance, and lifecycle authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以服务提供商清单、分类、合同、保证与生命周期权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-15.2-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "15.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Publish known, unknown, critical, unclassified, contract-gap, evidence-current, evidence-stale, tenant-misconfigured, incident, concentrated, and exit-incomplete providers with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已知、未知、关键、未分类、合同缺口、证据当前、证据过期、租户误配、事件、集中和退出不完整提供商，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-15.2-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "15.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Publish clause coverage, owner and reviewer completeness, approval age, triggered reviews, deviations, overdue actions, and superseded versions still in use with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 条款覆盖、责任人与复核人完整性、批准年龄、触发式复核、偏离、逾期行动及仍在使用的旧版本，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-15.2-EVD-08",
          "local_code": "EVD-08",
          "display_code": "E08",
          "safeguard_id": "15.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Require an independent party to reconstruct the decision from source receipts and reproduce the population, state transition, calculation, test result, exception, and final closure.",
          "zh": "要求独立人员使用来源回执重建决策，并复现总体、状态转换、计算、测试结果、例外和最终关闭。"
        },
        {
          "code": "CIS-15.2-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "15.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-15.2-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "15.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-15.2-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "15.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-15.2-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "15.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-15.2-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "15.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the service-provider inventory, classification, contract, assurance, and lifecycle authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护服务提供商清单、分类、合同、保证与生命周期权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-15.2-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "15.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Restrict authority to change discovered → owned → classified → contracted → configured → evidenced/monitored → incident/exception → renewed or exited; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“发现 → 确认责任 → 分类 → 签约 → 配置 → 取证/监测 → 事件/例外 → 续约或退出”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-15.2-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "15.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Restrict authority to change draft → reviewed → approved → effective → exception/withdrawn → superseded; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-15.2-SEC-08",
          "local_code": "SEC-08",
          "display_code": "S08",
          "safeguard_id": "15.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Threat-model the implementation system itself: forged evidence, poisoned inventory, privilege abuse, cross-tenant confusion, policy rollback, audit deletion, denial of service, and recovery compromise.",
          "zh": "威胁建模实施系统自身：伪造证据、污染清单、权限滥用、跨租户混淆、策略回滚、审计删除、拒绝服务和恢复失陷。"
        },
        {
          "code": "CIS-15.2-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "15.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-15.2-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "15.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-15.2-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "15.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-15.2-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "15.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-15.2-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "15.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise approved and unknown providers, tenant configuration, evidence expiry, control exception, provider incident, API/export loss, privileged support, contract breach, and clean exit through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 获批与未知提供商、租户配置、证据过期、控制例外、提供商事件、API/导出丢失、特权支持、违约和完整退出，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-15.2-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "15.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Run the positive control an approved provider with tested tenant controls, current evidence, notification path, and exit artifact; exercise negative, stale, duplicate, bypass, and outage controls including a shadow provider, missing clause, stale attestation, misconfigured tenant, unavailable export, subprocessor change, provider incident, and residual data after exit.",
          "zh": "运行正向控制“一家具备已测试租户控制、当前证据、通知路径和退出制品的获批提供商”，并执行包含“影子提供商、条款缺失、证明过期、租户误配、导出不可用、分处理方变化、提供商事件和退出后残余数据”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-15.2-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "15.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Run the positive control an approved current process used for a representative decision; exercise negative, stale, duplicate, bypass, and outage controls including an obsolete version, missing approver, undocumented deviation, overdue review, and bypassed workflow.",
          "zh": "运行正向控制“使用当前获批流程完成一项代表性决策”，并执行包含“旧版本、审批人缺失、未记录偏离、逾期复核和绕过流程”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-15.2-TST-08",
          "local_code": "TST-08",
          "display_code": "V08",
          "safeguard_id": "15.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Build a pairwise platform-and-failure matrix, then add high-consequence multi-factor cases, historical regression, source substitution, red-team challenge, and assessor replay.",
          "zh": "建立平台—故障两两组合矩阵，再加入高后果多因素案例、历史回归、来源替换、红队挑战和评估方重放。"
        },
        {
          "code": "CIS-15.2-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "15.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-15.2-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "15.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-15.2-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "15.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-15.2-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "15.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-15.2-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "15.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever procurement and finance, SSO and egress, CMDB/service catalogs, contracts, architecture and data flows, attestations, tenant configuration, incidents, and offboarding records change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 采购与财务、SSO 与出口流量、CMDB/服务目录、合同、架构与数据流、证明、租户配置、事件和退出记录 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-15.2-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "15.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Use known, unknown, critical, unclassified, contract-gap, evidence-current, evidence-stale, tenant-misconfigured, incident, concentrated, and exit-incomplete providers to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已知、未知、关键、未分类、合同缺口、证据当前、证据过期、租户误配、事件、集中和退出不完整提供商 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-15.2-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "15.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Use clause coverage, owner and reviewer completeness, approval age, triggered reviews, deviations, overdue actions, and superseded versions still in use to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 条款覆盖、责任人与复核人完整性、批准年龄、触发式复核、偏离、逾期行动及仍在使用的旧版本 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-15.2-OPS-08",
          "local_code": "OPS-08",
          "display_code": "R08",
          "safeguard_id": "15.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Use canary deployment, kill criteria, rollback, backlog burn-down, exception reduction, source-quality targets, quarterly design review, and a measurable retirement plan.",
          "zh": "采用金丝雀、停止标准、回滚、积压燃尽、例外缩减、来源质量目标、季度设计复核和可量化退役计划。"
        }
      ]
    },
    {
      "id": "15.3",
      "control": 15,
      "title_en": "Classify Service Providers",
      "title_zh": "服务提供商分级",
      "first_ig": 2,
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Users",
      "security_function": "Govern",
      "patterns": [
        "supplier",
        "inventory"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "15.1",
          "15.2"
        ],
        "variables": [
          "GV44",
          "GV45",
          "GV46",
          "M1",
          "M2",
          "M3",
          "M4",
          "M5"
        ],
        "metric_branches": 0,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [
        "annually"
      ],
      "implementation_contract": {
        "en": {
          "scope": "Classification reflects data sensitivity/volume, privilege and connectivity, service criticality/recoverability, substitutability, concentration, jurisdictions, regulations, software/update authority, threat exposure, inherent controls and residual risk.",
          "build": "Define tier criteria and evidence, classify before onboarding, select assessment/contract/monitoring/exit requirements by tier and review annually plus on scope, subprocessor, incident or architecture change.",
          "proof": "Give independent reviewers representative providers and edge cases and compare decisions; trace each tier to actual requirements and sample evidence.",
          "boundary": "A provider can have low confidentiality impact and critical availability impact; keep those ratings separate in a multidimensional model."
        },
        "zh": {
          "scope": "分级考虑数据敏感/体量、权限/连接、关键度/可恢复、可替代、集中度、司法辖区、法规、软件/更新权、威胁暴露、固有控制和剩余风险；规模/花费不是好代理。",
          "build": "定义 Tier 标准/证据，上线前分级，并按 Tier 选择评估、合同、监控和退出；每年及范围、分包、事件、架构变化时重审，业务/安全共同批准剩余风险。",
          "proof": "让独立评审者处理代表与边缘案例，比较结果；把 Tier 追到实际要求并抽证据。",
          "boundary": "低机密供应商也可能有高可用风险，应多维而非单标签。"
        }
      },
      "category_counts": {
        "outcome": 7,
        "scope": 7,
        "ownership": 7,
        "data": 7,
        "integration": 7,
        "control": 7,
        "timing": 7,
        "exception": 7,
        "evidence": 7,
        "security": 7,
        "testing": 7,
        "operations": 7
      },
      "requirement_count": 84,
      "requirements": [
        {
          "code": "CIS-15.3-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "15.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Classify Service Providers; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“服务提供商分级”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-15.3-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "15.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 15.3, official Asset Class Users, Security Function Govern, and IG2 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 15.3、官方资产类别“用户与身份”、安全功能“治理”和首次出现的 IG2，并保存来源抓取日期。"
        },
        {
          "code": "CIS-15.3-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "15.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Classification reflects data sensitivity/volume, privilege and connectivity, service criticality/recoverability, substitutability, concentration, jurisdictions, regulations, software/update authority, threat exposure, inherent controls and residual risk.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“分级考虑数据敏感/体量、权限/连接、关键度/可恢复、可替代、集中度、司法辖区、法规、软件/更新权、威胁暴露、固有控制和剩余风险；规模/花费不是好代理。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-15.3-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "15.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-15.3-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "15.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Classify Service Providers to its operating object—service providers, subprocessors, supplied products, integrations, privileged support, data and dependency paths, contracts, evidence, monitoring, and exit—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“服务提供商分级”连接到其运营对象——服务提供商、分处理方、供应产品、集成、特权支持、数据与依赖路径、合同、证据、监测和退出——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-15.3-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "15.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "For Classify Service Providers, express success as an observable decision over provider identity, supplied capability, data and privilege path, criticality, contract, assurance, tenant control, incident duty, dependency, and exit; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“服务提供商分级”，以 提供商身份、供应能力、数据与权限路径、关键度、合同、保证、租户控制、事件义务、依赖和退出 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-15.3-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "15.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "For Classify Service Providers, express success as an observable decision over observed, approved, unapproved, ownerless, stale, duplicate, and retired object identity; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“服务提供商分级”，以 已观测、已批准、未批准、无责任人、陈旧、重复和已退役对象身份 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-15.3-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "15.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-15.3-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "15.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-15.3-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "15.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-15.3-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "15.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-15.3-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "15.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across shadow vendors, nested subprocessors, click-through terms, provider plan limits, unavailable evidence, acquisitions, shared responsibility, concentration, emergency support, and incomplete deletion; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 影子供应商、嵌套分处理方、点击接受条款、提供商套餐限制、证据不可得、收购、共享责任、集中度、紧急支持和删除不完整 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-15.3-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "15.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Include shadow providers, subprocessors, acquisitions, click-through terms, plan limitations, shared responsibility, concentration, unavailable evidence, emergency support, and residual data in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 影子提供商、分处理方、收购、点击条款、套餐限制、共享责任、集中度、证据不可得、紧急支持和残余数据 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-15.3-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "15.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Include dormant, ephemeral, disconnected, externally managed, provider-held, aliased, cloned, and cross-tenant objects in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 休眠、短生、离线、外部托管、提供商持有、别名、克隆和跨租户对象 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-15.3-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "15.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-15.3-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "15.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-15.3-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "15.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-15.3-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "15.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-15.3-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "15.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind business and service owners, procurement, legal/privacy, security, architecture, finance, provider management, and incident response to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 业务与服务责任人、采购、法务/隐私、安全、架构、财务、提供商管理和事件响应 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-15.3-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "15.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Name who may transition discovered → owned → classified → contracted → configured → evidenced/monitored → incident/exception → renewed or exited, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 发现 → 确认责任 → 分类 → 签约 → 配置 → 取证/监测 → 事件/例外 → 续约或退出，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-15.3-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "15.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Name who may transition discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-15.3-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "15.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-15.3-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "15.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-15.3-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "15.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV44, GV45, GV46, M1, M2, M3, M4, M5) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV44, GV45, GV46, M1, M2, M3, M4, M5）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-15.3-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "15.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-15.3-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "15.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the service-provider inventory, classification, contract, assurance, and lifecycle authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把服务提供商清单、分类、合同、保证与生命周期权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-15.3-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "15.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle discovered → owned → classified → contracted → configured → evidenced/monitored → incident/exception → renewed or exited.",
          "zh": "对生命周期“发现 → 确认责任 → 分类 → 签约 → 配置 → 取证/监测 → 事件/例外 → 续约或退出”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-15.3-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "15.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence.",
          "zh": "对生命周期“发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-15.3-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "15.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 15.1, Safeguard 15.2; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 15.1、Safeguard 15.2 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-15.3-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "15.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-15.3-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "15.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-15.3-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "15.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-15.3-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "15.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile procurement and finance, SSO and egress, CMDB/service catalogs, contracts, architecture and data flows, attestations, tenant configuration, incidents, and offboarding records and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 采购与财务、SSO 与出口流量、CMDB/服务目录、合同、架构与数据流、证明、租户配置、事件和退出记录，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-15.3-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "15.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Require every connector carrying provider identity, supplied capability, data and privilege path, criticality, contract, assurance, tenant control, incident duty, dependency, and exit to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 提供商身份、供应能力、数据与权限路径、关键度、合同、保证、租户控制、事件义务、依赖和退出 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-15.3-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "15.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Require every connector carrying observed, approved, unapproved, ownerless, stale, duplicate, and retired object identity to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 已观测、已批准、未批准、无责任人、陈旧、重复和已退役对象身份 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-15.3-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "15.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Define tier criteria and evidence, classify before onboarding, select assessment/contract/monitoring/exit requirements by tier and review annually plus on scope, subprocessor, incident or architecture change.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“定义 Tier 标准/证据，上线前分级，并按 Tier 选择评估、合同、监控和退出；每年及范围、分包、事件、架构变化时重审，业务/安全共同批准剩余风险。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-15.3-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "15.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-15.3-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "15.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-15.3-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "15.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-15.3-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "15.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the service-provider inventory, classification, contract, assurance, and lifecycle authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在服务提供商清单、分类、合同、保证与生命周期权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-15.3-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "15.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Implement the explicit state machine discovered → owned → classified → contracted → configured → evidenced/monitored → incident/exception → renewed or exited; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“发现 → 确认责任 → 分类 → 签约 → 配置 → 取证/监测 → 事件/例外 → 续约或退出”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-15.3-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "15.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Implement the explicit state machine discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-15.3-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "15.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (annually); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（annually）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-15.3-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "15.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-15.3-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "15.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-15.3-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "15.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-15.3-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "15.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in service providers, subprocessors, supplied products, integrations, privileged support, data and dependency paths, contracts, evidence, monitoring, and exit; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 服务提供商、分处理方、供应产品、集成、特权支持、数据与依赖路径、合同、证据、监测和退出 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-15.3-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "15.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for discovered → owned → classified → contracted → configured → evidenced/monitored → incident/exception → renewed or exited; alert before each deadline becomes overdue.",
          "zh": "为“发现 → 确认责任 → 分类 → 签约 → 配置 → 取证/监测 → 事件/例外 → 续约或退出”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-15.3-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "15.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence; alert before each deadline becomes overdue.",
          "zh": "为“发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-15.3-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "15.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “A provider can have low confidentiality impact and critical availability impact; keep those ratings separate in a multidimensional model.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“低机密供应商也可能有高可用风险，应多维而非单标签。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-15.3-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "15.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-15.3-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "15.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-15.3-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "15.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-15.3-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "15.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat shadow vendors, nested subprocessors, click-through terms, provider plan limits, unavailable evidence, acquisitions, shared responsibility, concentration, emergency support, and incomplete deletion as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 影子供应商、嵌套分处理方、点击接受条款、提供商套餐限制、证据不可得、收购、共享责任、集中度、紧急支持和删除不完整 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-15.3-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "15.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Treat shadow providers, subprocessors, acquisitions, click-through terms, plan limitations, shared responsibility, concentration, unavailable evidence, emergency support, and residual data as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 影子提供商、分处理方、收购、点击条款、套餐限制、共享责任、集中度、证据不可得、紧急支持和残余数据 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-15.3-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "15.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Treat dormant, ephemeral, disconnected, externally managed, provider-held, aliased, cloned, and cross-tenant objects as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 休眠、短生、离线、外部托管、提供商持有、别名、克隆和跨租户对象 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-15.3-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "15.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Give independent reviewers representative providers and edge cases and compare decisions; trace each tier to actual requirements and sample evidence.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“让独立评审者处理代表与边缘案例，比较结果；把 Tier 追到实际要求并抽证据。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-15.3-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "15.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-15.3-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "15.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 0 pinned CAS metric branch(es), 8 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 0 个指标分支、8 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-15.3-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "15.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-15.3-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "15.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the service-provider inventory, classification, contract, assurance, and lifecycle authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以服务提供商清单、分类、合同、保证与生命周期权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-15.3-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "15.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Publish known, unknown, critical, unclassified, contract-gap, evidence-current, evidence-stale, tenant-misconfigured, incident, concentrated, and exit-incomplete providers with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已知、未知、关键、未分类、合同缺口、证据当前、证据过期、租户误配、事件、集中和退出不完整提供商，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-15.3-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "15.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Publish matched, missing, duplicate, stale, ownerless, unapproved, unevaluable, and retired-without-proof counts with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 匹配、缺失、重复、陈旧、无责任人、未批准、不可评估及无证明退役数量，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-15.3-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "15.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-15.3-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "15.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-15.3-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "15.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-15.3-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "15.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-15.3-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "15.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the service-provider inventory, classification, contract, assurance, and lifecycle authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护服务提供商清单、分类、合同、保证与生命周期权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-15.3-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "15.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Restrict authority to change discovered → owned → classified → contracted → configured → evidenced/monitored → incident/exception → renewed or exited; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“发现 → 确认责任 → 分类 → 签约 → 配置 → 取证/监测 → 事件/例外 → 续约或退出”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-15.3-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "15.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Restrict authority to change discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-15.3-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "15.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-15.3-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "15.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-15.3-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "15.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-15.3-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "15.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-15.3-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "15.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise approved and unknown providers, tenant configuration, evidence expiry, control exception, provider incident, API/export loss, privileged support, contract breach, and clean exit through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 获批与未知提供商、租户配置、证据过期、控制例外、提供商事件、API/导出丢失、特权支持、违约和完整退出，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-15.3-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "15.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Run the positive control an approved provider with tested tenant controls, current evidence, notification path, and exit artifact; exercise negative, stale, duplicate, bypass, and outage controls including a shadow provider, missing clause, stale attestation, misconfigured tenant, unavailable export, subprocessor change, provider incident, and residual data after exit.",
          "zh": "运行正向控制“一家具备已测试租户控制、当前证据、通知路径和退出制品的获批提供商”，并执行包含“影子提供商、条款缺失、证明过期、租户误配、导出不可用、分处理方变化、提供商事件和退出后残余数据”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-15.3-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "15.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Run the positive control a seeded approved object reconciled from two independent sources; exercise negative, stale, duplicate, bypass, and outage controls including an unknown object, duplicate identity, stale record, vanished object, failed source, and cross-tenant collision.",
          "zh": "运行正向控制“从两个独立来源对账的一项植入已批准对象”，并执行包含“未知对象、重复身份、陈旧记录、突然消失对象、失效来源和跨租户碰撞”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-15.3-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "15.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-15.3-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "15.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-15.3-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "15.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-15.3-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "15.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-15.3-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "15.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever procurement and finance, SSO and egress, CMDB/service catalogs, contracts, architecture and data flows, attestations, tenant configuration, incidents, and offboarding records change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 采购与财务、SSO 与出口流量、CMDB/服务目录、合同、架构与数据流、证明、租户配置、事件和退出记录 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-15.3-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "15.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Use known, unknown, critical, unclassified, contract-gap, evidence-current, evidence-stale, tenant-misconfigured, incident, concentrated, and exit-incomplete providers to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已知、未知、关键、未分类、合同缺口、证据当前、证据过期、租户误配、事件、集中和退出不完整提供商 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-15.3-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "15.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Use matched, missing, duplicate, stale, ownerless, unapproved, unevaluable, and retired-without-proof counts to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 匹配、缺失、重复、陈旧、无责任人、未批准、不可评估及无证明退役数量 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "15.4",
      "control": 15,
      "title_en": "Ensure Service Provider Contracts Include Security Requirements",
      "title_zh": "合同安全要求",
      "first_ig": 2,
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Documentation",
      "security_function": "Govern",
      "patterns": [
        "supplier"
      ],
      "expanded_complexity": true,
      "cas_context": {
        "dependencies": [
          "15.1",
          "15.2"
        ],
        "variables": [
          "GV44",
          "GV45",
          "M1",
          "M2",
          "M3",
          "M4",
          "M5",
          "M6"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [
        "annually"
      ],
      "implementation_contract": {
        "en": {
          "scope": "Scope contracts, orders, data-processing terms, SLAs and incorporated policies for providers according to classification.",
          "build": "Use tiered clauses with legal/procurement/security review, ensure obligations bind the exact service and subprocessors, negotiate notification and evidence timelines that meet response needs, and map each clause to an operating owner.",
          "proof": "Sample high-risk contracts and trace required events—incident notice, log request, deletion, assessment, recovery—to executable contacts, rights and evidence.",
          "boundary": "A signed contract cannot create a technical capability or make an unenforceable promise useful."
        },
        "zh": {
          "scope": "按供应商分级覆盖合同、订单、DPA、SLA 和引入政策；可含最低安全、最小权限、加密、日志/证据、漏洞/变化、事件/泄露通知、分包、数据地区/用途、连续性、审计、修复、销毁/返还和退出帮助。",
          "build": "用分层条款经法务/采购/安全复核，确保准确服务及分包都受约束，通知/证据时间满足响应，并把条款映射运营责任人；每年及续约/范围变化时复核。",
          "proof": "抽高风险合同，把事件通知、日志请求、删除、评估、恢复追到可执行联系人、权利和证据；桌演泄露/终止，记录缺口、豁免和修复，不能假设 Boilerplate 有效。",
          "boundary": "签合同不能凭空创造技术能力或使不可执行承诺有用。"
        }
      },
      "category_counts": {
        "outcome": 7,
        "scope": 7,
        "ownership": 7,
        "data": 7,
        "integration": 7,
        "control": 7,
        "timing": 7,
        "exception": 7,
        "evidence": 7,
        "security": 7,
        "testing": 7,
        "operations": 7
      },
      "requirement_count": 84,
      "requirements": [
        {
          "code": "CIS-15.4-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "15.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Ensure Service Provider Contracts Include Security Requirements; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“合同安全要求”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-15.4-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "15.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 15.4, official Asset Class Documentation, Security Function Govern, and IG2 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 15.4、官方资产类别“文档与治理”、安全功能“治理”和首次出现的 IG2，并保存来源抓取日期。"
        },
        {
          "code": "CIS-15.4-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "15.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Scope contracts, orders, data-processing terms, SLAs and incorporated policies for providers according to classification.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“按供应商分级覆盖合同、订单、DPA、SLA 和引入政策；可含最低安全、最小权限、加密、日志/证据、漏洞/变化、事件/泄露通知、分包、数据地区/用途、连续性、审计、修复、销毁/返还和退出帮助。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-15.4-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "15.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-15.4-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "15.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Ensure Service Provider Contracts Include Security Requirements to its operating object—service providers, subprocessors, supplied products, integrations, privileged support, data and dependency paths, contracts, evidence, monitoring, and exit—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“合同安全要求”连接到其运营对象——服务提供商、分处理方、供应产品、集成、特权支持、数据与依赖路径、合同、证据、监测和退出——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-15.4-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "15.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "For Ensure Service Provider Contracts Include Security Requirements, express success as an observable decision over provider identity, supplied capability, data and privilege path, criticality, contract, assurance, tenant control, incident duty, dependency, and exit; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“合同安全要求”，以 提供商身份、供应能力、数据与权限路径、关键度、合同、保证、租户控制、事件义务、依赖和退出 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-15.4-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "15.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "For the expanded Ensure Service Provider Contracts Include Security Requirements scope, resolve conflicts among security, safety, privacy, legal, availability, customer, and operational objectives through an explicit risk decision.",
          "zh": "对“合同安全要求”的扩展范围，通过显式风险决策解决安全、安全生产、隐私、法律、可用性、客户和运营目标冲突。"
        },
        {
          "code": "CIS-15.4-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "15.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-15.4-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "15.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-15.4-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "15.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-15.4-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "15.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-15.4-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "15.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across shadow vendors, nested subprocessors, click-through terms, provider plan limits, unavailable evidence, acquisitions, shared responsibility, concentration, emergency support, and incomplete deletion; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 影子供应商、嵌套分处理方、点击接受条款、提供商套餐限制、证据不可得、收购、共享责任、集中度、紧急支持和删除不完整 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-15.4-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "15.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Include shadow providers, subprocessors, acquisitions, click-through terms, plan limitations, shared responsibility, concentration, unavailable evidence, emergency support, and residual data in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 影子提供商、分处理方、收购、点击条款、套餐限制、共享责任、集中度、证据不可得、紧急支持和残余数据 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-15.4-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "15.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Define nested scope at enterprise, business service, tenant, environment, platform, object, identity, data set, and transaction levels; prohibit a parent result from hiding a failing child.",
          "zh": "按企业、业务服务、租户、环境、平台、对象、身份、数据集和交易定义嵌套范围，禁止父级结果遮蔽失败子级。"
        },
        {
          "code": "CIS-15.4-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "15.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-15.4-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "15.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-15.4-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "15.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-15.4-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "15.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-15.4-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "15.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind business and service owners, procurement, legal/privacy, security, architecture, finance, provider management, and incident response to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 业务与服务责任人、采购、法务/隐私、安全、架构、财务、提供商管理和事件响应 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-15.4-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "15.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Name who may transition discovered → owned → classified → contracted → configured → evidenced/monitored → incident/exception → renewed or exited, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 发现 → 确认责任 → 分类 → 签约 → 配置 → 取证/监测 → 事件/例外 → 续约或退出，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-15.4-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "15.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Model delegated authority, quorum or dual approval where warranted, escalation deadlines, provider handoffs, conflict resolution, and executive risk acceptance.",
          "zh": "建模委派权限、必要时的双人或法定人数审批、升级期限、提供商交接、冲突解决和管理层风险接受。"
        },
        {
          "code": "CIS-15.4-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "15.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-15.4-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "15.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-15.4-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "15.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV44, GV45, M1, M2, M3, M4, M5, M6) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV44, GV45, M1, M2, M3, M4, M5, M6）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-15.4-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "15.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-15.4-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "15.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the service-provider inventory, classification, contract, assurance, and lifecycle authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把服务提供商清单、分类、合同、保证与生命周期权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-15.4-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "15.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle discovered → owned → classified → contracted → configured → evidenced/monitored → incident/exception → renewed or exited.",
          "zh": "对生命周期“发现 → 确认责任 → 分类 → 签约 → 配置 → 取证/监测 → 事件/例外 → 续约或退出”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-15.4-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "15.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Version schemas and state transitions with migration, backfill, deduplication, lineage, historical denominator, deletion, and rollback semantics.",
          "zh": "对模式和状态转换做版本管理，定义迁移、回填、去重、血缘、历史分母、删除和回滚语义。"
        },
        {
          "code": "CIS-15.4-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "15.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 15.1, Safeguard 15.2; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 15.1、Safeguard 15.2 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-15.4-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "15.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-15.4-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "15.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-15.4-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "15.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-15.4-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "15.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile procurement and finance, SSO and egress, CMDB/service catalogs, contracts, architecture and data flows, attestations, tenant configuration, incidents, and offboarding records and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 采购与财务、SSO 与出口流量、CMDB/服务目录、合同、架构与数据流、证明、租户配置、事件和退出记录，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-15.4-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "15.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Require every connector carrying provider identity, supplied capability, data and privilege path, criticality, contract, assurance, tenant control, incident duty, dependency, and exit to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 提供商身份、供应能力、数据与权限路径、关键度、合同、保证、租户控制、事件义务、依赖和退出 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-15.4-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "15.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Define consistency rules across disagreeing sources, source precedence, confidence, reconciliation queues, dead-letter handling, reprocessing, and end-to-end trace identity.",
          "zh": "定义冲突来源的一致性、优先级、置信度、对账队列、死信、重处理和端到端追踪身份。"
        },
        {
          "code": "CIS-15.4-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "15.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Use tiered clauses with legal/procurement/security review, ensure obligations bind the exact service and subprocessors, negotiate notification and evidence timelines that meet response needs, and map each clause to an operating owner.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“用分层条款经法务/采购/安全复核，确保准确服务及分包都受约束，通知/证据时间满足响应，并把条款映射运营责任人；每年及续约/范围变化时复核。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-15.4-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "15.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-15.4-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "15.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-15.4-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "15.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-15.4-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "15.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the service-provider inventory, classification, contract, assurance, and lifecycle authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在服务提供商清单、分类、合同、保证与生命周期权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-15.4-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "15.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Implement the explicit state machine discovered → owned → classified → contracted → configured → evidenced/monitored → incident/exception → renewed or exited; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“发现 → 确认责任 → 分类 → 签约 → 配置 → 取证/监测 → 事件/例外 → 续约或退出”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-15.4-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "15.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Specify concurrent decisions, partial success, compensating transactions, repeated requests, stale policy, dependency outage, and recovery from an interrupted state transition.",
          "zh": "定义并发决策、部分成功、补偿事务、重复请求、陈旧策略、依赖中断和中途状态转换恢复。"
        },
        {
          "code": "CIS-15.4-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "15.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (annually); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（annually）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-15.4-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "15.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-15.4-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "15.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-15.4-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "15.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-15.4-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "15.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in service providers, subprocessors, supplied products, integrations, privileged support, data and dependency paths, contracts, evidence, monitoring, and exit; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 服务提供商、分处理方、供应产品、集成、特权支持、数据与依赖路径、合同、证据、监测和退出 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-15.4-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "15.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for discovered → owned → classified → contracted → configured → evidenced/monitored → incident/exception → renewed or exited; alert before each deadline becomes overdue.",
          "zh": "为“发现 → 确认责任 → 分类 → 签约 → 配置 → 取证/监测 → 事件/例外 → 续约或退出”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-15.4-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "15.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Allocate an end-to-end SLO budget across discovery, collection, processing, approval, enforcement, verification, and closure; prioritize overdue work by consequence and exposure.",
          "zh": "把端到端 SLO 预算分配到发现、采集、处理、审批、执行、验证和关闭，并按后果与暴露排列逾期工作。"
        },
        {
          "code": "CIS-15.4-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "15.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “A signed contract cannot create a technical capability or make an unenforceable promise useful.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“签合同不能凭空创造技术能力或使不可执行承诺有用。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-15.4-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "15.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-15.4-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "15.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-15.4-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "15.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-15.4-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "15.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat shadow vendors, nested subprocessors, click-through terms, provider plan limits, unavailable evidence, acquisitions, shared responsibility, concentration, emergency support, and incomplete deletion as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 影子供应商、嵌套分处理方、点击接受条款、提供商套餐限制、证据不可得、收购、共享责任、集中度、紧急支持和删除不完整 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-15.4-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "15.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Treat shadow providers, subprocessors, acquisitions, click-through terms, plan limitations, shared responsibility, concentration, unavailable evidence, emergency support, and residual data as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 影子提供商、分处理方、收购、点击条款、套餐限制、共享责任、集中度、证据不可得、紧急支持和残余数据 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-15.4-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "15.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Exercise compound failures where an exception, stale source, provider outage, unavailable owner, and degraded control overlap; define one safe command and one accountable decision.",
          "zh": "演练例外、陈旧来源、提供商中断、责任人不可用和控制降级同时出现的复合故障，明确一条安全指令和一个责任决策。"
        },
        {
          "code": "CIS-15.4-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "15.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Sample high-risk contracts and trace required events—incident notice, log request, deletion, assessment, recovery—to executable contacts, rights and evidence.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“抽高风险合同，把事件通知、日志请求、删除、评估、恢复追到可执行联系人、权利和证据；桌演泄露/终止，记录缺口、豁免和修复，不能假设 Boilerplate 有效。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-15.4-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "15.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-15.4-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "15.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 8 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、8 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-15.4-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "15.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-15.4-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "15.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the service-provider inventory, classification, contract, assurance, and lifecycle authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以服务提供商清单、分类、合同、保证与生命周期权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-15.4-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "15.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Publish known, unknown, critical, unclassified, contract-gap, evidence-current, evidence-stale, tenant-misconfigured, incident, concentrated, and exit-incomplete providers with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已知、未知、关键、未分类、合同缺口、证据当前、证据过期、租户误配、事件、集中和退出不完整提供商，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-15.4-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "15.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Require an independent party to reconstruct the decision from source receipts and reproduce the population, state transition, calculation, test result, exception, and final closure.",
          "zh": "要求独立人员使用来源回执重建决策，并复现总体、状态转换、计算、测试结果、例外和最终关闭。"
        },
        {
          "code": "CIS-15.4-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "15.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-15.4-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "15.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-15.4-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "15.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-15.4-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "15.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-15.4-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "15.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the service-provider inventory, classification, contract, assurance, and lifecycle authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护服务提供商清单、分类、合同、保证与生命周期权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-15.4-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "15.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Restrict authority to change discovered → owned → classified → contracted → configured → evidenced/monitored → incident/exception → renewed or exited; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“发现 → 确认责任 → 分类 → 签约 → 配置 → 取证/监测 → 事件/例外 → 续约或退出”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-15.4-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "15.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Threat-model the implementation system itself: forged evidence, poisoned inventory, privilege abuse, cross-tenant confusion, policy rollback, audit deletion, denial of service, and recovery compromise.",
          "zh": "威胁建模实施系统自身：伪造证据、污染清单、权限滥用、跨租户混淆、策略回滚、审计删除、拒绝服务和恢复失陷。"
        },
        {
          "code": "CIS-15.4-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "15.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-15.4-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "15.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-15.4-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "15.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-15.4-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "15.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-15.4-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "15.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise approved and unknown providers, tenant configuration, evidence expiry, control exception, provider incident, API/export loss, privileged support, contract breach, and clean exit through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 获批与未知提供商、租户配置、证据过期、控制例外、提供商事件、API/导出丢失、特权支持、违约和完整退出，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-15.4-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "15.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Run the positive control an approved provider with tested tenant controls, current evidence, notification path, and exit artifact; exercise negative, stale, duplicate, bypass, and outage controls including a shadow provider, missing clause, stale attestation, misconfigured tenant, unavailable export, subprocessor change, provider incident, and residual data after exit.",
          "zh": "运行正向控制“一家具备已测试租户控制、当前证据、通知路径和退出制品的获批提供商”，并执行包含“影子提供商、条款缺失、证明过期、租户误配、导出不可用、分处理方变化、提供商事件和退出后残余数据”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-15.4-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "15.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Build a pairwise platform-and-failure matrix, then add high-consequence multi-factor cases, historical regression, source substitution, red-team challenge, and assessor replay.",
          "zh": "建立平台—故障两两组合矩阵，再加入高后果多因素案例、历史回归、来源替换、红队挑战和评估方重放。"
        },
        {
          "code": "CIS-15.4-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "15.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-15.4-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "15.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-15.4-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "15.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-15.4-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "15.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-15.4-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "15.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever procurement and finance, SSO and egress, CMDB/service catalogs, contracts, architecture and data flows, attestations, tenant configuration, incidents, and offboarding records change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 采购与财务、SSO 与出口流量、CMDB/服务目录、合同、架构与数据流、证明、租户配置、事件和退出记录 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-15.4-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "15.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Use known, unknown, critical, unclassified, contract-gap, evidence-current, evidence-stale, tenant-misconfigured, incident, concentrated, and exit-incomplete providers to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已知、未知、关键、未分类、合同缺口、证据当前、证据过期、租户误配、事件、集中和退出不完整提供商 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-15.4-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "15.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Use canary deployment, kill criteria, rollback, backlog burn-down, exception reduction, source-quality targets, quarterly design review, and a measurable retirement plan.",
          "zh": "采用金丝雀、停止标准、回滚、积压燃尽、例外缩减、来源质量目标、季度设计复核和可量化退役计划。"
        }
      ]
    },
    {
      "id": "15.5",
      "control": 15,
      "title_en": "Assess Service Providers",
      "title_zh": "服务提供商评估",
      "first_ig": 3,
      "implementation_groups": [
        3
      ],
      "asset_class": "Users",
      "security_function": "Govern",
      "patterns": [
        "supplier"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "15.1",
          "15.2"
        ],
        "variables": [
          "GV44",
          "GV45",
          "M1",
          "M2",
          "M3",
          "M4"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [
        "annually"
      ],
      "implementation_contract": {
        "en": {
          "scope": "Assess each provider at onboarding, at least annually and at renewal according to classification, using evidence scoped to the exact service, entity, region, period and controls.",
          "build": "Start with service/data/access architecture and shared responsibility, request primary evidence, review exceptions/complementary user controls/subprocessors/incidents, validate remediation and issue a residual-risk decision with expiry.",
          "proof": "For sampled providers, trace claimed controls to report sections, tenant configuration and enterprise responsibilities; verify report period/bridge letter and close findings.",
          "boundary": "A clean certification opinion does not mean no exceptions and may exclude the product used."
        },
        "zh": {
          "scope": "上线、至少每年和续约时，按分级评估准确服务、法律实体、地区、期间和控制。",
          "build": "先画服务/数据/访问和共享责任，收一手证据，审例外、用户补充控制、分包与事件，验证修复并作有到期的剩余风险决定；高权、关键或供应链服务加深。",
          "proof": "抽样把供应商声明追到报告章节、租户配置和企业责任，确认报告期间/Bridge Letter 并关闭发现；合同/风险允许时复做技术或流程控制，并测试证据不足升级。",
          "boundary": "干净认证意见不等于无例外，且可能排除所用产品。"
        }
      },
      "category_counts": {
        "outcome": 6,
        "scope": 6,
        "ownership": 6,
        "data": 6,
        "integration": 6,
        "control": 6,
        "timing": 6,
        "exception": 6,
        "evidence": 6,
        "security": 6,
        "testing": 6,
        "operations": 6
      },
      "requirement_count": 72,
      "requirements": [
        {
          "code": "CIS-15.5-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "15.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Assess Service Providers; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“服务提供商评估”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-15.5-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "15.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 15.5, official Asset Class Users, Security Function Govern, and IG3 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 15.5、官方资产类别“用户与身份”、安全功能“治理”和首次出现的 IG3，并保存来源抓取日期。"
        },
        {
          "code": "CIS-15.5-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "15.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Assess each provider at onboarding, at least annually and at renewal according to classification, using evidence scoped to the exact service, entity, region, period and controls.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“上线、至少每年和续约时，按分级评估准确服务、法律实体、地区、期间和控制。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-15.5-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "15.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-15.5-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "15.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Assess Service Providers to its operating object—service providers, subprocessors, supplied products, integrations, privileged support, data and dependency paths, contracts, evidence, monitoring, and exit—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“服务提供商评估”连接到其运营对象——服务提供商、分处理方、供应产品、集成、特权支持、数据与依赖路径、合同、证据、监测和退出——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-15.5-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "15.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "For Assess Service Providers, express success as an observable decision over provider identity, supplied capability, data and privilege path, criticality, contract, assurance, tenant control, incident duty, dependency, and exit; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“服务提供商评估”，以 提供商身份、供应能力、数据与权限路径、关键度、合同、保证、租户控制、事件义务、依赖和退出 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-15.5-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "15.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-15.5-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "15.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-15.5-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "15.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-15.5-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "15.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-15.5-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "15.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across shadow vendors, nested subprocessors, click-through terms, provider plan limits, unavailable evidence, acquisitions, shared responsibility, concentration, emergency support, and incomplete deletion; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 影子供应商、嵌套分处理方、点击接受条款、提供商套餐限制、证据不可得、收购、共享责任、集中度、紧急支持和删除不完整 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-15.5-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "15.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Include shadow providers, subprocessors, acquisitions, click-through terms, plan limitations, shared responsibility, concentration, unavailable evidence, emergency support, and residual data in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 影子提供商、分处理方、收购、点击条款、套餐限制、共享责任、集中度、证据不可得、紧急支持和残余数据 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-15.5-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "15.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-15.5-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "15.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-15.5-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "15.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-15.5-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "15.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-15.5-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "15.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind business and service owners, procurement, legal/privacy, security, architecture, finance, provider management, and incident response to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 业务与服务责任人、采购、法务/隐私、安全、架构、财务、提供商管理和事件响应 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-15.5-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "15.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Name who may transition discovered → owned → classified → contracted → configured → evidenced/monitored → incident/exception → renewed or exited, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 发现 → 确认责任 → 分类 → 签约 → 配置 → 取证/监测 → 事件/例外 → 续约或退出，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-15.5-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "15.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-15.5-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "15.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-15.5-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "15.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV44, GV45, M1, M2, M3, M4) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV44, GV45, M1, M2, M3, M4）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-15.5-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "15.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-15.5-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "15.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the service-provider inventory, classification, contract, assurance, and lifecycle authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把服务提供商清单、分类、合同、保证与生命周期权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-15.5-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "15.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle discovered → owned → classified → contracted → configured → evidenced/monitored → incident/exception → renewed or exited.",
          "zh": "对生命周期“发现 → 确认责任 → 分类 → 签约 → 配置 → 取证/监测 → 事件/例外 → 续约或退出”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-15.5-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "15.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 15.1, Safeguard 15.2; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 15.1、Safeguard 15.2 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-15.5-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "15.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-15.5-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "15.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-15.5-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "15.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-15.5-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "15.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile procurement and finance, SSO and egress, CMDB/service catalogs, contracts, architecture and data flows, attestations, tenant configuration, incidents, and offboarding records and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 采购与财务、SSO 与出口流量、CMDB/服务目录、合同、架构与数据流、证明、租户配置、事件和退出记录，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-15.5-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "15.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Require every connector carrying provider identity, supplied capability, data and privilege path, criticality, contract, assurance, tenant control, incident duty, dependency, and exit to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 提供商身份、供应能力、数据与权限路径、关键度、合同、保证、租户控制、事件义务、依赖和退出 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-15.5-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "15.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Start with service/data/access architecture and shared responsibility, request primary evidence, review exceptions/complementary user controls/subprocessors/incidents, validate remediation and issue a residual-risk decision with expiry.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“先画服务/数据/访问和共享责任，收一手证据，审例外、用户补充控制、分包与事件，验证修复并作有到期的剩余风险决定；高权、关键或供应链服务加深。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-15.5-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "15.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-15.5-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "15.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-15.5-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "15.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-15.5-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "15.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the service-provider inventory, classification, contract, assurance, and lifecycle authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在服务提供商清单、分类、合同、保证与生命周期权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-15.5-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "15.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Implement the explicit state machine discovered → owned → classified → contracted → configured → evidenced/monitored → incident/exception → renewed or exited; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“发现 → 确认责任 → 分类 → 签约 → 配置 → 取证/监测 → 事件/例外 → 续约或退出”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-15.5-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "15.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (annually); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（annually）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-15.5-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "15.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-15.5-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "15.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-15.5-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "15.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-15.5-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "15.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in service providers, subprocessors, supplied products, integrations, privileged support, data and dependency paths, contracts, evidence, monitoring, and exit; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 服务提供商、分处理方、供应产品、集成、特权支持、数据与依赖路径、合同、证据、监测和退出 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-15.5-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "15.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for discovered → owned → classified → contracted → configured → evidenced/monitored → incident/exception → renewed or exited; alert before each deadline becomes overdue.",
          "zh": "为“发现 → 确认责任 → 分类 → 签约 → 配置 → 取证/监测 → 事件/例外 → 续约或退出”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-15.5-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "15.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “A clean certification opinion does not mean no exceptions and may exclude the product used.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“干净认证意见不等于无例外，且可能排除所用产品。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-15.5-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "15.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-15.5-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "15.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-15.5-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "15.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-15.5-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "15.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat shadow vendors, nested subprocessors, click-through terms, provider plan limits, unavailable evidence, acquisitions, shared responsibility, concentration, emergency support, and incomplete deletion as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 影子供应商、嵌套分处理方、点击接受条款、提供商套餐限制、证据不可得、收购、共享责任、集中度、紧急支持和删除不完整 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-15.5-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "15.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Treat shadow providers, subprocessors, acquisitions, click-through terms, plan limitations, shared responsibility, concentration, unavailable evidence, emergency support, and residual data as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 影子提供商、分处理方、收购、点击条款、套餐限制、共享责任、集中度、证据不可得、紧急支持和残余数据 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-15.5-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "15.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “For sampled providers, trace claimed controls to report sections, tenant configuration and enterprise responsibilities; verify report period/bridge letter and close findings.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“抽样把供应商声明追到报告章节、租户配置和企业责任，确认报告期间/Bridge Letter 并关闭发现；合同/风险允许时复做技术或流程控制，并测试证据不足升级。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-15.5-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "15.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-15.5-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "15.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 6 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、6 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-15.5-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "15.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-15.5-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "15.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the service-provider inventory, classification, contract, assurance, and lifecycle authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以服务提供商清单、分类、合同、保证与生命周期权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-15.5-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "15.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Publish known, unknown, critical, unclassified, contract-gap, evidence-current, evidence-stale, tenant-misconfigured, incident, concentrated, and exit-incomplete providers with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已知、未知、关键、未分类、合同缺口、证据当前、证据过期、租户误配、事件、集中和退出不完整提供商，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-15.5-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "15.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-15.5-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "15.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-15.5-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "15.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-15.5-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "15.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-15.5-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "15.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the service-provider inventory, classification, contract, assurance, and lifecycle authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护服务提供商清单、分类、合同、保证与生命周期权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-15.5-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "15.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Restrict authority to change discovered → owned → classified → contracted → configured → evidenced/monitored → incident/exception → renewed or exited; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“发现 → 确认责任 → 分类 → 签约 → 配置 → 取证/监测 → 事件/例外 → 续约或退出”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-15.5-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "15.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-15.5-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "15.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-15.5-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "15.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-15.5-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "15.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-15.5-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "15.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise approved and unknown providers, tenant configuration, evidence expiry, control exception, provider incident, API/export loss, privileged support, contract breach, and clean exit through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 获批与未知提供商、租户配置、证据过期、控制例外、提供商事件、API/导出丢失、特权支持、违约和完整退出，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-15.5-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "15.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Run the positive control an approved provider with tested tenant controls, current evidence, notification path, and exit artifact; exercise negative, stale, duplicate, bypass, and outage controls including a shadow provider, missing clause, stale attestation, misconfigured tenant, unavailable export, subprocessor change, provider incident, and residual data after exit.",
          "zh": "运行正向控制“一家具备已测试租户控制、当前证据、通知路径和退出制品的获批提供商”，并执行包含“影子提供商、条款缺失、证明过期、租户误配、导出不可用、分处理方变化、提供商事件和退出后残余数据”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-15.5-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "15.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-15.5-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "15.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-15.5-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "15.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-15.5-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "15.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-15.5-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "15.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever procurement and finance, SSO and egress, CMDB/service catalogs, contracts, architecture and data flows, attestations, tenant configuration, incidents, and offboarding records change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 采购与财务、SSO 与出口流量、CMDB/服务目录、合同、架构与数据流、证明、租户配置、事件和退出记录 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-15.5-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "15.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Use known, unknown, critical, unclassified, contract-gap, evidence-current, evidence-stale, tenant-misconfigured, incident, concentrated, and exit-incomplete providers to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已知、未知、关键、未分类、合同缺口、证据当前、证据过期、租户误配、事件、集中和退出不完整提供商 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "15.6",
      "control": 15,
      "title_en": "Monitor Service Providers",
      "title_zh": "服务提供商持续监测",
      "first_ig": 3,
      "implementation_groups": [
        3
      ],
      "asset_class": "Data",
      "security_function": "Govern",
      "patterns": [
        "supplier",
        "discovery"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "15.1",
          "15.2"
        ],
        "variables": [
          "GV44",
          "GV45",
          "M1",
          "M2",
          "M3",
          "M4"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "Monitoring follows provider risk between assessments: security advisories/incidents, releases and breaking changes, control/report updates, domain/certificate and external exposure, service availability, subprocessor/ownership/location changes, access/data-flow drift and dark-web signals where lawful and useful.",
          "build": "Define sources, cadence, thresholds, owner and response by provider tier; combine provider notices, tenant logs, technical telemetry, contract events and credible external intelligence.",
          "proof": "Inject a test provider notice, OAuth-scope change, service outage or overdue evidence and verify triage, owner, decision and access/data response.",
          "boundary": "Internet ratings and dark-web mentions are noisy, externally observable proxies and cannot replace service-specific evidence."
        },
        "zh": {
          "scope": "在两次评估间监控安全通告/事件、Release/破坏性变化、控制报告、域名/证书/外暴露、可用性、分包/所有权/地域、访问/数据流漂移和合法有用的暗网信号。",
          "build": "按 Tier 定来源、频率、阈值、责任和响应，结合供应商通知、租户日志、技术遥测、合同事件和可信外部情报；越阈值即重评/遏制，并记录假消息与来源限制。",
          "proof": "注入测试通知、OAuth Scope 变化、停机或逾期证据，验证分诊、责任、决定和访问/数据响应；抽查信号是否覆盖真实服务、告警是否关闭，并跟踪陈旧 Feed/未观测商。",
          "boundary": "互联网评分和暗网提及噪声高，只是外部代理，不能替代服务证据。"
        }
      },
      "category_counts": {
        "outcome": 7,
        "scope": 7,
        "ownership": 7,
        "data": 7,
        "integration": 7,
        "control": 7,
        "timing": 7,
        "exception": 7,
        "evidence": 7,
        "security": 7,
        "testing": 7,
        "operations": 7
      },
      "requirement_count": 84,
      "requirements": [
        {
          "code": "CIS-15.6-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "15.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Monitor Service Providers; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“服务提供商持续监测”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-15.6-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "15.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 15.6, official Asset Class Data, Security Function Govern, and IG3 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 15.6、官方资产类别“数据”、安全功能“治理”和首次出现的 IG3，并保存来源抓取日期。"
        },
        {
          "code": "CIS-15.6-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "15.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Monitoring follows provider risk between assessments: security advisories/incidents, releases and breaking changes, control/report updates, domain/certificate and external exposure, service availability, subprocessor/ownership/location changes, access/data-flow drift and dark-web signals where lawful and useful.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“在两次评估间监控安全通告/事件、Release/破坏性变化、控制报告、域名/证书/外暴露、可用性、分包/所有权/地域、访问/数据流漂移和合法有用的暗网信号。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-15.6-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "15.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-15.6-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "15.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Monitor Service Providers to its operating object—service providers, subprocessors, supplied products, integrations, privileged support, data and dependency paths, contracts, evidence, monitoring, and exit—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“服务提供商持续监测”连接到其运营对象——服务提供商、分处理方、供应产品、集成、特权支持、数据与依赖路径、合同、证据、监测和退出——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-15.6-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "15.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "For Monitor Service Providers, express success as an observable decision over provider identity, supplied capability, data and privilege path, criticality, contract, assurance, tenant control, incident duty, dependency, and exit; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“服务提供商持续监测”，以 提供商身份、供应能力、数据与权限路径、关键度、合同、保证、租户控制、事件义务、依赖和退出 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-15.6-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "15.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "For Monitor Service Providers, express success as an observable decision over coverage of every intended discovery vantage point, source, job, parser, and reconciliation path; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“服务提供商持续监测”，以 所有预期发现视角、来源、任务、解析器和对账路径的覆盖 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-15.6-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "15.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-15.6-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "15.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-15.6-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "15.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-15.6-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "15.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-15.6-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "15.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across shadow vendors, nested subprocessors, click-through terms, provider plan limits, unavailable evidence, acquisitions, shared responsibility, concentration, emergency support, and incomplete deletion; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 影子供应商、嵌套分处理方、点击接受条款、提供商套餐限制、证据不可得、收购、共享责任、集中度、紧急支持和删除不完整 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-15.6-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "15.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Include shadow providers, subprocessors, acquisitions, click-through terms, plan limitations, shared responsibility, concentration, unavailable evidence, emergency support, and residual data in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 影子提供商、分处理方、收购、点击条款、套餐限制、共享责任、集中度、证据不可得、紧急支持和残余数据 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-15.6-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "15.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Include unreachable zones, short-lived objects, blind spots, rate limits, credential failure, encrypted or proprietary protocols, and silent sensors in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 不可达区域、短生对象、盲区、限流、凭据失败、加密或专有协议和静默传感器 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-15.6-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "15.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-15.6-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "15.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-15.6-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "15.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-15.6-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "15.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-15.6-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "15.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind business and service owners, procurement, legal/privacy, security, architecture, finance, provider management, and incident response to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 业务与服务责任人、采购、法务/隐私、安全、架构、财务、提供商管理和事件响应 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-15.6-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "15.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Name who may transition discovered → owned → classified → contracted → configured → evidenced/monitored → incident/exception → renewed or exited, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 发现 → 确认责任 → 分类 → 签约 → 配置 → 取证/监测 → 事件/例外 → 续约或退出，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-15.6-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "15.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Name who may transition scheduled → started → observed → normalized → reconciled → dispositioned, with explicit partial and failed states, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 计划 → 启动 → 观测 → 归一化 → 对账 → 处置，并显式保留部分与失败状态，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-15.6-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "15.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-15.6-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "15.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-15.6-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "15.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV44, GV45, M1, M2, M3, M4) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV44, GV45, M1, M2, M3, M4）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-15.6-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "15.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-15.6-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "15.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the service-provider inventory, classification, contract, assurance, and lifecycle authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把服务提供商清单、分类、合同、保证与生命周期权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-15.6-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "15.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle discovered → owned → classified → contracted → configured → evidenced/monitored → incident/exception → renewed or exited.",
          "zh": "对生命周期“发现 → 确认责任 → 分类 → 签约 → 配置 → 取证/监测 → 事件/例外 → 续约或退出”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-15.6-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "15.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle scheduled → started → observed → normalized → reconciled → dispositioned, with explicit partial and failed states.",
          "zh": "对生命周期“计划 → 启动 → 观测 → 归一化 → 对账 → 处置，并显式保留部分与失败状态”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-15.6-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "15.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 15.1, Safeguard 15.2; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 15.1、Safeguard 15.2 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-15.6-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "15.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-15.6-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "15.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-15.6-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "15.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-15.6-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "15.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile procurement and finance, SSO and egress, CMDB/service catalogs, contracts, architecture and data flows, attestations, tenant configuration, incidents, and offboarding records and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 采购与财务、SSO 与出口流量、CMDB/服务目录、合同、架构与数据流、证明、租户配置、事件和退出记录，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-15.6-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "15.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Require every connector carrying provider identity, supplied capability, data and privilege path, criticality, contract, assurance, tenant control, incident duty, dependency, and exit to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 提供商身份、供应能力、数据与权限路径、关键度、合同、保证、租户控制、事件义务、依赖和退出 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-15.6-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "15.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Require every connector carrying coverage of every intended discovery vantage point, source, job, parser, and reconciliation path to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 所有预期发现视角、来源、任务、解析器和对账路径的覆盖 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-15.6-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "15.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Define sources, cadence, thresholds, owner and response by provider tier; combine provider notices, tenant logs, technical telemetry, contract events and credible external intelligence.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“按 Tier 定来源、频率、阈值、责任和响应，结合供应商通知、租户日志、技术遥测、合同事件和可信外部情报；越阈值即重评/遏制，并记录假消息与来源限制。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-15.6-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "15.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-15.6-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "15.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-15.6-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "15.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-15.6-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "15.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the service-provider inventory, classification, contract, assurance, and lifecycle authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在服务提供商清单、分类、合同、保证与生命周期权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-15.6-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "15.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Implement the explicit state machine discovered → owned → classified → contracted → configured → evidenced/monitored → incident/exception → renewed or exited; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“发现 → 确认责任 → 分类 → 签约 → 配置 → 取证/监测 → 事件/例外 → 续约或退出”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-15.6-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "15.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Implement the explicit state machine scheduled → started → observed → normalized → reconciled → dispositioned, with explicit partial and failed states; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“计划 → 启动 → 观测 → 归一化 → 对账 → 处置，并显式保留部分与失败状态”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-15.6-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "15.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-15.6-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "15.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-15.6-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "15.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-15.6-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "15.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-15.6-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "15.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in service providers, subprocessors, supplied products, integrations, privileged support, data and dependency paths, contracts, evidence, monitoring, and exit; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 服务提供商、分处理方、供应产品、集成、特权支持、数据与依赖路径、合同、证据、监测和退出 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-15.6-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "15.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for discovered → owned → classified → contracted → configured → evidenced/monitored → incident/exception → renewed or exited; alert before each deadline becomes overdue.",
          "zh": "为“发现 → 确认责任 → 分类 → 签约 → 配置 → 取证/监测 → 事件/例外 → 续约或退出”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-15.6-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "15.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for scheduled → started → observed → normalized → reconciled → dispositioned, with explicit partial and failed states; alert before each deadline becomes overdue.",
          "zh": "为“计划 → 启动 → 观测 → 归一化 → 对账 → 处置，并显式保留部分与失败状态”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-15.6-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "15.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “Internet ratings and dark-web mentions are noisy, externally observable proxies and cannot replace service-specific evidence.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“互联网评分和暗网提及噪声高，只是外部代理，不能替代服务证据。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-15.6-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "15.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-15.6-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "15.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-15.6-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "15.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-15.6-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "15.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat shadow vendors, nested subprocessors, click-through terms, provider plan limits, unavailable evidence, acquisitions, shared responsibility, concentration, emergency support, and incomplete deletion as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 影子供应商、嵌套分处理方、点击接受条款、提供商套餐限制、证据不可得、收购、共享责任、集中度、紧急支持和删除不完整 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-15.6-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "15.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Treat shadow providers, subprocessors, acquisitions, click-through terms, plan limitations, shared responsibility, concentration, unavailable evidence, emergency support, and residual data as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 影子提供商、分处理方、收购、点击条款、套餐限制、共享责任、集中度、证据不可得、紧急支持和残余数据 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-15.6-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "15.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Treat unreachable zones, short-lived objects, blind spots, rate limits, credential failure, encrypted or proprietary protocols, and silent sensors as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 不可达区域、短生对象、盲区、限流、凭据失败、加密或专有协议和静默传感器 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-15.6-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "15.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Inject a test provider notice, OAuth-scope change, service outage or overdue evidence and verify triage, owner, decision and access/data response.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“注入测试通知、OAuth Scope 变化、停机或逾期证据，验证分诊、责任、决定和访问/数据响应；抽查信号是否覆盖真实服务、告警是否关闭，并跟踪陈旧 Feed/未观测商。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-15.6-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "15.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-15.6-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "15.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 6 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、6 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-15.6-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "15.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-15.6-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "15.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the service-provider inventory, classification, contract, assurance, and lifecycle authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以服务提供商清单、分类、合同、保证与生命周期权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-15.6-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "15.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Publish known, unknown, critical, unclassified, contract-gap, evidence-current, evidence-stale, tenant-misconfigured, incident, concentrated, and exit-incomplete providers with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已知、未知、关键、未分类、合同缺口、证据当前、证据过期、租户误配、事件、集中和退出不完整提供商，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-15.6-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "15.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Publish scheduled, successful, partial, failed, stale, blind, newly discovered, unmatched, and reconciled observations with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 计划、成功、部分、失败、陈旧、盲区、新发现、未匹配和已对账观测，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-15.6-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "15.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-15.6-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "15.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-15.6-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "15.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-15.6-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "15.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-15.6-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "15.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the service-provider inventory, classification, contract, assurance, and lifecycle authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护服务提供商清单、分类、合同、保证与生命周期权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-15.6-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "15.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Restrict authority to change discovered → owned → classified → contracted → configured → evidenced/monitored → incident/exception → renewed or exited; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“发现 → 确认责任 → 分类 → 签约 → 配置 → 取证/监测 → 事件/例外 → 续约或退出”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-15.6-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "15.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Restrict authority to change scheduled → started → observed → normalized → reconciled → dispositioned, with explicit partial and failed states; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“计划 → 启动 → 观测 → 归一化 → 对账 → 处置，并显式保留部分与失败状态”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-15.6-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "15.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-15.6-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "15.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-15.6-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "15.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-15.6-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "15.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-15.6-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "15.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise approved and unknown providers, tenant configuration, evidence expiry, control exception, provider incident, API/export loss, privileged support, contract breach, and clean exit through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 获批与未知提供商、租户配置、证据过期、控制例外、提供商事件、API/导出丢失、特权支持、违约和完整退出，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-15.6-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "15.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Run the positive control an approved provider with tested tenant controls, current evidence, notification path, and exit artifact; exercise negative, stale, duplicate, bypass, and outage controls including a shadow provider, missing clause, stale attestation, misconfigured tenant, unavailable export, subprocessor change, provider incident, and residual data after exit.",
          "zh": "运行正向控制“一家具备已测试租户控制、当前证据、通知路径和退出制品的获批提供商”，并执行包含“影子提供商、条款缺失、证明过期、租户误配、导出不可用、分处理方变化、提供商事件和退出后残余数据”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-15.6-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "15.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Run the positive control a known object visible from each representative vantage point; exercise negative, stale, duplicate, bypass, and outage controls including an unknown and short-lived object, failed credential, blocked scan, silent sensor, parser drift, and uncovered segment.",
          "zh": "运行正向控制“从每个代表性视角可见的一项已知对象”，并执行包含“未知与短生对象、凭据失败、扫描受阻、传感器静默、解析漂移和未覆盖网段”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-15.6-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "15.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-15.6-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "15.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-15.6-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "15.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-15.6-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "15.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-15.6-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "15.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever procurement and finance, SSO and egress, CMDB/service catalogs, contracts, architecture and data flows, attestations, tenant configuration, incidents, and offboarding records change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 采购与财务、SSO 与出口流量、CMDB/服务目录、合同、架构与数据流、证明、租户配置、事件和退出记录 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-15.6-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "15.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Use known, unknown, critical, unclassified, contract-gap, evidence-current, evidence-stale, tenant-misconfigured, incident, concentrated, and exit-incomplete providers to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已知、未知、关键、未分类、合同缺口、证据当前、证据过期、租户误配、事件、集中和退出不完整提供商 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-15.6-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "15.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original discovery pattern analysis",
          "basis_zh": "SOSEC 原创 discovery 模式分析",
          "en": "Use scheduled, successful, partial, failed, stale, blind, newly discovered, unmatched, and reconciled observations to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 计划、成功、部分、失败、陈旧、盲区、新发现、未匹配和已对账观测 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "15.7",
      "control": 15,
      "title_en": "Securely Decommission Service Providers",
      "title_zh": "服务提供商安全退出",
      "first_ig": 3,
      "implementation_groups": [
        3
      ],
      "asset_class": "Data",
      "security_function": "Protect",
      "patterns": [
        "supplier"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "15.1",
          "15.2"
        ],
        "variables": [
          "GV44",
          "GV45",
          "M1",
          "M2",
          "M3",
          "M4"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "Decommissioning covers contracts, users/service accounts, keys/tokens/certificates, network and API links, SSO/OAuth, data flows, stored/backup data, domains, software/agents, support access, billing and dependent providers.",
          "build": "Plan exit before onboarding, identify successor/export and retention, freeze changes, export/validate data, revoke access and routes, rotate shared secrets, request and verify disposal, update inventories and monitor for residual use.",
          "proof": "Run an exit checklist against a real or test service, then attempt old login, token, API, network route, DNS/email and data retrieval.",
          "boundary": "Deletion certificates may exclude backups/subprocessors and need scoped interpretation."
        },
        "zh": {
          "scope": "退出覆盖合同、用户/服务账户、Key/Token/证书、网络/API、SSO/OAuth、数据流、存储/备份数据、域名、软件/Agent、支持访问、账单和依赖商；保留法定记录同时终止权限。",
          "build": "上线前就规划退出，确定替代/导出和保留，冻结变化，导出/验数据，撤访问/路由，轮换共享秘密，请求/验证销毁，更新台账并监测残留；业务、技术、数据、法务、安全共同验收。",
          "proof": "用真实或测试服务走清单，再尝试旧登录、Token、API、路由、DNS/邮件和取数；结案后对账事件/费用，验证导出与删除证据，并在服务商保留窗口后复测。",
          "boundary": "删除证明可能排除备份/分包，需看范围。"
        }
      },
      "category_counts": {
        "outcome": 6,
        "scope": 6,
        "ownership": 6,
        "data": 6,
        "integration": 6,
        "control": 6,
        "timing": 6,
        "exception": 6,
        "evidence": 6,
        "security": 6,
        "testing": 6,
        "operations": 6
      },
      "requirement_count": 72,
      "requirements": [
        {
          "code": "CIS-15.7-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "15.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Securely Decommission Service Providers; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“服务提供商安全退出”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-15.7-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "15.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 15.7, official Asset Class Data, Security Function Protect, and IG3 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 15.7、官方资产类别“数据”、安全功能“保护”和首次出现的 IG3，并保存来源抓取日期。"
        },
        {
          "code": "CIS-15.7-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "15.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Decommissioning covers contracts, users/service accounts, keys/tokens/certificates, network and API links, SSO/OAuth, data flows, stored/backup data, domains, software/agents, support access, billing and dependent providers.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“退出覆盖合同、用户/服务账户、Key/Token/证书、网络/API、SSO/OAuth、数据流、存储/备份数据、域名、软件/Agent、支持访问、账单和依赖商；保留法定记录同时终止权限。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-15.7-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "15.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-15.7-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "15.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Securely Decommission Service Providers to its operating object—service providers, subprocessors, supplied products, integrations, privileged support, data and dependency paths, contracts, evidence, monitoring, and exit—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“服务提供商安全退出”连接到其运营对象——服务提供商、分处理方、供应产品、集成、特权支持、数据与依赖路径、合同、证据、监测和退出——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-15.7-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "15.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "For Securely Decommission Service Providers, express success as an observable decision over provider identity, supplied capability, data and privilege path, criticality, contract, assurance, tenant control, incident duty, dependency, and exit; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“服务提供商安全退出”，以 提供商身份、供应能力、数据与权限路径、关键度、合同、保证、租户控制、事件义务、依赖和退出 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-15.7-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "15.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-15.7-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "15.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-15.7-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "15.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-15.7-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "15.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-15.7-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "15.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across shadow vendors, nested subprocessors, click-through terms, provider plan limits, unavailable evidence, acquisitions, shared responsibility, concentration, emergency support, and incomplete deletion; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 影子供应商、嵌套分处理方、点击接受条款、提供商套餐限制、证据不可得、收购、共享责任、集中度、紧急支持和删除不完整 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-15.7-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "15.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Include shadow providers, subprocessors, acquisitions, click-through terms, plan limitations, shared responsibility, concentration, unavailable evidence, emergency support, and residual data in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 影子提供商、分处理方、收购、点击条款、套餐限制、共享责任、集中度、证据不可得、紧急支持和残余数据 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-15.7-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "15.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-15.7-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "15.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-15.7-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "15.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-15.7-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "15.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-15.7-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "15.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind business and service owners, procurement, legal/privacy, security, architecture, finance, provider management, and incident response to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 业务与服务责任人、采购、法务/隐私、安全、架构、财务、提供商管理和事件响应 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-15.7-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "15.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Name who may transition discovered → owned → classified → contracted → configured → evidenced/monitored → incident/exception → renewed or exited, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 发现 → 确认责任 → 分类 → 签约 → 配置 → 取证/监测 → 事件/例外 → 续约或退出，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-15.7-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "15.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-15.7-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "15.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-15.7-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "15.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV44, GV45, M1, M2, M3, M4) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV44, GV45, M1, M2, M3, M4）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-15.7-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "15.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-15.7-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "15.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the service-provider inventory, classification, contract, assurance, and lifecycle authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把服务提供商清单、分类、合同、保证与生命周期权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-15.7-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "15.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle discovered → owned → classified → contracted → configured → evidenced/monitored → incident/exception → renewed or exited.",
          "zh": "对生命周期“发现 → 确认责任 → 分类 → 签约 → 配置 → 取证/监测 → 事件/例外 → 续约或退出”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-15.7-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "15.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 15.1, Safeguard 15.2; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 15.1、Safeguard 15.2 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-15.7-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "15.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-15.7-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "15.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-15.7-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "15.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-15.7-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "15.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile procurement and finance, SSO and egress, CMDB/service catalogs, contracts, architecture and data flows, attestations, tenant configuration, incidents, and offboarding records and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 采购与财务、SSO 与出口流量、CMDB/服务目录、合同、架构与数据流、证明、租户配置、事件和退出记录，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-15.7-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "15.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Require every connector carrying provider identity, supplied capability, data and privilege path, criticality, contract, assurance, tenant control, incident duty, dependency, and exit to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 提供商身份、供应能力、数据与权限路径、关键度、合同、保证、租户控制、事件义务、依赖和退出 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-15.7-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "15.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Plan exit before onboarding, identify successor/export and retention, freeze changes, export/validate data, revoke access and routes, rotate shared secrets, request and verify disposal, update inventories and monitor for residual use.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“上线前就规划退出，确定替代/导出和保留，冻结变化，导出/验数据，撤访问/路由，轮换共享秘密，请求/验证销毁，更新台账并监测残留；业务、技术、数据、法务、安全共同验收。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-15.7-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "15.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-15.7-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "15.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-15.7-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "15.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-15.7-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "15.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the service-provider inventory, classification, contract, assurance, and lifecycle authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在服务提供商清单、分类、合同、保证与生命周期权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-15.7-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "15.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Implement the explicit state machine discovered → owned → classified → contracted → configured → evidenced/monitored → incident/exception → renewed or exited; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“发现 → 确认责任 → 分类 → 签约 → 配置 → 取证/监测 → 事件/例外 → 续约或退出”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-15.7-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "15.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-15.7-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "15.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-15.7-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "15.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-15.7-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "15.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-15.7-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "15.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in service providers, subprocessors, supplied products, integrations, privileged support, data and dependency paths, contracts, evidence, monitoring, and exit; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 服务提供商、分处理方、供应产品、集成、特权支持、数据与依赖路径、合同、证据、监测和退出 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-15.7-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "15.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for discovered → owned → classified → contracted → configured → evidenced/monitored → incident/exception → renewed or exited; alert before each deadline becomes overdue.",
          "zh": "为“发现 → 确认责任 → 分类 → 签约 → 配置 → 取证/监测 → 事件/例外 → 续约或退出”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-15.7-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "15.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “Deletion certificates may exclude backups/subprocessors and need scoped interpretation.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“删除证明可能排除备份/分包，需看范围。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-15.7-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "15.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-15.7-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "15.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-15.7-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "15.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-15.7-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "15.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat shadow vendors, nested subprocessors, click-through terms, provider plan limits, unavailable evidence, acquisitions, shared responsibility, concentration, emergency support, and incomplete deletion as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 影子供应商、嵌套分处理方、点击接受条款、提供商套餐限制、证据不可得、收购、共享责任、集中度、紧急支持和删除不完整 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-15.7-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "15.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Treat shadow providers, subprocessors, acquisitions, click-through terms, plan limitations, shared responsibility, concentration, unavailable evidence, emergency support, and residual data as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 影子提供商、分处理方、收购、点击条款、套餐限制、共享责任、集中度、证据不可得、紧急支持和残余数据 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-15.7-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "15.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Run an exit checklist against a real or test service, then attempt old login, token, API, network route, DNS/email and data retrieval.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“用真实或测试服务走清单，再尝试旧登录、Token、API、路由、DNS/邮件和取数；结案后对账事件/费用，验证导出与删除证据，并在服务商保留窗口后复测。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-15.7-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "15.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-15.7-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "15.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 6 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、6 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-15.7-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "15.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-15.7-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "15.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the service-provider inventory, classification, contract, assurance, and lifecycle authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以服务提供商清单、分类、合同、保证与生命周期权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-15.7-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "15.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Publish known, unknown, critical, unclassified, contract-gap, evidence-current, evidence-stale, tenant-misconfigured, incident, concentrated, and exit-incomplete providers with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已知、未知、关键、未分类、合同缺口、证据当前、证据过期、租户误配、事件、集中和退出不完整提供商，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-15.7-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "15.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-15.7-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "15.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-15.7-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "15.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-15.7-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "15.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-15.7-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "15.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the service-provider inventory, classification, contract, assurance, and lifecycle authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护服务提供商清单、分类、合同、保证与生命周期权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-15.7-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "15.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Restrict authority to change discovered → owned → classified → contracted → configured → evidenced/monitored → incident/exception → renewed or exited; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“发现 → 确认责任 → 分类 → 签约 → 配置 → 取证/监测 → 事件/例外 → 续约或退出”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-15.7-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "15.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-15.7-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "15.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-15.7-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "15.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-15.7-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "15.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-15.7-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "15.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise approved and unknown providers, tenant configuration, evidence expiry, control exception, provider incident, API/export loss, privileged support, contract breach, and clean exit through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 获批与未知提供商、租户配置、证据过期、控制例外、提供商事件、API/导出丢失、特权支持、违约和完整退出，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-15.7-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "15.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Run the positive control an approved provider with tested tenant controls, current evidence, notification path, and exit artifact; exercise negative, stale, duplicate, bypass, and outage controls including a shadow provider, missing clause, stale attestation, misconfigured tenant, unavailable export, subprocessor change, provider incident, and residual data after exit.",
          "zh": "运行正向控制“一家具备已测试租户控制、当前证据、通知路径和退出制品的获批提供商”，并执行包含“影子提供商、条款缺失、证明过期、租户误配、导出不可用、分处理方变化、提供商事件和退出后残余数据”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-15.7-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "15.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-15.7-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "15.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-15.7-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "15.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-15.7-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "15.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-15.7-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "15.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever procurement and finance, SSO and egress, CMDB/service catalogs, contracts, architecture and data flows, attestations, tenant configuration, incidents, and offboarding records change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 采购与财务、SSO 与出口流量、CMDB/服务目录、合同、架构与数据流、证明、租户配置、事件和退出记录 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-15.7-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "15.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Use known, unknown, critical, unclassified, contract-gap, evidence-current, evidence-stale, tenant-misconfigured, incident, concentrated, and exit-incomplete providers to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已知、未知、关键、未分类、合同缺口、证据当前、证据过期、租户误配、事件、集中和退出不完整提供商 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "16.1",
      "control": 16,
      "title_en": "Establish and Maintain a Secure Application Development Process",
      "title_zh": "安全应用开发流程",
      "first_ig": 2,
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Documentation",
      "security_function": "Govern",
      "patterns": [
        "software_dev",
        "governance"
      ],
      "expanded_complexity": true,
      "cas_context": {
        "dependencies": [],
        "variables": [
          "GV49",
          "M1",
          "M2",
          "M3"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [
        "annually"
      ],
      "implementation_contract": {
        "en": {
          "scope": "The process covers software the enterprise designs, builds, configures or materially customizes, including web/mobile/API, services, infrastructure code, data/AI pipelines and low-code workflows.",
          "build": "Define secure design/coding standards, roles, training, threat modeling, component/source trust, secrets, reviews/tests, release gates, exception and response.",
          "proof": "Select representative changes and trace security requirements, design decision, review, tests, artifact provenance, approval and deployed result.",
          "boundary": "A six-topic document can pass CAS while delivery bypasses it."
        },
        "zh": {
          "scope": "覆盖企业设计、开发、配置或深度定制的软件，包括 Web/移动/API、服务、IaC、数据/AI 管道和低代码，从需求、设计、编码、依赖、构建、测试、发布、运行、漏洞接收一直到退役，按后果缩放。",
          "build": "定义安全设计/编码、角色、培训、威胁建模、组件/来源信任、秘密、评审/测试、发布 Gate、例外和响应，把证据嵌入版本库/CI/CD；每年及平台、威胁、产品重大变化时更新，并给团队好用的 Paved Road。",
          "proof": "从代表变更追安全要求、设计决定、评审、测试、制品来源、批准和部署结果；放一个安全的失败检查，验证发布被阻断或走显式风险 Gate，并检查 Hotfix/低代码路径。",
          "boundary": "六主题文档可过 CAS，但交付可能全绕过。"
        }
      },
      "category_counts": {
        "outcome": 8,
        "scope": 8,
        "ownership": 8,
        "data": 8,
        "integration": 8,
        "control": 8,
        "timing": 8,
        "exception": 8,
        "evidence": 8,
        "security": 8,
        "testing": 8,
        "operations": 8
      },
      "requirement_count": 96,
      "requirements": [
        {
          "code": "CIS-16.1-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "16.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Establish and Maintain a Secure Application Development Process; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“安全应用开发流程”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-16.1-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "16.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 16.1, official Asset Class Documentation, Security Function Govern, and IG2 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 16.1、官方资产类别“文档与治理”、安全功能“治理”和首次出现的 IG2，并保存来源抓取日期。"
        },
        {
          "code": "CIS-16.1-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "16.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “The process covers software the enterprise designs, builds, configures or materially customizes, including web/mobile/API, services, infrastructure code, data/AI pipelines and low-code workflows.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“覆盖企业设计、开发、配置或深度定制的软件，包括 Web/移动/API、服务、IaC、数据/AI 管道和低代码，从需求、设计、编码、依赖、构建、测试、发布、运行、漏洞接收一直到退役，按后果缩放。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-16.1-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "16.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-16.1-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "16.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Establish and Maintain a Secure Application Development Process to its operating object—applications, services, APIs, code, dependencies, build and deployment systems, design invariants, vulnerability reports, tests, and production behavior—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“安全应用开发流程”连接到其运营对象——应用、服务、API、代码、依赖、构建与部署系统、设计不变量、漏洞报告、测试和生产行为——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-16.1-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "16.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "For Establish and Maintain a Secure Application Development Process, express success as an observable decision over source-to-production software identity, design invariant, component trust, build provenance, test result, deployment state, runtime outcome, and vulnerability response; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“安全应用开发流程”，以 从源码到生产的软件身份、设计不变量、组件信任、构建来源、测试结果、部署状态、运行结果和漏洞响应 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-16.1-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "16.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "For Establish and Maintain a Secure Application Development Process, express success as an observable decision over a documented decision system with policy, process, procedure, accountable owner, approval, and review; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“安全应用开发流程”，以 包含策略、流程、程序、责任人、审批和复核的文档化决策系统 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-16.1-OUT-08",
          "local_code": "OUT-08",
          "display_code": "O08",
          "safeguard_id": "16.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "For the expanded Establish and Maintain a Secure Application Development Process scope, resolve conflicts among security, safety, privacy, legal, availability, customer, and operational objectives through an explicit risk decision.",
          "zh": "对“安全应用开发流程”的扩展范围，通过显式风险决策解决安全、安全生产、隐私、法律、可用性、客户和运营目标冲突。"
        },
        {
          "code": "CIS-16.1-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "16.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-16.1-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "16.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-16.1-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "16.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-16.1-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "16.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-16.1-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "16.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across generated code, forks, vendoring, transitive and mutable dependencies, build compromise, feature flags, tenant logic, business-logic flaws, secrets, emergency release, and provider components; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 生成代码、分叉、vendoring、传递与可变依赖、构建失陷、功能开关、租户逻辑、业务逻辑缺陷、秘密、紧急发布和提供商组件 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-16.1-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "16.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Include generated and copied code, forks, vendoring, transitive dependencies, mutable tags, build plugins, feature flags, tenant logic, secrets, emergency release, and provider components in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 生成与复制代码、分叉、vendoring、传递依赖、可变标签、构建插件、功能开关、租户逻辑、秘密、紧急发布和提供商组件 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-16.1-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "16.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Include missing policy clauses, conflicting authorities, local deviations, obsolete documentation, and decisions made outside the governed workflow in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 策略条款缺失、权限冲突、本地偏离、文档过期及绕过治理流程的决策 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-16.1-SCP-08",
          "local_code": "SCP-08",
          "display_code": "P08",
          "safeguard_id": "16.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Define nested scope at enterprise, business service, tenant, environment, platform, object, identity, data set, and transaction levels; prohibit a parent result from hiding a failing child.",
          "zh": "按企业、业务服务、租户、环境、平台、对象、身份、数据集和交易定义嵌套范围，禁止父级结果遮蔽失败子级。"
        },
        {
          "code": "CIS-16.1-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "16.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-16.1-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "16.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-16.1-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "16.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-16.1-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "16.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-16.1-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "16.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind product and engineering owners, developers, security champions, application security, platform engineering, vulnerability response, architecture, and operations to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 产品与工程责任人、开发者、安全负责人、应用安全、平台工程、漏洞响应、架构和运营 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-16.1-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "16.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Name who may transition designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-16.1-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "16.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Name who may transition draft → reviewed → approved → effective → exception/withdrawn → superseded, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-16.1-OWN-08",
          "local_code": "OWN-08",
          "display_code": "W08",
          "safeguard_id": "16.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Model delegated authority, quorum or dual approval where warranted, escalation deadlines, provider handoffs, conflict resolution, and executive risk acceptance.",
          "zh": "建模委派权限、必要时的双人或法定人数审批、升级期限、提供商交接、冲突解决和管理层风险接受。"
        },
        {
          "code": "CIS-16.1-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "16.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-16.1-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "16.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-16.1-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "16.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV49, M1, M2, M3) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV49, M1, M2, M3）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-16.1-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "16.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-16.1-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "16.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the secure-development, component, vulnerability, threat-model, build, release, and exception authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把安全开发、组件、漏洞、威胁模型、构建、发布与例外权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-16.1-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "16.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired.",
          "zh": "对生命周期“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-16.1-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "16.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle draft → reviewed → approved → effective → exception/withdrawn → superseded.",
          "zh": "对生命周期“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-16.1-DAT-08",
          "local_code": "DAT-08",
          "display_code": "D08",
          "safeguard_id": "16.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Version schemas and state transitions with migration, backfill, deduplication, lineage, historical denominator, deletion, and rollback semantics.",
          "zh": "对模式和状态转换做版本管理，定义迁移、回填、去重、血缘、历史分母、删除和回滚语义。"
        },
        {
          "code": "CIS-16.1-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "16.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for no explicit predecessor in the pinned CAS page; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 固定 CAS 页面没有列出显式前置项 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-16.1-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "16.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-16.1-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "16.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-16.1-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "16.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-16.1-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "16.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile repositories, issue trackers, CI/CD, artifact registries, SBOMs, dependency sources, architecture models, scanners, tests, reports, deployments, and runtime telemetry and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 代码库、问题系统、CI/CD、制品库、SBOM、依赖来源、架构模型、扫描器、测试、报告、部署和运行遥测，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-16.1-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "16.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Require every connector carrying source-to-production software identity, design invariant, component trust, build provenance, test result, deployment state, runtime outcome, and vulnerability response to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 从源码到生产的软件身份、设计不变量、组件信任、构建来源、测试结果、部署状态、运行结果和漏洞响应 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-16.1-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "16.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Require every connector carrying a documented decision system with policy, process, procedure, accountable owner, approval, and review to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 包含策略、流程、程序、责任人、审批和复核的文档化决策系统 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-16.1-INT-08",
          "local_code": "INT-08",
          "display_code": "I08",
          "safeguard_id": "16.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Define consistency rules across disagreeing sources, source precedence, confidence, reconciliation queues, dead-letter handling, reprocessing, and end-to-end trace identity.",
          "zh": "定义冲突来源的一致性、优先级、置信度、对账队列、死信、重处理和端到端追踪身份。"
        },
        {
          "code": "CIS-16.1-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "16.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Define secure design/coding standards, roles, training, threat modeling, component/source trust, secrets, reviews/tests, release gates, exception and response.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“定义安全设计/编码、角色、培训、威胁建模、组件/来源信任、秘密、评审/测试、发布 Gate、例外和响应，把证据嵌入版本库/CI/CD；每年及平台、威胁、产品重大变化时更新，并给团队好用的 Paved Road。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-16.1-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "16.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-16.1-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "16.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-16.1-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "16.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-16.1-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "16.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the secure-development, component, vulnerability, threat-model, build, release, and exception authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在安全开发、组件、漏洞、威胁模型、构建、发布与例外权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-16.1-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "16.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Implement the explicit state machine designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-16.1-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "16.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Implement the explicit state machine draft → reviewed → approved → effective → exception/withdrawn → superseded; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-16.1-CTL-08",
          "local_code": "CTL-08",
          "display_code": "C08",
          "safeguard_id": "16.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Specify concurrent decisions, partial success, compensating transactions, repeated requests, stale policy, dependency outage, and recovery from an interrupted state transition.",
          "zh": "定义并发决策、部分成功、补偿事务、重复请求、陈旧策略、依赖中断和中途状态转换恢复。"
        },
        {
          "code": "CIS-16.1-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "16.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (annually); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（annually）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-16.1-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "16.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-16.1-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "16.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-16.1-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "16.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-16.1-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "16.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in applications, services, APIs, code, dependencies, build and deployment systems, design invariants, vulnerability reports, tests, and production behavior; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 应用、服务、API、代码、依赖、构建与部署系统、设计不变量、漏洞报告、测试和生产行为 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-16.1-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "16.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; alert before each deadline becomes overdue.",
          "zh": "为“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-16.1-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "16.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for draft → reviewed → approved → effective → exception/withdrawn → superseded; alert before each deadline becomes overdue.",
          "zh": "为“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-16.1-TIM-08",
          "local_code": "TIM-08",
          "display_code": "T08",
          "safeguard_id": "16.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Allocate an end-to-end SLO budget across discovery, collection, processing, approval, enforcement, verification, and closure; prioritize overdue work by consequence and exposure.",
          "zh": "把端到端 SLO 预算分配到发现、采集、处理、审批、执行、验证和关闭，并按后果与暴露排列逾期工作。"
        },
        {
          "code": "CIS-16.1-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "16.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “A six-topic document can pass CAS while delivery bypasses it.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“六主题文档可过 CAS，但交付可能全绕过。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-16.1-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "16.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-16.1-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "16.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-16.1-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "16.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-16.1-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "16.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat generated code, forks, vendoring, transitive and mutable dependencies, build compromise, feature flags, tenant logic, business-logic flaws, secrets, emergency release, and provider components as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 生成代码、分叉、vendoring、传递与可变依赖、构建失陷、功能开关、租户逻辑、业务逻辑缺陷、秘密、紧急发布和提供商组件 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-16.1-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "16.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Treat generated and copied code, forks, vendoring, transitive dependencies, mutable tags, build plugins, feature flags, tenant logic, secrets, emergency release, and provider components as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 生成与复制代码、分叉、vendoring、传递依赖、可变标签、构建插件、功能开关、租户逻辑、秘密、紧急发布和提供商组件 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-16.1-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "16.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Treat missing policy clauses, conflicting authorities, local deviations, obsolete documentation, and decisions made outside the governed workflow as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 策略条款缺失、权限冲突、本地偏离、文档过期及绕过治理流程的决策 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-16.1-EXC-08",
          "local_code": "EXC-08",
          "display_code": "X08",
          "safeguard_id": "16.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Exercise compound failures where an exception, stale source, provider outage, unavailable owner, and degraded control overlap; define one safe command and one accountable decision.",
          "zh": "演练例外、陈旧来源、提供商中断、责任人不可用和控制降级同时出现的复合故障，明确一条安全指令和一个责任决策。"
        },
        {
          "code": "CIS-16.1-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "16.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Select representative changes and trace security requirements, design decision, review, tests, artifact provenance, approval and deployed result.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“从代表变更追安全要求、设计决定、评审、测试、制品来源、批准和部署结果；放一个安全的失败检查，验证发布被阻断或走显式风险 Gate，并检查 Hotfix/低代码路径。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-16.1-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "16.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-16.1-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "16.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 4 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、4 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-16.1-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "16.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-16.1-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "16.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the secure-development, component, vulnerability, threat-model, build, release, and exception authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以安全开发、组件、漏洞、威胁模型、构建、发布与例外权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-16.1-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "16.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Publish reviewed, unreviewed, reproducible, provenance-bound, vulnerable, test-failed, exception, deployed-unverified, drifted, rolled-back, and regression-protected releases with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已评审、未评审、可复现、来源绑定、存在漏洞、测试失败、例外、已部署未验证、漂移、已回滚和受回归保护发布物，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-16.1-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "16.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Publish clause coverage, owner and reviewer completeness, approval age, triggered reviews, deviations, overdue actions, and superseded versions still in use with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 条款覆盖、责任人与复核人完整性、批准年龄、触发式复核、偏离、逾期行动及仍在使用的旧版本，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-16.1-EVD-08",
          "local_code": "EVD-08",
          "display_code": "E08",
          "safeguard_id": "16.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Require an independent party to reconstruct the decision from source receipts and reproduce the population, state transition, calculation, test result, exception, and final closure.",
          "zh": "要求独立人员使用来源回执重建决策，并复现总体、状态转换、计算、测试结果、例外和最终关闭。"
        },
        {
          "code": "CIS-16.1-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "16.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-16.1-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "16.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-16.1-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "16.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-16.1-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "16.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-16.1-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "16.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the secure-development, component, vulnerability, threat-model, build, release, and exception authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护安全开发、组件、漏洞、威胁模型、构建、发布与例外权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-16.1-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "16.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Restrict authority to change designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-16.1-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "16.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Restrict authority to change draft → reviewed → approved → effective → exception/withdrawn → superseded; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-16.1-SEC-08",
          "local_code": "SEC-08",
          "display_code": "S08",
          "safeguard_id": "16.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Threat-model the implementation system itself: forged evidence, poisoned inventory, privilege abuse, cross-tenant confusion, policy rollback, audit deletion, denial of service, and recovery compromise.",
          "zh": "威胁建模实施系统自身：伪造证据、污染清单、权限滥用、跨租户混淆、策略回滚、审计删除、拒绝服务和恢复失陷。"
        },
        {
          "code": "CIS-16.1-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "16.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-16.1-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "16.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-16.1-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "16.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-16.1-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "16.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-16.1-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "16.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise secure and insecure design paths, trusted and substituted components, accepted and rejected reports, code-level controls, authenticated abuse, build provenance, rollback, and regression through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 安全与不安全设计路径、可信与被替换组件、接受与拒绝报告、代码级控制、认证后滥用、构建来源、回滚和回归，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-16.1-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "16.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Run the positive control a trusted build that preserves the security invariant through deployment and runtime; exercise negative, stale, duplicate, bypass, and outage controls including a substituted dependency, unreviewed change, poisoned build input, failed security test, bypass path, vulnerable release, rollback, and regression.",
          "zh": "运行正向控制“一个把安全不变量贯穿部署与运行的可信构建”，并执行包含“依赖替换、未评审变更、构建输入污染、安全测试失败、绕过路径、漏洞发布、回滚和回归”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-16.1-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "16.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Run the positive control an approved current process used for a representative decision; exercise negative, stale, duplicate, bypass, and outage controls including an obsolete version, missing approver, undocumented deviation, overdue review, and bypassed workflow.",
          "zh": "运行正向控制“使用当前获批流程完成一项代表性决策”，并执行包含“旧版本、审批人缺失、未记录偏离、逾期复核和绕过流程”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-16.1-TST-08",
          "local_code": "TST-08",
          "display_code": "V08",
          "safeguard_id": "16.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Build a pairwise platform-and-failure matrix, then add high-consequence multi-factor cases, historical regression, source substitution, red-team challenge, and assessor replay.",
          "zh": "建立平台—故障两两组合矩阵，再加入高后果多因素案例、历史回归、来源替换、红队挑战和评估方重放。"
        },
        {
          "code": "CIS-16.1-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "16.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-16.1-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "16.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-16.1-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "16.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-16.1-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "16.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-16.1-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "16.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever repositories, issue trackers, CI/CD, artifact registries, SBOMs, dependency sources, architecture models, scanners, tests, reports, deployments, and runtime telemetry change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 代码库、问题系统、CI/CD、制品库、SBOM、依赖来源、架构模型、扫描器、测试、报告、部署和运行遥测 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-16.1-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "16.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Use reviewed, unreviewed, reproducible, provenance-bound, vulnerable, test-failed, exception, deployed-unverified, drifted, rolled-back, and regression-protected releases to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已评审、未评审、可复现、来源绑定、存在漏洞、测试失败、例外、已部署未验证、漂移、已回滚和受回归保护发布物 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-16.1-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "16.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Use clause coverage, owner and reviewer completeness, approval age, triggered reviews, deviations, overdue actions, and superseded versions still in use to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 条款覆盖、责任人与复核人完整性、批准年龄、触发式复核、偏离、逾期行动及仍在使用的旧版本 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-16.1-OPS-08",
          "local_code": "OPS-08",
          "display_code": "R08",
          "safeguard_id": "16.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Use canary deployment, kill criteria, rollback, backlog burn-down, exception reduction, source-quality targets, quarterly design review, and a measurable retirement plan.",
          "zh": "采用金丝雀、停止标准、回滚、积压燃尽、例外缩减、来源质量目标、季度设计复核和可量化退役计划。"
        }
      ]
    },
    {
      "id": "16.2",
      "control": 16,
      "title_en": "Establish and Maintain a Process to Accept and Address Software Vulnerabilities",
      "title_zh": "软件漏洞接收与处置",
      "first_ig": 2,
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Documentation",
      "security_function": "Govern",
      "patterns": [
        "software_dev",
        "vulnerability",
        "governance"
      ],
      "expanded_complexity": true,
      "cas_context": {
        "dependencies": [],
        "variables": [
          "GV48",
          "M1",
          "M2",
          "M3"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [
        "annually"
      ],
      "implementation_contract": {
        "en": {
          "scope": "Scope external and internal reports for every supported product/component, with a public or discoverable reporting channel, safe-harbor expectations where appropriate, product/version ownership and coordinated handling.",
          "build": "Publish contact or security.txt, acknowledge securely, protect reporter/data, deduplicate and track intake, validation, severity, owner, remediation, test, advisory and disclosure timelines.",
          "proof": "Submit a benign test report from outside and inside, verify acknowledgement, confidential exchange, triage, ownership, fix test and closure timing.",
          "boundary": "A mailbox that nobody monitors is not a process."
        },
        "zh": {
          "scope": "覆盖所有受支持产品/组件的内外部漏洞报告，提供公开或可发现的入口、适当 Safe Harbor、产品/版本责任和协调处置。",
          "build": "发布联系或 security.txt，安全确认和交换，保护报告者/数据，去重并跟踪接收、验证、严重度、责任、修复、测试、公告和披露；有备用联系人/垃圾处理/指标，每年及变化时更新。",
          "proof": "从外部和内部提交无害测试报告，验证确认、保密通信、分诊、认领、修复测试和时延；测试重复、无效、Embargo、高危和主响应人失联，检查老化/无主案件。",
          "boundary": "无人看邮箱不是流程。"
        }
      },
      "category_counts": {
        "outcome": 9,
        "scope": 9,
        "ownership": 9,
        "data": 9,
        "integration": 9,
        "control": 9,
        "timing": 9,
        "exception": 9,
        "evidence": 9,
        "security": 9,
        "testing": 9,
        "operations": 9
      },
      "requirement_count": 108,
      "requirements": [
        {
          "code": "CIS-16.2-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "16.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Establish and Maintain a Process to Accept and Address Software Vulnerabilities; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“软件漏洞接收与处置”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-16.2-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "16.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 16.2, official Asset Class Documentation, Security Function Govern, and IG2 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 16.2、官方资产类别“文档与治理”、安全功能“治理”和首次出现的 IG2，并保存来源抓取日期。"
        },
        {
          "code": "CIS-16.2-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "16.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Scope external and internal reports for every supported product/component, with a public or discoverable reporting channel, safe-harbor expectations where appropriate, product/version ownership and coordinated handling.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“覆盖所有受支持产品/组件的内外部漏洞报告，提供公开或可发现的入口、适当 Safe Harbor、产品/版本责任和协调处置。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-16.2-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "16.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-16.2-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "16.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Establish and Maintain a Process to Accept and Address Software Vulnerabilities to its operating object—applications, services, APIs, code, dependencies, build and deployment systems, design invariants, vulnerability reports, tests, and production behavior—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“软件漏洞接收与处置”连接到其运营对象——应用、服务、API、代码、依赖、构建与部署系统、设计不变量、漏洞报告、测试和生产行为——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-16.2-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "16.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "For Establish and Maintain a Process to Accept and Address Software Vulnerabilities, express success as an observable decision over source-to-production software identity, design invariant, component trust, build provenance, test result, deployment state, runtime outcome, and vulnerability response; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“软件漏洞接收与处置”，以 从源码到生产的软件身份、设计不变量、组件信任、构建来源、测试结果、部署状态、运行结果和漏洞响应 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-16.2-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "16.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "For Establish and Maintain a Process to Accept and Address Software Vulnerabilities, express success as an observable decision over affected artifact identity, exploitability, business consequence, remediation choice, deployed fix, compensating control, and residual exposure; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“软件漏洞接收与处置”，以 受影响制品身份、可利用性、业务后果、修复选择、已部署修复、补偿控制和残余暴露 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-16.2-OUT-08",
          "local_code": "OUT-08",
          "display_code": "O08",
          "safeguard_id": "16.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "For Establish and Maintain a Process to Accept and Address Software Vulnerabilities, express success as an observable decision over a documented decision system with policy, process, procedure, accountable owner, approval, and review; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“软件漏洞接收与处置”，以 包含策略、流程、程序、责任人、审批和复核的文档化决策系统 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-16.2-OUT-09",
          "local_code": "OUT-09",
          "display_code": "O09",
          "safeguard_id": "16.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "For the expanded Establish and Maintain a Process to Accept and Address Software Vulnerabilities scope, resolve conflicts among security, safety, privacy, legal, availability, customer, and operational objectives through an explicit risk decision.",
          "zh": "对“软件漏洞接收与处置”的扩展范围，通过显式风险决策解决安全、安全生产、隐私、法律、可用性、客户和运营目标冲突。"
        },
        {
          "code": "CIS-16.2-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "16.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-16.2-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "16.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-16.2-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "16.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-16.2-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "16.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-16.2-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "16.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across generated code, forks, vendoring, transitive and mutable dependencies, build compromise, feature flags, tenant logic, business-logic flaws, secrets, emergency release, and provider components; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 生成代码、分叉、vendoring、传递与可变依赖、构建失陷、功能开关、租户逻辑、业务逻辑缺陷、秘密、紧急发布和提供商组件 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-16.2-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "16.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Include generated and copied code, forks, vendoring, transitive dependencies, mutable tags, build plugins, feature flags, tenant logic, secrets, emergency release, and provider components in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 生成与复制代码、分叉、vendoring、传递依赖、可变标签、构建插件、功能开关、租户逻辑、秘密、紧急发布和提供商组件 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-16.2-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "16.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Include unknown versions, false positives, unavailable fixes, vendor lag, ephemeral workloads, unscannable platforms, inherited dependencies, mitigation-only states, and recurrence in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 未知版本、误报、无可用修复、厂商滞后、短生工作负载、不可扫描平台、继承依赖、仅缓解状态和复发 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-16.2-SCP-08",
          "local_code": "SCP-08",
          "display_code": "P08",
          "safeguard_id": "16.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Include missing policy clauses, conflicting authorities, local deviations, obsolete documentation, and decisions made outside the governed workflow in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 策略条款缺失、权限冲突、本地偏离、文档过期及绕过治理流程的决策 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-16.2-SCP-09",
          "local_code": "SCP-09",
          "display_code": "P09",
          "safeguard_id": "16.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Define nested scope at enterprise, business service, tenant, environment, platform, object, identity, data set, and transaction levels; prohibit a parent result from hiding a failing child.",
          "zh": "按企业、业务服务、租户、环境、平台、对象、身份、数据集和交易定义嵌套范围，禁止父级结果遮蔽失败子级。"
        },
        {
          "code": "CIS-16.2-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "16.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-16.2-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "16.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-16.2-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "16.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-16.2-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "16.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-16.2-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "16.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind product and engineering owners, developers, security champions, application security, platform engineering, vulnerability response, architecture, and operations to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 产品与工程责任人、开发者、安全负责人、应用安全、平台工程、漏洞响应、架构和运营 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-16.2-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "16.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Name who may transition designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-16.2-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "16.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Name who may transition discovered → validated → prioritized → assigned → fixed/mitigated/excepted → deployed → retested → closed/reopened, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 发现 → 验证 → 定级 → 分派 → 修复/缓解/例外 → 部署 → 复测 → 关闭/重开，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-16.2-OWN-08",
          "local_code": "OWN-08",
          "display_code": "W08",
          "safeguard_id": "16.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Name who may transition draft → reviewed → approved → effective → exception/withdrawn → superseded, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-16.2-OWN-09",
          "local_code": "OWN-09",
          "display_code": "W09",
          "safeguard_id": "16.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Model delegated authority, quorum or dual approval where warranted, escalation deadlines, provider handoffs, conflict resolution, and executive risk acceptance.",
          "zh": "建模委派权限、必要时的双人或法定人数审批、升级期限、提供商交接、冲突解决和管理层风险接受。"
        },
        {
          "code": "CIS-16.2-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "16.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-16.2-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "16.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-16.2-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "16.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV48, M1, M2, M3) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV48, M1, M2, M3）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-16.2-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "16.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-16.2-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "16.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the secure-development, component, vulnerability, threat-model, build, release, and exception authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把安全开发、组件、漏洞、威胁模型、构建、发布与例外权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-16.2-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "16.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired.",
          "zh": "对生命周期“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-16.2-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "16.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle discovered → validated → prioritized → assigned → fixed/mitigated/excepted → deployed → retested → closed/reopened.",
          "zh": "对生命周期“发现 → 验证 → 定级 → 分派 → 修复/缓解/例外 → 部署 → 复测 → 关闭/重开”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-16.2-DAT-08",
          "local_code": "DAT-08",
          "display_code": "D08",
          "safeguard_id": "16.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle draft → reviewed → approved → effective → exception/withdrawn → superseded.",
          "zh": "对生命周期“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-16.2-DAT-09",
          "local_code": "DAT-09",
          "display_code": "D09",
          "safeguard_id": "16.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Version schemas and state transitions with migration, backfill, deduplication, lineage, historical denominator, deletion, and rollback semantics.",
          "zh": "对模式和状态转换做版本管理，定义迁移、回填、去重、血缘、历史分母、删除和回滚语义。"
        },
        {
          "code": "CIS-16.2-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "16.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for no explicit predecessor in the pinned CAS page; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 固定 CAS 页面没有列出显式前置项 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-16.2-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "16.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-16.2-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "16.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-16.2-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "16.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-16.2-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "16.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile repositories, issue trackers, CI/CD, artifact registries, SBOMs, dependency sources, architecture models, scanners, tests, reports, deployments, and runtime telemetry and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 代码库、问题系统、CI/CD、制品库、SBOM、依赖来源、架构模型、扫描器、测试、报告、部署和运行遥测，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-16.2-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "16.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Require every connector carrying source-to-production software identity, design invariant, component trust, build provenance, test result, deployment state, runtime outcome, and vulnerability response to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 从源码到生产的软件身份、设计不变量、组件信任、构建来源、测试结果、部署状态、运行结果和漏洞响应 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-16.2-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "16.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Require every connector carrying affected artifact identity, exploitability, business consequence, remediation choice, deployed fix, compensating control, and residual exposure to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 受影响制品身份、可利用性、业务后果、修复选择、已部署修复、补偿控制和残余暴露 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-16.2-INT-08",
          "local_code": "INT-08",
          "display_code": "I08",
          "safeguard_id": "16.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Require every connector carrying a documented decision system with policy, process, procedure, accountable owner, approval, and review to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 包含策略、流程、程序、责任人、审批和复核的文档化决策系统 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-16.2-INT-09",
          "local_code": "INT-09",
          "display_code": "I09",
          "safeguard_id": "16.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Define consistency rules across disagreeing sources, source precedence, confidence, reconciliation queues, dead-letter handling, reprocessing, and end-to-end trace identity.",
          "zh": "定义冲突来源的一致性、优先级、置信度、对账队列、死信、重处理和端到端追踪身份。"
        },
        {
          "code": "CIS-16.2-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "16.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Publish contact or security.txt, acknowledge securely, protect reporter/data, deduplicate and track intake, validation, severity, owner, remediation, test, advisory and disclosure timelines.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“发布联系或 security.txt，安全确认和交换，保护报告者/数据，去重并跟踪接收、验证、严重度、责任、修复、测试、公告和披露；有备用联系人/垃圾处理/指标，每年及变化时更新。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-16.2-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "16.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-16.2-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "16.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-16.2-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "16.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-16.2-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "16.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the secure-development, component, vulnerability, threat-model, build, release, and exception authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在安全开发、组件、漏洞、威胁模型、构建、发布与例外权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-16.2-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "16.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Implement the explicit state machine designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-16.2-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "16.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Implement the explicit state machine discovered → validated → prioritized → assigned → fixed/mitigated/excepted → deployed → retested → closed/reopened; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“发现 → 验证 → 定级 → 分派 → 修复/缓解/例外 → 部署 → 复测 → 关闭/重开”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-16.2-CTL-08",
          "local_code": "CTL-08",
          "display_code": "C08",
          "safeguard_id": "16.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Implement the explicit state machine draft → reviewed → approved → effective → exception/withdrawn → superseded; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-16.2-CTL-09",
          "local_code": "CTL-09",
          "display_code": "C09",
          "safeguard_id": "16.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Specify concurrent decisions, partial success, compensating transactions, repeated requests, stale policy, dependency outage, and recovery from an interrupted state transition.",
          "zh": "定义并发决策、部分成功、补偿事务、重复请求、陈旧策略、依赖中断和中途状态转换恢复。"
        },
        {
          "code": "CIS-16.2-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "16.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (annually); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（annually）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-16.2-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "16.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-16.2-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "16.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-16.2-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "16.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-16.2-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "16.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in applications, services, APIs, code, dependencies, build and deployment systems, design invariants, vulnerability reports, tests, and production behavior; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 应用、服务、API、代码、依赖、构建与部署系统、设计不变量、漏洞报告、测试和生产行为 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-16.2-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "16.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; alert before each deadline becomes overdue.",
          "zh": "为“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-16.2-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "16.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for discovered → validated → prioritized → assigned → fixed/mitigated/excepted → deployed → retested → closed/reopened; alert before each deadline becomes overdue.",
          "zh": "为“发现 → 验证 → 定级 → 分派 → 修复/缓解/例外 → 部署 → 复测 → 关闭/重开”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-16.2-TIM-08",
          "local_code": "TIM-08",
          "display_code": "T08",
          "safeguard_id": "16.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for draft → reviewed → approved → effective → exception/withdrawn → superseded; alert before each deadline becomes overdue.",
          "zh": "为“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-16.2-TIM-09",
          "local_code": "TIM-09",
          "display_code": "T09",
          "safeguard_id": "16.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Allocate an end-to-end SLO budget across discovery, collection, processing, approval, enforcement, verification, and closure; prioritize overdue work by consequence and exposure.",
          "zh": "把端到端 SLO 预算分配到发现、采集、处理、审批、执行、验证和关闭，并按后果与暴露排列逾期工作。"
        },
        {
          "code": "CIS-16.2-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "16.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “A mailbox that nobody monitors is not a process.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“无人看邮箱不是流程。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-16.2-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "16.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-16.2-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "16.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-16.2-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "16.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-16.2-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "16.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat generated code, forks, vendoring, transitive and mutable dependencies, build compromise, feature flags, tenant logic, business-logic flaws, secrets, emergency release, and provider components as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 生成代码、分叉、vendoring、传递与可变依赖、构建失陷、功能开关、租户逻辑、业务逻辑缺陷、秘密、紧急发布和提供商组件 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-16.2-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "16.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Treat generated and copied code, forks, vendoring, transitive dependencies, mutable tags, build plugins, feature flags, tenant logic, secrets, emergency release, and provider components as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 生成与复制代码、分叉、vendoring、传递依赖、可变标签、构建插件、功能开关、租户逻辑、秘密、紧急发布和提供商组件 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-16.2-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "16.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Treat unknown versions, false positives, unavailable fixes, vendor lag, ephemeral workloads, unscannable platforms, inherited dependencies, mitigation-only states, and recurrence as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 未知版本、误报、无可用修复、厂商滞后、短生工作负载、不可扫描平台、继承依赖、仅缓解状态和复发 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-16.2-EXC-08",
          "local_code": "EXC-08",
          "display_code": "X08",
          "safeguard_id": "16.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Treat missing policy clauses, conflicting authorities, local deviations, obsolete documentation, and decisions made outside the governed workflow as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 策略条款缺失、权限冲突、本地偏离、文档过期及绕过治理流程的决策 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-16.2-EXC-09",
          "local_code": "EXC-09",
          "display_code": "X09",
          "safeguard_id": "16.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Exercise compound failures where an exception, stale source, provider outage, unavailable owner, and degraded control overlap; define one safe command and one accountable decision.",
          "zh": "演练例外、陈旧来源、提供商中断、责任人不可用和控制降级同时出现的复合故障，明确一条安全指令和一个责任决策。"
        },
        {
          "code": "CIS-16.2-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "16.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Submit a benign test report from outside and inside, verify acknowledgement, confidential exchange, triage, ownership, fix test and closure timing.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“从外部和内部提交无害测试报告，验证确认、保密通信、分诊、认领、修复测试和时延；测试重复、无效、Embargo、高危和主响应人失联，检查老化/无主案件。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-16.2-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "16.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-16.2-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "16.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 4 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、4 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-16.2-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "16.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-16.2-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "16.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the secure-development, component, vulnerability, threat-model, build, release, and exception authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以安全开发、组件、漏洞、威胁模型、构建、发布与例外权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-16.2-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "16.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Publish reviewed, unreviewed, reproducible, provenance-bound, vulnerable, test-failed, exception, deployed-unverified, drifted, rolled-back, and regression-protected releases with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已评审、未评审、可复现、来源绑定、存在漏洞、测试失败、例外、已部署未验证、漂移、已回滚和受回归保护发布物，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-16.2-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "16.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Publish open, validated, false-positive, overdue, mitigated, excepted, deployed-unverified, retest-failed, reopened, and exposure-weighted findings with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 开放、已验证、误报、逾期、已缓解、例外、已部署未验证、复测失败、重开和暴露加权发现，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-16.2-EVD-08",
          "local_code": "EVD-08",
          "display_code": "E08",
          "safeguard_id": "16.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Publish clause coverage, owner and reviewer completeness, approval age, triggered reviews, deviations, overdue actions, and superseded versions still in use with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 条款覆盖、责任人与复核人完整性、批准年龄、触发式复核、偏离、逾期行动及仍在使用的旧版本，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-16.2-EVD-09",
          "local_code": "EVD-09",
          "display_code": "E09",
          "safeguard_id": "16.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Require an independent party to reconstruct the decision from source receipts and reproduce the population, state transition, calculation, test result, exception, and final closure.",
          "zh": "要求独立人员使用来源回执重建决策，并复现总体、状态转换、计算、测试结果、例外和最终关闭。"
        },
        {
          "code": "CIS-16.2-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "16.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-16.2-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "16.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-16.2-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "16.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-16.2-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "16.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-16.2-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "16.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the secure-development, component, vulnerability, threat-model, build, release, and exception authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护安全开发、组件、漏洞、威胁模型、构建、发布与例外权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-16.2-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "16.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Restrict authority to change designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-16.2-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "16.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Restrict authority to change discovered → validated → prioritized → assigned → fixed/mitigated/excepted → deployed → retested → closed/reopened; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“发现 → 验证 → 定级 → 分派 → 修复/缓解/例外 → 部署 → 复测 → 关闭/重开”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-16.2-SEC-08",
          "local_code": "SEC-08",
          "display_code": "S08",
          "safeguard_id": "16.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Restrict authority to change draft → reviewed → approved → effective → exception/withdrawn → superseded; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-16.2-SEC-09",
          "local_code": "SEC-09",
          "display_code": "S09",
          "safeguard_id": "16.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Threat-model the implementation system itself: forged evidence, poisoned inventory, privilege abuse, cross-tenant confusion, policy rollback, audit deletion, denial of service, and recovery compromise.",
          "zh": "威胁建模实施系统自身：伪造证据、污染清单、权限滥用、跨租户混淆、策略回滚、审计删除、拒绝服务和恢复失陷。"
        },
        {
          "code": "CIS-16.2-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "16.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-16.2-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "16.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-16.2-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "16.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-16.2-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "16.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-16.2-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "16.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise secure and insecure design paths, trusted and substituted components, accepted and rejected reports, code-level controls, authenticated abuse, build provenance, rollback, and regression through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 安全与不安全设计路径、可信与被替换组件、接受与拒绝报告、代码级控制、认证后滥用、构建来源、回滚和回归，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-16.2-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "16.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Run the positive control a trusted build that preserves the security invariant through deployment and runtime; exercise negative, stale, duplicate, bypass, and outage controls including a substituted dependency, unreviewed change, poisoned build input, failed security test, bypass path, vulnerable release, rollback, and regression.",
          "zh": "运行正向控制“一个把安全不变量贯穿部署与运行的可信构建”，并执行包含“依赖替换、未评审变更、构建输入污染、安全测试失败、绕过路径、漏洞发布、回滚和回归”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-16.2-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "16.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Run the positive control a known vulnerable artifact repaired and independently retested; exercise negative, stale, duplicate, bypass, and outage controls including credential failure, wrong version match, unavailable fix, mitigation bypass, failed deployment, rollback, recurring finding, and exposed unowned asset.",
          "zh": "运行正向控制“一项已知漏洞制品完成修复并独立复测”，并执行包含“凭据失败、版本误配、无可用修复、缓解绕过、部署失败、回滚、问题复发和外露无主资产”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-16.2-TST-08",
          "local_code": "TST-08",
          "display_code": "V08",
          "safeguard_id": "16.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Run the positive control an approved current process used for a representative decision; exercise negative, stale, duplicate, bypass, and outage controls including an obsolete version, missing approver, undocumented deviation, overdue review, and bypassed workflow.",
          "zh": "运行正向控制“使用当前获批流程完成一项代表性决策”，并执行包含“旧版本、审批人缺失、未记录偏离、逾期复核和绕过流程”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-16.2-TST-09",
          "local_code": "TST-09",
          "display_code": "V09",
          "safeguard_id": "16.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Build a pairwise platform-and-failure matrix, then add high-consequence multi-factor cases, historical regression, source substitution, red-team challenge, and assessor replay.",
          "zh": "建立平台—故障两两组合矩阵，再加入高后果多因素案例、历史回归、来源替换、红队挑战和评估方重放。"
        },
        {
          "code": "CIS-16.2-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "16.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-16.2-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "16.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-16.2-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "16.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-16.2-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "16.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-16.2-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "16.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever repositories, issue trackers, CI/CD, artifact registries, SBOMs, dependency sources, architecture models, scanners, tests, reports, deployments, and runtime telemetry change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 代码库、问题系统、CI/CD、制品库、SBOM、依赖来源、架构模型、扫描器、测试、报告、部署和运行遥测 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-16.2-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "16.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Use reviewed, unreviewed, reproducible, provenance-bound, vulnerable, test-failed, exception, deployed-unverified, drifted, rolled-back, and regression-protected releases to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已评审、未评审、可复现、来源绑定、存在漏洞、测试失败、例外、已部署未验证、漂移、已回滚和受回归保护发布物 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-16.2-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "16.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Use open, validated, false-positive, overdue, mitigated, excepted, deployed-unverified, retest-failed, reopened, and exposure-weighted findings to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 开放、已验证、误报、逾期、已缓解、例外、已部署未验证、复测失败、重开和暴露加权发现 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-16.2-OPS-08",
          "local_code": "OPS-08",
          "display_code": "R08",
          "safeguard_id": "16.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Use clause coverage, owner and reviewer completeness, approval age, triggered reviews, deviations, overdue actions, and superseded versions still in use to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 条款覆盖、责任人与复核人完整性、批准年龄、触发式复核、偏离、逾期行动及仍在使用的旧版本 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-16.2-OPS-09",
          "local_code": "OPS-09",
          "display_code": "R09",
          "safeguard_id": "16.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Use canary deployment, kill criteria, rollback, backlog burn-down, exception reduction, source-quality targets, quarterly design review, and a measurable retirement plan.",
          "zh": "采用金丝雀、停止标准、回滚、积压燃尽、例外缩减、来源质量目标、季度设计复核和可量化退役计划。"
        }
      ]
    },
    {
      "id": "16.3",
      "control": 16,
      "title_en": "Perform Root Cause Analysis on Security Vulnerabilities",
      "title_zh": "漏洞根因分析",
      "first_ig": 2,
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Software",
      "security_function": "Detect",
      "patterns": [
        "software_dev",
        "vulnerability"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "16.2"
        ],
        "variables": [
          "M1",
          "M2",
          "M3",
          "M4",
          "M5"
        ],
        "metric_branches": 2,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "The population should include security vulnerabilities whose consequence, recurrence or systemic pattern warrants analysis, with a declared threshold; doing a shallow RCA on every low-value scanner finding can crowd out learning.",
          "build": "Use a blameless method to distinguish introduction, escape and impact-enabling causes, classify patterns, assign systemic actions and feed standards, training, templates, tests and architecture.",
          "proof": "Sample addressed vulnerabilities and trace RCA evidence to code/history and follow-up controls.",
          "boundary": "“Developer mistake” is not a root cause."
        },
        "zh": {
          "scope": "对后果高、重复或呈系统模式的安全漏洞做根因分析，并声明阈值；所有低价值扫描项都做浅 RCA 会挤掉学习。",
          "build": "无责地区分引入原因、逃逸原因和放大影响原因，分类模式，分配系统行动，反馈标准、培训、模板、测试和架构；行动有责任/日期并验证能跨产品降低同类。",
          "proof": "抽样已处理漏洞，把 RCA 证据追到代码/历史与后续控制；用相关历史/注入案例验证新 Guard 能抓复发。",
          "boundary": "“开发者失误”不是根因。"
        }
      },
      "category_counts": {
        "outcome": 7,
        "scope": 7,
        "ownership": 7,
        "data": 7,
        "integration": 7,
        "control": 7,
        "timing": 7,
        "exception": 7,
        "evidence": 7,
        "security": 7,
        "testing": 7,
        "operations": 7
      },
      "requirement_count": 84,
      "requirements": [
        {
          "code": "CIS-16.3-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "16.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Perform Root Cause Analysis on Security Vulnerabilities; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“漏洞根因分析”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-16.3-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "16.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 16.3, official Asset Class Software, Security Function Detect, and IG2 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 16.3、官方资产类别“软件”、安全功能“检测”和首次出现的 IG2，并保存来源抓取日期。"
        },
        {
          "code": "CIS-16.3-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "16.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “The population should include security vulnerabilities whose consequence, recurrence or systemic pattern warrants analysis, with a declared threshold; doing a shallow RCA on every low-value scanner finding can crowd out learning.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“对后果高、重复或呈系统模式的安全漏洞做根因分析，并声明阈值；所有低价值扫描项都做浅 RCA 会挤掉学习。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-16.3-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "16.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-16.3-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "16.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Perform Root Cause Analysis on Security Vulnerabilities to its operating object—applications, services, APIs, code, dependencies, build and deployment systems, design invariants, vulnerability reports, tests, and production behavior—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“漏洞根因分析”连接到其运营对象——应用、服务、API、代码、依赖、构建与部署系统、设计不变量、漏洞报告、测试和生产行为——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-16.3-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "16.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "For Perform Root Cause Analysis on Security Vulnerabilities, express success as an observable decision over source-to-production software identity, design invariant, component trust, build provenance, test result, deployment state, runtime outcome, and vulnerability response; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“漏洞根因分析”，以 从源码到生产的软件身份、设计不变量、组件信任、构建来源、测试结果、部署状态、运行结果和漏洞响应 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-16.3-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "16.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "For Perform Root Cause Analysis on Security Vulnerabilities, express success as an observable decision over affected artifact identity, exploitability, business consequence, remediation choice, deployed fix, compensating control, and residual exposure; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“漏洞根因分析”，以 受影响制品身份、可利用性、业务后果、修复选择、已部署修复、补偿控制和残余暴露 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-16.3-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "16.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-16.3-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "16.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-16.3-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "16.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-16.3-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "16.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-16.3-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "16.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across generated code, forks, vendoring, transitive and mutable dependencies, build compromise, feature flags, tenant logic, business-logic flaws, secrets, emergency release, and provider components; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 生成代码、分叉、vendoring、传递与可变依赖、构建失陷、功能开关、租户逻辑、业务逻辑缺陷、秘密、紧急发布和提供商组件 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-16.3-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "16.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Include generated and copied code, forks, vendoring, transitive dependencies, mutable tags, build plugins, feature flags, tenant logic, secrets, emergency release, and provider components in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 生成与复制代码、分叉、vendoring、传递依赖、可变标签、构建插件、功能开关、租户逻辑、秘密、紧急发布和提供商组件 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-16.3-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "16.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Include unknown versions, false positives, unavailable fixes, vendor lag, ephemeral workloads, unscannable platforms, inherited dependencies, mitigation-only states, and recurrence in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 未知版本、误报、无可用修复、厂商滞后、短生工作负载、不可扫描平台、继承依赖、仅缓解状态和复发 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-16.3-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "16.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-16.3-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "16.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-16.3-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "16.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-16.3-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "16.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-16.3-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "16.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind product and engineering owners, developers, security champions, application security, platform engineering, vulnerability response, architecture, and operations to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 产品与工程责任人、开发者、安全负责人、应用安全、平台工程、漏洞响应、架构和运营 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-16.3-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "16.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Name who may transition designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-16.3-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "16.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Name who may transition discovered → validated → prioritized → assigned → fixed/mitigated/excepted → deployed → retested → closed/reopened, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 发现 → 验证 → 定级 → 分派 → 修复/缓解/例外 → 部署 → 复测 → 关闭/重开，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-16.3-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "16.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-16.3-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "16.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-16.3-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "16.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (M1, M2, M3, M4, M5) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（M1, M2, M3, M4, M5）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-16.3-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "16.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-16.3-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "16.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the secure-development, component, vulnerability, threat-model, build, release, and exception authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把安全开发、组件、漏洞、威胁模型、构建、发布与例外权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-16.3-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "16.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired.",
          "zh": "对生命周期“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-16.3-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "16.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle discovered → validated → prioritized → assigned → fixed/mitigated/excepted → deployed → retested → closed/reopened.",
          "zh": "对生命周期“发现 → 验证 → 定级 → 分派 → 修复/缓解/例外 → 部署 → 复测 → 关闭/重开”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-16.3-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "16.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 16.2; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 16.2 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-16.3-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "16.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-16.3-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "16.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-16.3-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "16.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-16.3-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "16.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile repositories, issue trackers, CI/CD, artifact registries, SBOMs, dependency sources, architecture models, scanners, tests, reports, deployments, and runtime telemetry and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 代码库、问题系统、CI/CD、制品库、SBOM、依赖来源、架构模型、扫描器、测试、报告、部署和运行遥测，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-16.3-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "16.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Require every connector carrying source-to-production software identity, design invariant, component trust, build provenance, test result, deployment state, runtime outcome, and vulnerability response to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 从源码到生产的软件身份、设计不变量、组件信任、构建来源、测试结果、部署状态、运行结果和漏洞响应 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-16.3-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "16.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Require every connector carrying affected artifact identity, exploitability, business consequence, remediation choice, deployed fix, compensating control, and residual exposure to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 受影响制品身份、可利用性、业务后果、修复选择、已部署修复、补偿控制和残余暴露 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-16.3-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "16.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Use a blameless method to distinguish introduction, escape and impact-enabling causes, classify patterns, assign systemic actions and feed standards, training, templates, tests and architecture.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“无责地区分引入原因、逃逸原因和放大影响原因，分类模式，分配系统行动，反馈标准、培训、模板、测试和架构；行动有责任/日期并验证能跨产品降低同类。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-16.3-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "16.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-16.3-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "16.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-16.3-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "16.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-16.3-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "16.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the secure-development, component, vulnerability, threat-model, build, release, and exception authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在安全开发、组件、漏洞、威胁模型、构建、发布与例外权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-16.3-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "16.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Implement the explicit state machine designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-16.3-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "16.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Implement the explicit state machine discovered → validated → prioritized → assigned → fixed/mitigated/excepted → deployed → retested → closed/reopened; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“发现 → 验证 → 定级 → 分派 → 修复/缓解/例外 → 部署 → 复测 → 关闭/重开”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-16.3-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "16.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-16.3-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "16.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-16.3-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "16.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-16.3-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "16.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-16.3-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "16.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in applications, services, APIs, code, dependencies, build and deployment systems, design invariants, vulnerability reports, tests, and production behavior; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 应用、服务、API、代码、依赖、构建与部署系统、设计不变量、漏洞报告、测试和生产行为 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-16.3-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "16.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; alert before each deadline becomes overdue.",
          "zh": "为“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-16.3-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "16.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for discovered → validated → prioritized → assigned → fixed/mitigated/excepted → deployed → retested → closed/reopened; alert before each deadline becomes overdue.",
          "zh": "为“发现 → 验证 → 定级 → 分派 → 修复/缓解/例外 → 部署 → 复测 → 关闭/重开”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-16.3-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "16.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: ““Developer mistake” is not a root cause.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：““开发者失误”不是根因。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-16.3-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "16.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-16.3-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "16.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-16.3-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "16.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-16.3-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "16.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat generated code, forks, vendoring, transitive and mutable dependencies, build compromise, feature flags, tenant logic, business-logic flaws, secrets, emergency release, and provider components as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 生成代码、分叉、vendoring、传递与可变依赖、构建失陷、功能开关、租户逻辑、业务逻辑缺陷、秘密、紧急发布和提供商组件 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-16.3-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "16.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Treat generated and copied code, forks, vendoring, transitive dependencies, mutable tags, build plugins, feature flags, tenant logic, secrets, emergency release, and provider components as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 生成与复制代码、分叉、vendoring、传递依赖、可变标签、构建插件、功能开关、租户逻辑、秘密、紧急发布和提供商组件 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-16.3-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "16.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Treat unknown versions, false positives, unavailable fixes, vendor lag, ephemeral workloads, unscannable platforms, inherited dependencies, mitigation-only states, and recurrence as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 未知版本、误报、无可用修复、厂商滞后、短生工作负载、不可扫描平台、继承依赖、仅缓解状态和复发 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-16.3-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "16.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Sample addressed vulnerabilities and trace RCA evidence to code/history and follow-up controls.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“抽样已处理漏洞，把 RCA 证据追到代码/历史与后续控制；用相关历史/注入案例验证新 Guard 能抓复发。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-16.3-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "16.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-16.3-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "16.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 2 pinned CAS metric branch(es), 5 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 2 个指标分支、5 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-16.3-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "16.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-16.3-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "16.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the secure-development, component, vulnerability, threat-model, build, release, and exception authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以安全开发、组件、漏洞、威胁模型、构建、发布与例外权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-16.3-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "16.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Publish reviewed, unreviewed, reproducible, provenance-bound, vulnerable, test-failed, exception, deployed-unverified, drifted, rolled-back, and regression-protected releases with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已评审、未评审、可复现、来源绑定、存在漏洞、测试失败、例外、已部署未验证、漂移、已回滚和受回归保护发布物，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-16.3-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "16.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Publish open, validated, false-positive, overdue, mitigated, excepted, deployed-unverified, retest-failed, reopened, and exposure-weighted findings with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 开放、已验证、误报、逾期、已缓解、例外、已部署未验证、复测失败、重开和暴露加权发现，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-16.3-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "16.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-16.3-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "16.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-16.3-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "16.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-16.3-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "16.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-16.3-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "16.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the secure-development, component, vulnerability, threat-model, build, release, and exception authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护安全开发、组件、漏洞、威胁模型、构建、发布与例外权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-16.3-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "16.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Restrict authority to change designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-16.3-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "16.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Restrict authority to change discovered → validated → prioritized → assigned → fixed/mitigated/excepted → deployed → retested → closed/reopened; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“发现 → 验证 → 定级 → 分派 → 修复/缓解/例外 → 部署 → 复测 → 关闭/重开”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-16.3-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "16.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-16.3-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "16.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-16.3-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "16.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-16.3-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "16.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-16.3-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "16.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise secure and insecure design paths, trusted and substituted components, accepted and rejected reports, code-level controls, authenticated abuse, build provenance, rollback, and regression through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 安全与不安全设计路径、可信与被替换组件、接受与拒绝报告、代码级控制、认证后滥用、构建来源、回滚和回归，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-16.3-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "16.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Run the positive control a trusted build that preserves the security invariant through deployment and runtime; exercise negative, stale, duplicate, bypass, and outage controls including a substituted dependency, unreviewed change, poisoned build input, failed security test, bypass path, vulnerable release, rollback, and regression.",
          "zh": "运行正向控制“一个把安全不变量贯穿部署与运行的可信构建”，并执行包含“依赖替换、未评审变更、构建输入污染、安全测试失败、绕过路径、漏洞发布、回滚和回归”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-16.3-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "16.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Run the positive control a known vulnerable artifact repaired and independently retested; exercise negative, stale, duplicate, bypass, and outage controls including credential failure, wrong version match, unavailable fix, mitigation bypass, failed deployment, rollback, recurring finding, and exposed unowned asset.",
          "zh": "运行正向控制“一项已知漏洞制品完成修复并独立复测”，并执行包含“凭据失败、版本误配、无可用修复、缓解绕过、部署失败、回滚、问题复发和外露无主资产”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-16.3-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "16.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-16.3-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "16.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-16.3-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "16.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-16.3-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "16.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-16.3-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "16.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever repositories, issue trackers, CI/CD, artifact registries, SBOMs, dependency sources, architecture models, scanners, tests, reports, deployments, and runtime telemetry change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 代码库、问题系统、CI/CD、制品库、SBOM、依赖来源、架构模型、扫描器、测试、报告、部署和运行遥测 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-16.3-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "16.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Use reviewed, unreviewed, reproducible, provenance-bound, vulnerable, test-failed, exception, deployed-unverified, drifted, rolled-back, and regression-protected releases to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已评审、未评审、可复现、来源绑定、存在漏洞、测试失败、例外、已部署未验证、漂移、已回滚和受回归保护发布物 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-16.3-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "16.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Use open, validated, false-positive, overdue, mitigated, excepted, deployed-unverified, retest-failed, reopened, and exposure-weighted findings to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 开放、已验证、误报、逾期、已缓解、例外、已部署未验证、复测失败、重开和暴露加权发现 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "16.4",
      "control": 16,
      "title_en": "Establish and Manage an Inventory of Third-Party Software Components",
      "title_zh": "第三方组件与 SBOM",
      "first_ig": 2,
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Software",
      "security_function": "Identfy",
      "patterns": [
        "software_dev",
        "inventory",
        "supplier"
      ],
      "expanded_complexity": true,
      "cas_context": {
        "dependencies": [
          "2.1"
        ],
        "variables": [
          "GV47",
          "M1",
          "M2",
          "M3",
          "M4",
          "M5"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [
        "monthly"
      ],
      "implementation_contract": {
        "en": {
          "scope": "Include direct and transitive open-source/commercial libraries, frameworks, plugins, container bases, build tools and runtime services used or planned, linked to exact product, version, environment and released artifact.",
          "build": "Generate and reconcile SBOMs from lockfiles, build and artifacts, record supplier/source, version/digest, license, support, risk and owner, and review at least monthly plus every build.",
          "proof": "Build a test artifact with direct/transitive components and compare source lock, resolver, SBOM, artifact scan and running deployment.",
          "boundary": "CAS labels the security function “Identfy” and compares a day measure to 12 months despite the safeguard's monthly cadence."
        },
        "zh": {
          "scope": "包括当前和计划使用的直接/传递开源与商业库、框架、插件、容器 Base、构建工具和运行服务，并关联准确产品、版本、环境与发布制品；只有包名、无生态/来源/摘要会歧义。",
          "build": "从 Lockfile、Build 和 Artifact 生成/对账 SBOM，记录供应商/来源、版本/摘要、许可证、支持、风险和责任人，至少每月及每次构建审查；保留来源/依赖关系，未过批准的计划项及时移除。",
          "proof": "构建含直接/传递依赖的测试制品，对比源码锁、Resolver、SBOM、制品扫描和运行部署；替换摘要/来源验证发现。",
          "boundary": "CAS 把功能写成 “Identfy”，又把以天计的时效拿去与 12 个月比较，而本项要求月审。"
        }
      },
      "category_counts": {
        "outcome": 9,
        "scope": 9,
        "ownership": 9,
        "data": 9,
        "integration": 9,
        "control": 9,
        "timing": 9,
        "exception": 9,
        "evidence": 9,
        "security": 9,
        "testing": 9,
        "operations": 9
      },
      "requirement_count": 108,
      "requirements": [
        {
          "code": "CIS-16.4-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "16.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Establish and Manage an Inventory of Third-Party Software Components; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“第三方组件与 SBOM”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-16.4-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "16.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 16.4, official Asset Class Software, Security Function Identfy, and IG2 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 16.4、官方资产类别“软件”、安全功能“Identfy”和首次出现的 IG2，并保存来源抓取日期。"
        },
        {
          "code": "CIS-16.4-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "16.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Include direct and transitive open-source/commercial libraries, frameworks, plugins, container bases, build tools and runtime services used or planned, linked to exact product, version, environment and released artifact.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“包括当前和计划使用的直接/传递开源与商业库、框架、插件、容器 Base、构建工具和运行服务，并关联准确产品、版本、环境与发布制品；只有包名、无生态/来源/摘要会歧义。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-16.4-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "16.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-16.4-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "16.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Establish and Manage an Inventory of Third-Party Software Components to its operating object—applications, services, APIs, code, dependencies, build and deployment systems, design invariants, vulnerability reports, tests, and production behavior—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“第三方组件与 SBOM”连接到其运营对象——应用、服务、API、代码、依赖、构建与部署系统、设计不变量、漏洞报告、测试和生产行为——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-16.4-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "16.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "For Establish and Manage an Inventory of Third-Party Software Components, express success as an observable decision over source-to-production software identity, design invariant, component trust, build provenance, test result, deployment state, runtime outcome, and vulnerability response; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“第三方组件与 SBOM”，以 从源码到生产的软件身份、设计不变量、组件信任、构建来源、测试结果、部署状态、运行结果和漏洞响应 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-16.4-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "16.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "For Establish and Manage an Inventory of Third-Party Software Components, express success as an observable decision over observed, approved, unapproved, ownerless, stale, duplicate, and retired object identity; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“第三方组件与 SBOM”，以 已观测、已批准、未批准、无责任人、陈旧、重复和已退役对象身份 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-16.4-OUT-08",
          "local_code": "OUT-08",
          "display_code": "O08",
          "safeguard_id": "16.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "For Establish and Manage an Inventory of Third-Party Software Components, express success as an observable decision over provider identity, supplied capability, data and privilege path, criticality, contract, assurance, tenant control, incident duty, dependency, and exit; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“第三方组件与 SBOM”，以 提供商身份、供应能力、数据与权限路径、关键度、合同、保证、租户控制、事件义务、依赖和退出 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-16.4-OUT-09",
          "local_code": "OUT-09",
          "display_code": "O09",
          "safeguard_id": "16.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "For the expanded Establish and Manage an Inventory of Third-Party Software Components scope, resolve conflicts among security, safety, privacy, legal, availability, customer, and operational objectives through an explicit risk decision.",
          "zh": "对“第三方组件与 SBOM”的扩展范围，通过显式风险决策解决安全、安全生产、隐私、法律、可用性、客户和运营目标冲突。"
        },
        {
          "code": "CIS-16.4-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "16.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-16.4-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "16.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-16.4-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "16.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-16.4-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "16.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-16.4-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "16.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across generated code, forks, vendoring, transitive and mutable dependencies, build compromise, feature flags, tenant logic, business-logic flaws, secrets, emergency release, and provider components; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 生成代码、分叉、vendoring、传递与可变依赖、构建失陷、功能开关、租户逻辑、业务逻辑缺陷、秘密、紧急发布和提供商组件 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-16.4-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "16.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Include generated and copied code, forks, vendoring, transitive dependencies, mutable tags, build plugins, feature flags, tenant logic, secrets, emergency release, and provider components in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 生成与复制代码、分叉、vendoring、传递依赖、可变标签、构建插件、功能开关、租户逻辑、秘密、紧急发布和提供商组件 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-16.4-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "16.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Include dormant, ephemeral, disconnected, externally managed, provider-held, aliased, cloned, and cross-tenant objects in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 休眠、短生、离线、外部托管、提供商持有、别名、克隆和跨租户对象 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-16.4-SCP-08",
          "local_code": "SCP-08",
          "display_code": "P08",
          "safeguard_id": "16.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Include shadow providers, subprocessors, acquisitions, click-through terms, plan limitations, shared responsibility, concentration, unavailable evidence, emergency support, and residual data in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 影子提供商、分处理方、收购、点击条款、套餐限制、共享责任、集中度、证据不可得、紧急支持和残余数据 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-16.4-SCP-09",
          "local_code": "SCP-09",
          "display_code": "P09",
          "safeguard_id": "16.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Define nested scope at enterprise, business service, tenant, environment, platform, object, identity, data set, and transaction levels; prohibit a parent result from hiding a failing child.",
          "zh": "按企业、业务服务、租户、环境、平台、对象、身份、数据集和交易定义嵌套范围，禁止父级结果遮蔽失败子级。"
        },
        {
          "code": "CIS-16.4-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "16.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-16.4-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "16.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-16.4-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "16.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-16.4-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "16.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-16.4-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "16.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind product and engineering owners, developers, security champions, application security, platform engineering, vulnerability response, architecture, and operations to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 产品与工程责任人、开发者、安全负责人、应用安全、平台工程、漏洞响应、架构和运营 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-16.4-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "16.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Name who may transition designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-16.4-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "16.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Name who may transition discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-16.4-OWN-08",
          "local_code": "OWN-08",
          "display_code": "W08",
          "safeguard_id": "16.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Name who may transition discovered → owned → classified → contracted → configured → evidenced/monitored → incident/exception → renewed or exited, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 发现 → 确认责任 → 分类 → 签约 → 配置 → 取证/监测 → 事件/例外 → 续约或退出，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-16.4-OWN-09",
          "local_code": "OWN-09",
          "display_code": "W09",
          "safeguard_id": "16.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Model delegated authority, quorum or dual approval where warranted, escalation deadlines, provider handoffs, conflict resolution, and executive risk acceptance.",
          "zh": "建模委派权限、必要时的双人或法定人数审批、升级期限、提供商交接、冲突解决和管理层风险接受。"
        },
        {
          "code": "CIS-16.4-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "16.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-16.4-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "16.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-16.4-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "16.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV47, M1, M2, M3, M4, M5) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV47, M1, M2, M3, M4, M5）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-16.4-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "16.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-16.4-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "16.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the secure-development, component, vulnerability, threat-model, build, release, and exception authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把安全开发、组件、漏洞、威胁模型、构建、发布与例外权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-16.4-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "16.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired.",
          "zh": "对生命周期“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-16.4-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "16.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence.",
          "zh": "对生命周期“发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-16.4-DAT-08",
          "local_code": "DAT-08",
          "display_code": "D08",
          "safeguard_id": "16.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle discovered → owned → classified → contracted → configured → evidenced/monitored → incident/exception → renewed or exited.",
          "zh": "对生命周期“发现 → 确认责任 → 分类 → 签约 → 配置 → 取证/监测 → 事件/例外 → 续约或退出”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-16.4-DAT-09",
          "local_code": "DAT-09",
          "display_code": "D09",
          "safeguard_id": "16.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Version schemas and state transitions with migration, backfill, deduplication, lineage, historical denominator, deletion, and rollback semantics.",
          "zh": "对模式和状态转换做版本管理，定义迁移、回填、去重、血缘、历史分母、删除和回滚语义。"
        },
        {
          "code": "CIS-16.4-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "16.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 2.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 2.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-16.4-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "16.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-16.4-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "16.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-16.4-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "16.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-16.4-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "16.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile repositories, issue trackers, CI/CD, artifact registries, SBOMs, dependency sources, architecture models, scanners, tests, reports, deployments, and runtime telemetry and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 代码库、问题系统、CI/CD、制品库、SBOM、依赖来源、架构模型、扫描器、测试、报告、部署和运行遥测，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-16.4-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "16.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Require every connector carrying source-to-production software identity, design invariant, component trust, build provenance, test result, deployment state, runtime outcome, and vulnerability response to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 从源码到生产的软件身份、设计不变量、组件信任、构建来源、测试结果、部署状态、运行结果和漏洞响应 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-16.4-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "16.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Require every connector carrying observed, approved, unapproved, ownerless, stale, duplicate, and retired object identity to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 已观测、已批准、未批准、无责任人、陈旧、重复和已退役对象身份 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-16.4-INT-08",
          "local_code": "INT-08",
          "display_code": "I08",
          "safeguard_id": "16.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Require every connector carrying provider identity, supplied capability, data and privilege path, criticality, contract, assurance, tenant control, incident duty, dependency, and exit to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 提供商身份、供应能力、数据与权限路径、关键度、合同、保证、租户控制、事件义务、依赖和退出 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-16.4-INT-09",
          "local_code": "INT-09",
          "display_code": "I09",
          "safeguard_id": "16.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Define consistency rules across disagreeing sources, source precedence, confidence, reconciliation queues, dead-letter handling, reprocessing, and end-to-end trace identity.",
          "zh": "定义冲突来源的一致性、优先级、置信度、对账队列、死信、重处理和端到端追踪身份。"
        },
        {
          "code": "CIS-16.4-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "16.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Generate and reconcile SBOMs from lockfiles, build and artifacts, record supplier/source, version/digest, license, support, risk and owner, and review at least monthly plus every build.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“从 Lockfile、Build 和 Artifact 生成/对账 SBOM，记录供应商/来源、版本/摘要、许可证、支持、风险和责任人，至少每月及每次构建审查；保留来源/依赖关系，未过批准的计划项及时移除。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-16.4-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "16.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-16.4-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "16.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-16.4-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "16.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-16.4-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "16.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the secure-development, component, vulnerability, threat-model, build, release, and exception authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在安全开发、组件、漏洞、威胁模型、构建、发布与例外权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-16.4-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "16.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Implement the explicit state machine designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-16.4-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "16.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Implement the explicit state machine discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-16.4-CTL-08",
          "local_code": "CTL-08",
          "display_code": "C08",
          "safeguard_id": "16.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Implement the explicit state machine discovered → owned → classified → contracted → configured → evidenced/monitored → incident/exception → renewed or exited; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“发现 → 确认责任 → 分类 → 签约 → 配置 → 取证/监测 → 事件/例外 → 续约或退出”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-16.4-CTL-09",
          "local_code": "CTL-09",
          "display_code": "C09",
          "safeguard_id": "16.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Specify concurrent decisions, partial success, compensating transactions, repeated requests, stale policy, dependency outage, and recovery from an interrupted state transition.",
          "zh": "定义并发决策、部分成功、补偿事务、重复请求、陈旧策略、依赖中断和中途状态转换恢复。"
        },
        {
          "code": "CIS-16.4-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "16.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (monthly); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（monthly）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-16.4-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "16.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-16.4-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "16.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-16.4-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "16.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-16.4-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "16.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in applications, services, APIs, code, dependencies, build and deployment systems, design invariants, vulnerability reports, tests, and production behavior; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 应用、服务、API、代码、依赖、构建与部署系统、设计不变量、漏洞报告、测试和生产行为 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-16.4-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "16.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; alert before each deadline becomes overdue.",
          "zh": "为“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-16.4-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "16.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence; alert before each deadline becomes overdue.",
          "zh": "为“发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-16.4-TIM-08",
          "local_code": "TIM-08",
          "display_code": "T08",
          "safeguard_id": "16.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for discovered → owned → classified → contracted → configured → evidenced/monitored → incident/exception → renewed or exited; alert before each deadline becomes overdue.",
          "zh": "为“发现 → 确认责任 → 分类 → 签约 → 配置 → 取证/监测 → 事件/例外 → 续约或退出”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-16.4-TIM-09",
          "local_code": "TIM-09",
          "display_code": "T09",
          "safeguard_id": "16.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Allocate an end-to-end SLO budget across discovery, collection, processing, approval, enforcement, verification, and closure; prioritize overdue work by consequence and exposure.",
          "zh": "把端到端 SLO 预算分配到发现、采集、处理、审批、执行、验证和关闭，并按后果与暴露排列逾期工作。"
        },
        {
          "code": "CIS-16.4-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "16.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “CAS labels the security function “Identfy” and compares a day measure to 12 months despite the safeguard's monthly cadence.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“CAS 把功能写成 “Identfy”，又把以天计的时效拿去与 12 个月比较，而本项要求月审。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-16.4-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "16.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-16.4-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "16.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-16.4-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "16.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-16.4-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "16.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat generated code, forks, vendoring, transitive and mutable dependencies, build compromise, feature flags, tenant logic, business-logic flaws, secrets, emergency release, and provider components as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 生成代码、分叉、vendoring、传递与可变依赖、构建失陷、功能开关、租户逻辑、业务逻辑缺陷、秘密、紧急发布和提供商组件 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-16.4-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "16.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Treat generated and copied code, forks, vendoring, transitive dependencies, mutable tags, build plugins, feature flags, tenant logic, secrets, emergency release, and provider components as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 生成与复制代码、分叉、vendoring、传递依赖、可变标签、构建插件、功能开关、租户逻辑、秘密、紧急发布和提供商组件 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-16.4-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "16.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Treat dormant, ephemeral, disconnected, externally managed, provider-held, aliased, cloned, and cross-tenant objects as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 休眠、短生、离线、外部托管、提供商持有、别名、克隆和跨租户对象 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-16.4-EXC-08",
          "local_code": "EXC-08",
          "display_code": "X08",
          "safeguard_id": "16.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Treat shadow providers, subprocessors, acquisitions, click-through terms, plan limitations, shared responsibility, concentration, unavailable evidence, emergency support, and residual data as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 影子提供商、分处理方、收购、点击条款、套餐限制、共享责任、集中度、证据不可得、紧急支持和残余数据 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-16.4-EXC-09",
          "local_code": "EXC-09",
          "display_code": "X09",
          "safeguard_id": "16.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Exercise compound failures where an exception, stale source, provider outage, unavailable owner, and degraded control overlap; define one safe command and one accountable decision.",
          "zh": "演练例外、陈旧来源、提供商中断、责任人不可用和控制降级同时出现的复合故障，明确一条安全指令和一个责任决策。"
        },
        {
          "code": "CIS-16.4-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "16.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Build a test artifact with direct/transitive components and compare source lock, resolver, SBOM, artifact scan and running deployment.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“构建含直接/传递依赖的测试制品，对比源码锁、Resolver、SBOM、制品扫描和运行部署；替换摘要/来源验证发现。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-16.4-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "16.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-16.4-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "16.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 6 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、6 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-16.4-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "16.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-16.4-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "16.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the secure-development, component, vulnerability, threat-model, build, release, and exception authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以安全开发、组件、漏洞、威胁模型、构建、发布与例外权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-16.4-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "16.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Publish reviewed, unreviewed, reproducible, provenance-bound, vulnerable, test-failed, exception, deployed-unverified, drifted, rolled-back, and regression-protected releases with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已评审、未评审、可复现、来源绑定、存在漏洞、测试失败、例外、已部署未验证、漂移、已回滚和受回归保护发布物，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-16.4-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "16.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Publish matched, missing, duplicate, stale, ownerless, unapproved, unevaluable, and retired-without-proof counts with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 匹配、缺失、重复、陈旧、无责任人、未批准、不可评估及无证明退役数量，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-16.4-EVD-08",
          "local_code": "EVD-08",
          "display_code": "E08",
          "safeguard_id": "16.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Publish known, unknown, critical, unclassified, contract-gap, evidence-current, evidence-stale, tenant-misconfigured, incident, concentrated, and exit-incomplete providers with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已知、未知、关键、未分类、合同缺口、证据当前、证据过期、租户误配、事件、集中和退出不完整提供商，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-16.4-EVD-09",
          "local_code": "EVD-09",
          "display_code": "E09",
          "safeguard_id": "16.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Require an independent party to reconstruct the decision from source receipts and reproduce the population, state transition, calculation, test result, exception, and final closure.",
          "zh": "要求独立人员使用来源回执重建决策，并复现总体、状态转换、计算、测试结果、例外和最终关闭。"
        },
        {
          "code": "CIS-16.4-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "16.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-16.4-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "16.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-16.4-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "16.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-16.4-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "16.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-16.4-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "16.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the secure-development, component, vulnerability, threat-model, build, release, and exception authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护安全开发、组件、漏洞、威胁模型、构建、发布与例外权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-16.4-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "16.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Restrict authority to change designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-16.4-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "16.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Restrict authority to change discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-16.4-SEC-08",
          "local_code": "SEC-08",
          "display_code": "S08",
          "safeguard_id": "16.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Restrict authority to change discovered → owned → classified → contracted → configured → evidenced/monitored → incident/exception → renewed or exited; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“发现 → 确认责任 → 分类 → 签约 → 配置 → 取证/监测 → 事件/例外 → 续约或退出”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-16.4-SEC-09",
          "local_code": "SEC-09",
          "display_code": "S09",
          "safeguard_id": "16.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Threat-model the implementation system itself: forged evidence, poisoned inventory, privilege abuse, cross-tenant confusion, policy rollback, audit deletion, denial of service, and recovery compromise.",
          "zh": "威胁建模实施系统自身：伪造证据、污染清单、权限滥用、跨租户混淆、策略回滚、审计删除、拒绝服务和恢复失陷。"
        },
        {
          "code": "CIS-16.4-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "16.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-16.4-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "16.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-16.4-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "16.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-16.4-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "16.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-16.4-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "16.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise secure and insecure design paths, trusted and substituted components, accepted and rejected reports, code-level controls, authenticated abuse, build provenance, rollback, and regression through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 安全与不安全设计路径、可信与被替换组件、接受与拒绝报告、代码级控制、认证后滥用、构建来源、回滚和回归，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-16.4-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "16.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Run the positive control a trusted build that preserves the security invariant through deployment and runtime; exercise negative, stale, duplicate, bypass, and outage controls including a substituted dependency, unreviewed change, poisoned build input, failed security test, bypass path, vulnerable release, rollback, and regression.",
          "zh": "运行正向控制“一个把安全不变量贯穿部署与运行的可信构建”，并执行包含“依赖替换、未评审变更、构建输入污染、安全测试失败、绕过路径、漏洞发布、回滚和回归”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-16.4-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "16.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Run the positive control a seeded approved object reconciled from two independent sources; exercise negative, stale, duplicate, bypass, and outage controls including an unknown object, duplicate identity, stale record, vanished object, failed source, and cross-tenant collision.",
          "zh": "运行正向控制“从两个独立来源对账的一项植入已批准对象”，并执行包含“未知对象、重复身份、陈旧记录、突然消失对象、失效来源和跨租户碰撞”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-16.4-TST-08",
          "local_code": "TST-08",
          "display_code": "V08",
          "safeguard_id": "16.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Run the positive control an approved provider with tested tenant controls, current evidence, notification path, and exit artifact; exercise negative, stale, duplicate, bypass, and outage controls including a shadow provider, missing clause, stale attestation, misconfigured tenant, unavailable export, subprocessor change, provider incident, and residual data after exit.",
          "zh": "运行正向控制“一家具备已测试租户控制、当前证据、通知路径和退出制品的获批提供商”，并执行包含“影子提供商、条款缺失、证明过期、租户误配、导出不可用、分处理方变化、提供商事件和退出后残余数据”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-16.4-TST-09",
          "local_code": "TST-09",
          "display_code": "V09",
          "safeguard_id": "16.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Build a pairwise platform-and-failure matrix, then add high-consequence multi-factor cases, historical regression, source substitution, red-team challenge, and assessor replay.",
          "zh": "建立平台—故障两两组合矩阵，再加入高后果多因素案例、历史回归、来源替换、红队挑战和评估方重放。"
        },
        {
          "code": "CIS-16.4-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "16.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-16.4-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "16.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-16.4-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "16.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-16.4-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "16.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-16.4-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "16.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever repositories, issue trackers, CI/CD, artifact registries, SBOMs, dependency sources, architecture models, scanners, tests, reports, deployments, and runtime telemetry change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 代码库、问题系统、CI/CD、制品库、SBOM、依赖来源、架构模型、扫描器、测试、报告、部署和运行遥测 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-16.4-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "16.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Use reviewed, unreviewed, reproducible, provenance-bound, vulnerable, test-failed, exception, deployed-unverified, drifted, rolled-back, and regression-protected releases to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已评审、未评审、可复现、来源绑定、存在漏洞、测试失败、例外、已部署未验证、漂移、已回滚和受回归保护发布物 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-16.4-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "16.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Use matched, missing, duplicate, stale, ownerless, unapproved, unevaluable, and retired-without-proof counts to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 匹配、缺失、重复、陈旧、无责任人、未批准、不可评估及无证明退役数量 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-16.4-OPS-08",
          "local_code": "OPS-08",
          "display_code": "R08",
          "safeguard_id": "16.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Use known, unknown, critical, unclassified, contract-gap, evidence-current, evidence-stale, tenant-misconfigured, incident, concentrated, and exit-incomplete providers to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已知、未知、关键、未分类、合同缺口、证据当前、证据过期、租户误配、事件、集中和退出不完整提供商 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-16.4-OPS-09",
          "local_code": "OPS-09",
          "display_code": "R09",
          "safeguard_id": "16.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Use canary deployment, kill criteria, rollback, backlog burn-down, exception reduction, source-quality targets, quarterly design review, and a measurable retirement plan.",
          "zh": "采用金丝雀、停止标准、回滚、积压燃尽、例外缩减、来源质量目标、季度设计复核和可量化退役计划。"
        }
      ]
    },
    {
      "id": "16.5",
      "control": 16,
      "title_en": "Use Up-to-Date and Trusted Third-Party Software Components",
      "title_zh": "可信且及时的第三方组件",
      "first_ig": 2,
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Software",
      "security_function": "Protect",
      "patterns": [
        "software_dev",
        "vulnerability",
        "supplier"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "16.4"
        ],
        "variables": [
          "GV47",
          "M1",
          "M2",
          "M3",
          "M4"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "The decision covers component version, source, publisher/maintainer, integrity/provenance, support, known risk, release maturity and compatibility.",
          "build": "Resolve only through controlled repositories, pin and verify digests/signatures/provenance, monitor advisories and support, update within risk SLO and test before promotion.",
          "proof": "Attempt dependency confusion, typosquat/unapproved registry, modified digest, unsupported and known-vulnerable versions in a test build.",
          "boundary": "A trusted component can become compromised and an old version may be safer during a bad release, requiring time-bounded hold."
        },
        "zh": {
          "scope": "判定同时看组件版本、来源、发布者/维护者、完整性/Provenance、支持、已知风险、成熟度和兼容性。",
          "build": "只经受控仓库解析，固定并验摘要/签名/来源，监控通告与支持，在风险 SLO 内更新并先测试；优先维护良好、窄功能组件，移除废弃/重复依赖，定义紧急替换/回滚。",
          "proof": "在测试构建尝试依赖混淆、Typosquat、未批准 Registry、改摘要、不支持和已知漏洞版本，验证阻断/评审、制品关联和部署版本，并抽验上游所有权/发布真实性和更新结果。",
          "boundary": "可信组件也会被攻陷，坏版本期间旧版可能暂时更安全，需限时 Hold。"
        }
      },
      "category_counts": {
        "outcome": 8,
        "scope": 8,
        "ownership": 8,
        "data": 8,
        "integration": 8,
        "control": 8,
        "timing": 8,
        "exception": 8,
        "evidence": 8,
        "security": 8,
        "testing": 8,
        "operations": 8
      },
      "requirement_count": 96,
      "requirements": [
        {
          "code": "CIS-16.5-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "16.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Use Up-to-Date and Trusted Third-Party Software Components; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“可信且及时的第三方组件”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-16.5-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "16.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 16.5, official Asset Class Software, Security Function Protect, and IG2 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 16.5、官方资产类别“软件”、安全功能“保护”和首次出现的 IG2，并保存来源抓取日期。"
        },
        {
          "code": "CIS-16.5-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "16.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “The decision covers component version, source, publisher/maintainer, integrity/provenance, support, known risk, release maturity and compatibility.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“判定同时看组件版本、来源、发布者/维护者、完整性/Provenance、支持、已知风险、成熟度和兼容性。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-16.5-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "16.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-16.5-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "16.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Use Up-to-Date and Trusted Third-Party Software Components to its operating object—applications, services, APIs, code, dependencies, build and deployment systems, design invariants, vulnerability reports, tests, and production behavior—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“可信且及时的第三方组件”连接到其运营对象——应用、服务、API、代码、依赖、构建与部署系统、设计不变量、漏洞报告、测试和生产行为——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-16.5-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "16.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "For Use Up-to-Date and Trusted Third-Party Software Components, express success as an observable decision over source-to-production software identity, design invariant, component trust, build provenance, test result, deployment state, runtime outcome, and vulnerability response; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“可信且及时的第三方组件”，以 从源码到生产的软件身份、设计不变量、组件信任、构建来源、测试结果、部署状态、运行结果和漏洞响应 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-16.5-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "16.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "For Use Up-to-Date and Trusted Third-Party Software Components, express success as an observable decision over affected artifact identity, exploitability, business consequence, remediation choice, deployed fix, compensating control, and residual exposure; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“可信且及时的第三方组件”，以 受影响制品身份、可利用性、业务后果、修复选择、已部署修复、补偿控制和残余暴露 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-16.5-OUT-08",
          "local_code": "OUT-08",
          "display_code": "O08",
          "safeguard_id": "16.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "For Use Up-to-Date and Trusted Third-Party Software Components, express success as an observable decision over provider identity, supplied capability, data and privilege path, criticality, contract, assurance, tenant control, incident duty, dependency, and exit; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“可信且及时的第三方组件”，以 提供商身份、供应能力、数据与权限路径、关键度、合同、保证、租户控制、事件义务、依赖和退出 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-16.5-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "16.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-16.5-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "16.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-16.5-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "16.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-16.5-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "16.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-16.5-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "16.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across generated code, forks, vendoring, transitive and mutable dependencies, build compromise, feature flags, tenant logic, business-logic flaws, secrets, emergency release, and provider components; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 生成代码、分叉、vendoring、传递与可变依赖、构建失陷、功能开关、租户逻辑、业务逻辑缺陷、秘密、紧急发布和提供商组件 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-16.5-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "16.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Include generated and copied code, forks, vendoring, transitive dependencies, mutable tags, build plugins, feature flags, tenant logic, secrets, emergency release, and provider components in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 生成与复制代码、分叉、vendoring、传递依赖、可变标签、构建插件、功能开关、租户逻辑、秘密、紧急发布和提供商组件 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-16.5-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "16.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Include unknown versions, false positives, unavailable fixes, vendor lag, ephemeral workloads, unscannable platforms, inherited dependencies, mitigation-only states, and recurrence in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 未知版本、误报、无可用修复、厂商滞后、短生工作负载、不可扫描平台、继承依赖、仅缓解状态和复发 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-16.5-SCP-08",
          "local_code": "SCP-08",
          "display_code": "P08",
          "safeguard_id": "16.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Include shadow providers, subprocessors, acquisitions, click-through terms, plan limitations, shared responsibility, concentration, unavailable evidence, emergency support, and residual data in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 影子提供商、分处理方、收购、点击条款、套餐限制、共享责任、集中度、证据不可得、紧急支持和残余数据 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-16.5-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "16.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-16.5-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "16.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-16.5-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "16.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-16.5-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "16.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-16.5-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "16.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind product and engineering owners, developers, security champions, application security, platform engineering, vulnerability response, architecture, and operations to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 产品与工程责任人、开发者、安全负责人、应用安全、平台工程、漏洞响应、架构和运营 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-16.5-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "16.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Name who may transition designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-16.5-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "16.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Name who may transition discovered → validated → prioritized → assigned → fixed/mitigated/excepted → deployed → retested → closed/reopened, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 发现 → 验证 → 定级 → 分派 → 修复/缓解/例外 → 部署 → 复测 → 关闭/重开，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-16.5-OWN-08",
          "local_code": "OWN-08",
          "display_code": "W08",
          "safeguard_id": "16.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Name who may transition discovered → owned → classified → contracted → configured → evidenced/monitored → incident/exception → renewed or exited, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 发现 → 确认责任 → 分类 → 签约 → 配置 → 取证/监测 → 事件/例外 → 续约或退出，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-16.5-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "16.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-16.5-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "16.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-16.5-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "16.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV47, M1, M2, M3, M4) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV47, M1, M2, M3, M4）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-16.5-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "16.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-16.5-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "16.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the secure-development, component, vulnerability, threat-model, build, release, and exception authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把安全开发、组件、漏洞、威胁模型、构建、发布与例外权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-16.5-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "16.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired.",
          "zh": "对生命周期“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-16.5-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "16.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle discovered → validated → prioritized → assigned → fixed/mitigated/excepted → deployed → retested → closed/reopened.",
          "zh": "对生命周期“发现 → 验证 → 定级 → 分派 → 修复/缓解/例外 → 部署 → 复测 → 关闭/重开”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-16.5-DAT-08",
          "local_code": "DAT-08",
          "display_code": "D08",
          "safeguard_id": "16.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle discovered → owned → classified → contracted → configured → evidenced/monitored → incident/exception → renewed or exited.",
          "zh": "对生命周期“发现 → 确认责任 → 分类 → 签约 → 配置 → 取证/监测 → 事件/例外 → 续约或退出”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-16.5-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "16.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 16.4; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 16.4 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-16.5-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "16.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-16.5-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "16.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-16.5-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "16.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-16.5-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "16.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile repositories, issue trackers, CI/CD, artifact registries, SBOMs, dependency sources, architecture models, scanners, tests, reports, deployments, and runtime telemetry and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 代码库、问题系统、CI/CD、制品库、SBOM、依赖来源、架构模型、扫描器、测试、报告、部署和运行遥测，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-16.5-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "16.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Require every connector carrying source-to-production software identity, design invariant, component trust, build provenance, test result, deployment state, runtime outcome, and vulnerability response to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 从源码到生产的软件身份、设计不变量、组件信任、构建来源、测试结果、部署状态、运行结果和漏洞响应 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-16.5-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "16.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Require every connector carrying affected artifact identity, exploitability, business consequence, remediation choice, deployed fix, compensating control, and residual exposure to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 受影响制品身份、可利用性、业务后果、修复选择、已部署修复、补偿控制和残余暴露 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-16.5-INT-08",
          "local_code": "INT-08",
          "display_code": "I08",
          "safeguard_id": "16.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Require every connector carrying provider identity, supplied capability, data and privilege path, criticality, contract, assurance, tenant control, incident duty, dependency, and exit to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 提供商身份、供应能力、数据与权限路径、关键度、合同、保证、租户控制、事件义务、依赖和退出 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-16.5-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "16.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Resolve only through controlled repositories, pin and verify digests/signatures/provenance, monitor advisories and support, update within risk SLO and test before promotion.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“只经受控仓库解析，固定并验摘要/签名/来源，监控通告与支持，在风险 SLO 内更新并先测试；优先维护良好、窄功能组件，移除废弃/重复依赖，定义紧急替换/回滚。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-16.5-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "16.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-16.5-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "16.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-16.5-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "16.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-16.5-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "16.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the secure-development, component, vulnerability, threat-model, build, release, and exception authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在安全开发、组件、漏洞、威胁模型、构建、发布与例外权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-16.5-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "16.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Implement the explicit state machine designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-16.5-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "16.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Implement the explicit state machine discovered → validated → prioritized → assigned → fixed/mitigated/excepted → deployed → retested → closed/reopened; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“发现 → 验证 → 定级 → 分派 → 修复/缓解/例外 → 部署 → 复测 → 关闭/重开”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-16.5-CTL-08",
          "local_code": "CTL-08",
          "display_code": "C08",
          "safeguard_id": "16.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Implement the explicit state machine discovered → owned → classified → contracted → configured → evidenced/monitored → incident/exception → renewed or exited; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“发现 → 确认责任 → 分类 → 签约 → 配置 → 取证/监测 → 事件/例外 → 续约或退出”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-16.5-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "16.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-16.5-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "16.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-16.5-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "16.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-16.5-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "16.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-16.5-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "16.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in applications, services, APIs, code, dependencies, build and deployment systems, design invariants, vulnerability reports, tests, and production behavior; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 应用、服务、API、代码、依赖、构建与部署系统、设计不变量、漏洞报告、测试和生产行为 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-16.5-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "16.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; alert before each deadline becomes overdue.",
          "zh": "为“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-16.5-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "16.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for discovered → validated → prioritized → assigned → fixed/mitigated/excepted → deployed → retested → closed/reopened; alert before each deadline becomes overdue.",
          "zh": "为“发现 → 验证 → 定级 → 分派 → 修复/缓解/例外 → 部署 → 复测 → 关闭/重开”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-16.5-TIM-08",
          "local_code": "TIM-08",
          "display_code": "T08",
          "safeguard_id": "16.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for discovered → owned → classified → contracted → configured → evidenced/monitored → incident/exception → renewed or exited; alert before each deadline becomes overdue.",
          "zh": "为“发现 → 确认责任 → 分类 → 签约 → 配置 → 取证/监测 → 事件/例外 → 续约或退出”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-16.5-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "16.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “A trusted component can become compromised and an old version may be safer during a bad release, requiring time-bounded hold.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“可信组件也会被攻陷，坏版本期间旧版可能暂时更安全，需限时 Hold。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-16.5-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "16.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-16.5-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "16.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-16.5-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "16.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-16.5-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "16.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat generated code, forks, vendoring, transitive and mutable dependencies, build compromise, feature flags, tenant logic, business-logic flaws, secrets, emergency release, and provider components as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 生成代码、分叉、vendoring、传递与可变依赖、构建失陷、功能开关、租户逻辑、业务逻辑缺陷、秘密、紧急发布和提供商组件 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-16.5-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "16.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Treat generated and copied code, forks, vendoring, transitive dependencies, mutable tags, build plugins, feature flags, tenant logic, secrets, emergency release, and provider components as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 生成与复制代码、分叉、vendoring、传递依赖、可变标签、构建插件、功能开关、租户逻辑、秘密、紧急发布和提供商组件 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-16.5-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "16.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Treat unknown versions, false positives, unavailable fixes, vendor lag, ephemeral workloads, unscannable platforms, inherited dependencies, mitigation-only states, and recurrence as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 未知版本、误报、无可用修复、厂商滞后、短生工作负载、不可扫描平台、继承依赖、仅缓解状态和复发 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-16.5-EXC-08",
          "local_code": "EXC-08",
          "display_code": "X08",
          "safeguard_id": "16.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Treat shadow providers, subprocessors, acquisitions, click-through terms, plan limitations, shared responsibility, concentration, unavailable evidence, emergency support, and residual data as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 影子提供商、分处理方、收购、点击条款、套餐限制、共享责任、集中度、证据不可得、紧急支持和残余数据 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-16.5-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "16.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Attempt dependency confusion, typosquat/unapproved registry, modified digest, unsupported and known-vulnerable versions in a test build.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“在测试构建尝试依赖混淆、Typosquat、未批准 Registry、改摘要、不支持和已知漏洞版本，验证阻断/评审、制品关联和部署版本，并抽验上游所有权/发布真实性和更新结果。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-16.5-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "16.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-16.5-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "16.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 5 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、5 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-16.5-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "16.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-16.5-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "16.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the secure-development, component, vulnerability, threat-model, build, release, and exception authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以安全开发、组件、漏洞、威胁模型、构建、发布与例外权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-16.5-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "16.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Publish reviewed, unreviewed, reproducible, provenance-bound, vulnerable, test-failed, exception, deployed-unverified, drifted, rolled-back, and regression-protected releases with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已评审、未评审、可复现、来源绑定、存在漏洞、测试失败、例外、已部署未验证、漂移、已回滚和受回归保护发布物，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-16.5-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "16.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Publish open, validated, false-positive, overdue, mitigated, excepted, deployed-unverified, retest-failed, reopened, and exposure-weighted findings with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 开放、已验证、误报、逾期、已缓解、例外、已部署未验证、复测失败、重开和暴露加权发现，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-16.5-EVD-08",
          "local_code": "EVD-08",
          "display_code": "E08",
          "safeguard_id": "16.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Publish known, unknown, critical, unclassified, contract-gap, evidence-current, evidence-stale, tenant-misconfigured, incident, concentrated, and exit-incomplete providers with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已知、未知、关键、未分类、合同缺口、证据当前、证据过期、租户误配、事件、集中和退出不完整提供商，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-16.5-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "16.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-16.5-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "16.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-16.5-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "16.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-16.5-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "16.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-16.5-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "16.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the secure-development, component, vulnerability, threat-model, build, release, and exception authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护安全开发、组件、漏洞、威胁模型、构建、发布与例外权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-16.5-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "16.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Restrict authority to change designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-16.5-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "16.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Restrict authority to change discovered → validated → prioritized → assigned → fixed/mitigated/excepted → deployed → retested → closed/reopened; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“发现 → 验证 → 定级 → 分派 → 修复/缓解/例外 → 部署 → 复测 → 关闭/重开”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-16.5-SEC-08",
          "local_code": "SEC-08",
          "display_code": "S08",
          "safeguard_id": "16.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Restrict authority to change discovered → owned → classified → contracted → configured → evidenced/monitored → incident/exception → renewed or exited; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“发现 → 确认责任 → 分类 → 签约 → 配置 → 取证/监测 → 事件/例外 → 续约或退出”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-16.5-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "16.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-16.5-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "16.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-16.5-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "16.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-16.5-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "16.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-16.5-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "16.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise secure and insecure design paths, trusted and substituted components, accepted and rejected reports, code-level controls, authenticated abuse, build provenance, rollback, and regression through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 安全与不安全设计路径、可信与被替换组件、接受与拒绝报告、代码级控制、认证后滥用、构建来源、回滚和回归，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-16.5-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "16.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Run the positive control a trusted build that preserves the security invariant through deployment and runtime; exercise negative, stale, duplicate, bypass, and outage controls including a substituted dependency, unreviewed change, poisoned build input, failed security test, bypass path, vulnerable release, rollback, and regression.",
          "zh": "运行正向控制“一个把安全不变量贯穿部署与运行的可信构建”，并执行包含“依赖替换、未评审变更、构建输入污染、安全测试失败、绕过路径、漏洞发布、回滚和回归”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-16.5-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "16.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Run the positive control a known vulnerable artifact repaired and independently retested; exercise negative, stale, duplicate, bypass, and outage controls including credential failure, wrong version match, unavailable fix, mitigation bypass, failed deployment, rollback, recurring finding, and exposed unowned asset.",
          "zh": "运行正向控制“一项已知漏洞制品完成修复并独立复测”，并执行包含“凭据失败、版本误配、无可用修复、缓解绕过、部署失败、回滚、问题复发和外露无主资产”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-16.5-TST-08",
          "local_code": "TST-08",
          "display_code": "V08",
          "safeguard_id": "16.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Run the positive control an approved provider with tested tenant controls, current evidence, notification path, and exit artifact; exercise negative, stale, duplicate, bypass, and outage controls including a shadow provider, missing clause, stale attestation, misconfigured tenant, unavailable export, subprocessor change, provider incident, and residual data after exit.",
          "zh": "运行正向控制“一家具备已测试租户控制、当前证据、通知路径和退出制品的获批提供商”，并执行包含“影子提供商、条款缺失、证明过期、租户误配、导出不可用、分处理方变化、提供商事件和退出后残余数据”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-16.5-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "16.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-16.5-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "16.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-16.5-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "16.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-16.5-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "16.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-16.5-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "16.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever repositories, issue trackers, CI/CD, artifact registries, SBOMs, dependency sources, architecture models, scanners, tests, reports, deployments, and runtime telemetry change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 代码库、问题系统、CI/CD、制品库、SBOM、依赖来源、架构模型、扫描器、测试、报告、部署和运行遥测 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-16.5-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "16.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Use reviewed, unreviewed, reproducible, provenance-bound, vulnerable, test-failed, exception, deployed-unverified, drifted, rolled-back, and regression-protected releases to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已评审、未评审、可复现、来源绑定、存在漏洞、测试失败、例外、已部署未验证、漂移、已回滚和受回归保护发布物 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-16.5-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "16.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Use open, validated, false-positive, overdue, mitigated, excepted, deployed-unverified, retest-failed, reopened, and exposure-weighted findings to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 开放、已验证、误报、逾期、已缓解、例外、已部署未验证、复测失败、重开和暴露加权发现 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-16.5-OPS-08",
          "local_code": "OPS-08",
          "display_code": "R08",
          "safeguard_id": "16.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original supplier pattern analysis",
          "basis_zh": "SOSEC 原创 supplier 模式分析",
          "en": "Use known, unknown, critical, unclassified, contract-gap, evidence-current, evidence-stale, tenant-misconfigured, incident, concentrated, and exit-incomplete providers to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已知、未知、关键、未分类、合同缺口、证据当前、证据过期、租户误配、事件、集中和退出不完整提供商 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "16.6",
      "control": 16,
      "title_en": "Establish and Maintain a Severity Rating System and Process for Application Vulnerabilities",
      "title_zh": "应用漏洞严重度与发布门槛",
      "first_ig": 2,
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Documentation",
      "security_function": "Govern",
      "patterns": [
        "software_dev",
        "vulnerability",
        "governance"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "16.2"
        ],
        "variables": [
          "GV48",
          "M1",
          "M2",
          "M3"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [
        "annually"
      ],
      "implementation_contract": {
        "en": {
          "scope": "The system rates vulnerabilities in application context using exploitability, exposure, privilege, data/business consequence, chaining, control strength and active exploitation.",
          "build": "Create consistent severity/risk criteria, triage authority, SLOs, minimum release acceptability, exception/expiry and escalation.",
          "proof": "Give multiple reviewers representative standalone, chained and context-changing findings and compare decisions.",
          "boundary": "CVSS alone lacks business and architecture context; lowering severity to ship is not risk treatment."
        },
        "zh": {
          "scope": "系统要用应用上下文评估可利用性、暴露、权限、数据/业务后果、串链、现有控制和活跃利用，并为代码、依赖、配置、设计的发布前后发现设发布阻断/修复决定。",
          "build": "制定一致严重度/风险标准、分诊权、SLO、最低发布可接受度、例外/到期和升级；校准扫描器分数，覆盖需证据，每年及重大事件/威胁/模型变化时更新。",
          "proof": "给多名评审者独立、串链和上下文改变的代表发现，比较决定；测试含 Gate 级问题和将到期例外的发布，验证阻断、批准、部署跟踪和后续修复。",
          "boundary": "CVSS 没有业务/架构上下文；为上线降分不是风险处置。"
        }
      },
      "category_counts": {
        "outcome": 8,
        "scope": 8,
        "ownership": 8,
        "data": 8,
        "integration": 8,
        "control": 8,
        "timing": 8,
        "exception": 8,
        "evidence": 8,
        "security": 8,
        "testing": 8,
        "operations": 8
      },
      "requirement_count": 96,
      "requirements": [
        {
          "code": "CIS-16.6-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "16.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Establish and Maintain a Severity Rating System and Process for Application Vulnerabilities; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“应用漏洞严重度与发布门槛”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-16.6-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "16.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 16.6, official Asset Class Documentation, Security Function Govern, and IG2 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 16.6、官方资产类别“文档与治理”、安全功能“治理”和首次出现的 IG2，并保存来源抓取日期。"
        },
        {
          "code": "CIS-16.6-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "16.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “The system rates vulnerabilities in application context using exploitability, exposure, privilege, data/business consequence, chaining, control strength and active exploitation.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“系统要用应用上下文评估可利用性、暴露、权限、数据/业务后果、串链、现有控制和活跃利用，并为代码、依赖、配置、设计的发布前后发现设发布阻断/修复决定。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-16.6-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "16.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-16.6-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "16.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Establish and Maintain a Severity Rating System and Process for Application Vulnerabilities to its operating object—applications, services, APIs, code, dependencies, build and deployment systems, design invariants, vulnerability reports, tests, and production behavior—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“应用漏洞严重度与发布门槛”连接到其运营对象——应用、服务、API、代码、依赖、构建与部署系统、设计不变量、漏洞报告、测试和生产行为——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-16.6-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "16.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "For Establish and Maintain a Severity Rating System and Process for Application Vulnerabilities, express success as an observable decision over source-to-production software identity, design invariant, component trust, build provenance, test result, deployment state, runtime outcome, and vulnerability response; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“应用漏洞严重度与发布门槛”，以 从源码到生产的软件身份、设计不变量、组件信任、构建来源、测试结果、部署状态、运行结果和漏洞响应 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-16.6-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "16.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "For Establish and Maintain a Severity Rating System and Process for Application Vulnerabilities, express success as an observable decision over affected artifact identity, exploitability, business consequence, remediation choice, deployed fix, compensating control, and residual exposure; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“应用漏洞严重度与发布门槛”，以 受影响制品身份、可利用性、业务后果、修复选择、已部署修复、补偿控制和残余暴露 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-16.6-OUT-08",
          "local_code": "OUT-08",
          "display_code": "O08",
          "safeguard_id": "16.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "For Establish and Maintain a Severity Rating System and Process for Application Vulnerabilities, express success as an observable decision over a documented decision system with policy, process, procedure, accountable owner, approval, and review; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“应用漏洞严重度与发布门槛”，以 包含策略、流程、程序、责任人、审批和复核的文档化决策系统 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-16.6-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "16.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-16.6-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "16.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-16.6-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "16.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-16.6-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "16.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-16.6-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "16.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across generated code, forks, vendoring, transitive and mutable dependencies, build compromise, feature flags, tenant logic, business-logic flaws, secrets, emergency release, and provider components; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 生成代码、分叉、vendoring、传递与可变依赖、构建失陷、功能开关、租户逻辑、业务逻辑缺陷、秘密、紧急发布和提供商组件 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-16.6-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "16.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Include generated and copied code, forks, vendoring, transitive dependencies, mutable tags, build plugins, feature flags, tenant logic, secrets, emergency release, and provider components in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 生成与复制代码、分叉、vendoring、传递依赖、可变标签、构建插件、功能开关、租户逻辑、秘密、紧急发布和提供商组件 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-16.6-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "16.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Include unknown versions, false positives, unavailable fixes, vendor lag, ephemeral workloads, unscannable platforms, inherited dependencies, mitigation-only states, and recurrence in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 未知版本、误报、无可用修复、厂商滞后、短生工作负载、不可扫描平台、继承依赖、仅缓解状态和复发 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-16.6-SCP-08",
          "local_code": "SCP-08",
          "display_code": "P08",
          "safeguard_id": "16.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Include missing policy clauses, conflicting authorities, local deviations, obsolete documentation, and decisions made outside the governed workflow in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 策略条款缺失、权限冲突、本地偏离、文档过期及绕过治理流程的决策 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-16.6-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "16.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-16.6-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "16.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-16.6-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "16.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-16.6-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "16.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-16.6-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "16.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind product and engineering owners, developers, security champions, application security, platform engineering, vulnerability response, architecture, and operations to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 产品与工程责任人、开发者、安全负责人、应用安全、平台工程、漏洞响应、架构和运营 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-16.6-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "16.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Name who may transition designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-16.6-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "16.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Name who may transition discovered → validated → prioritized → assigned → fixed/mitigated/excepted → deployed → retested → closed/reopened, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 发现 → 验证 → 定级 → 分派 → 修复/缓解/例外 → 部署 → 复测 → 关闭/重开，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-16.6-OWN-08",
          "local_code": "OWN-08",
          "display_code": "W08",
          "safeguard_id": "16.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Name who may transition draft → reviewed → approved → effective → exception/withdrawn → superseded, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-16.6-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "16.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-16.6-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "16.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-16.6-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "16.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV48, M1, M2, M3) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV48, M1, M2, M3）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-16.6-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "16.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-16.6-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "16.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the secure-development, component, vulnerability, threat-model, build, release, and exception authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把安全开发、组件、漏洞、威胁模型、构建、发布与例外权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-16.6-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "16.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired.",
          "zh": "对生命周期“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-16.6-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "16.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle discovered → validated → prioritized → assigned → fixed/mitigated/excepted → deployed → retested → closed/reopened.",
          "zh": "对生命周期“发现 → 验证 → 定级 → 分派 → 修复/缓解/例外 → 部署 → 复测 → 关闭/重开”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-16.6-DAT-08",
          "local_code": "DAT-08",
          "display_code": "D08",
          "safeguard_id": "16.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle draft → reviewed → approved → effective → exception/withdrawn → superseded.",
          "zh": "对生命周期“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-16.6-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "16.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 16.2; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 16.2 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-16.6-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "16.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-16.6-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "16.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-16.6-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "16.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-16.6-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "16.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile repositories, issue trackers, CI/CD, artifact registries, SBOMs, dependency sources, architecture models, scanners, tests, reports, deployments, and runtime telemetry and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 代码库、问题系统、CI/CD、制品库、SBOM、依赖来源、架构模型、扫描器、测试、报告、部署和运行遥测，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-16.6-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "16.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Require every connector carrying source-to-production software identity, design invariant, component trust, build provenance, test result, deployment state, runtime outcome, and vulnerability response to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 从源码到生产的软件身份、设计不变量、组件信任、构建来源、测试结果、部署状态、运行结果和漏洞响应 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-16.6-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "16.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Require every connector carrying affected artifact identity, exploitability, business consequence, remediation choice, deployed fix, compensating control, and residual exposure to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 受影响制品身份、可利用性、业务后果、修复选择、已部署修复、补偿控制和残余暴露 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-16.6-INT-08",
          "local_code": "INT-08",
          "display_code": "I08",
          "safeguard_id": "16.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Require every connector carrying a documented decision system with policy, process, procedure, accountable owner, approval, and review to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 包含策略、流程、程序、责任人、审批和复核的文档化决策系统 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-16.6-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "16.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Create consistent severity/risk criteria, triage authority, SLOs, minimum release acceptability, exception/expiry and escalation.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“制定一致严重度/风险标准、分诊权、SLO、最低发布可接受度、例外/到期和升级；校准扫描器分数，覆盖需证据，每年及重大事件/威胁/模型变化时更新。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-16.6-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "16.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-16.6-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "16.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-16.6-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "16.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-16.6-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "16.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the secure-development, component, vulnerability, threat-model, build, release, and exception authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在安全开发、组件、漏洞、威胁模型、构建、发布与例外权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-16.6-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "16.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Implement the explicit state machine designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-16.6-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "16.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Implement the explicit state machine discovered → validated → prioritized → assigned → fixed/mitigated/excepted → deployed → retested → closed/reopened; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“发现 → 验证 → 定级 → 分派 → 修复/缓解/例外 → 部署 → 复测 → 关闭/重开”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-16.6-CTL-08",
          "local_code": "CTL-08",
          "display_code": "C08",
          "safeguard_id": "16.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Implement the explicit state machine draft → reviewed → approved → effective → exception/withdrawn → superseded; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-16.6-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "16.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (annually); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（annually）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-16.6-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "16.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-16.6-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "16.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-16.6-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "16.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-16.6-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "16.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in applications, services, APIs, code, dependencies, build and deployment systems, design invariants, vulnerability reports, tests, and production behavior; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 应用、服务、API、代码、依赖、构建与部署系统、设计不变量、漏洞报告、测试和生产行为 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-16.6-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "16.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; alert before each deadline becomes overdue.",
          "zh": "为“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-16.6-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "16.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for discovered → validated → prioritized → assigned → fixed/mitigated/excepted → deployed → retested → closed/reopened; alert before each deadline becomes overdue.",
          "zh": "为“发现 → 验证 → 定级 → 分派 → 修复/缓解/例外 → 部署 → 复测 → 关闭/重开”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-16.6-TIM-08",
          "local_code": "TIM-08",
          "display_code": "T08",
          "safeguard_id": "16.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for draft → reviewed → approved → effective → exception/withdrawn → superseded; alert before each deadline becomes overdue.",
          "zh": "为“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-16.6-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "16.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “CVSS alone lacks business and architecture context; lowering severity to ship is not risk treatment.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“CVSS 没有业务/架构上下文；为上线降分不是风险处置。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-16.6-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "16.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-16.6-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "16.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-16.6-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "16.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-16.6-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "16.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat generated code, forks, vendoring, transitive and mutable dependencies, build compromise, feature flags, tenant logic, business-logic flaws, secrets, emergency release, and provider components as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 生成代码、分叉、vendoring、传递与可变依赖、构建失陷、功能开关、租户逻辑、业务逻辑缺陷、秘密、紧急发布和提供商组件 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-16.6-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "16.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Treat generated and copied code, forks, vendoring, transitive dependencies, mutable tags, build plugins, feature flags, tenant logic, secrets, emergency release, and provider components as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 生成与复制代码、分叉、vendoring、传递依赖、可变标签、构建插件、功能开关、租户逻辑、秘密、紧急发布和提供商组件 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-16.6-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "16.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Treat unknown versions, false positives, unavailable fixes, vendor lag, ephemeral workloads, unscannable platforms, inherited dependencies, mitigation-only states, and recurrence as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 未知版本、误报、无可用修复、厂商滞后、短生工作负载、不可扫描平台、继承依赖、仅缓解状态和复发 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-16.6-EXC-08",
          "local_code": "EXC-08",
          "display_code": "X08",
          "safeguard_id": "16.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Treat missing policy clauses, conflicting authorities, local deviations, obsolete documentation, and decisions made outside the governed workflow as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 策略条款缺失、权限冲突、本地偏离、文档过期及绕过治理流程的决策 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-16.6-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "16.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Give multiple reviewers representative standalone, chained and context-changing findings and compare decisions.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“给多名评审者独立、串链和上下文改变的代表发现，比较决定；测试含 Gate 级问题和将到期例外的发布，验证阻断、批准、部署跟踪和后续修复。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-16.6-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "16.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-16.6-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "16.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 4 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、4 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-16.6-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "16.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-16.6-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "16.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the secure-development, component, vulnerability, threat-model, build, release, and exception authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以安全开发、组件、漏洞、威胁模型、构建、发布与例外权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-16.6-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "16.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Publish reviewed, unreviewed, reproducible, provenance-bound, vulnerable, test-failed, exception, deployed-unverified, drifted, rolled-back, and regression-protected releases with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已评审、未评审、可复现、来源绑定、存在漏洞、测试失败、例外、已部署未验证、漂移、已回滚和受回归保护发布物，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-16.6-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "16.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Publish open, validated, false-positive, overdue, mitigated, excepted, deployed-unverified, retest-failed, reopened, and exposure-weighted findings with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 开放、已验证、误报、逾期、已缓解、例外、已部署未验证、复测失败、重开和暴露加权发现，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-16.6-EVD-08",
          "local_code": "EVD-08",
          "display_code": "E08",
          "safeguard_id": "16.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Publish clause coverage, owner and reviewer completeness, approval age, triggered reviews, deviations, overdue actions, and superseded versions still in use with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 条款覆盖、责任人与复核人完整性、批准年龄、触发式复核、偏离、逾期行动及仍在使用的旧版本，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-16.6-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "16.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-16.6-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "16.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-16.6-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "16.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-16.6-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "16.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-16.6-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "16.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the secure-development, component, vulnerability, threat-model, build, release, and exception authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护安全开发、组件、漏洞、威胁模型、构建、发布与例外权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-16.6-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "16.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Restrict authority to change designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-16.6-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "16.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Restrict authority to change discovered → validated → prioritized → assigned → fixed/mitigated/excepted → deployed → retested → closed/reopened; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“发现 → 验证 → 定级 → 分派 → 修复/缓解/例外 → 部署 → 复测 → 关闭/重开”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-16.6-SEC-08",
          "local_code": "SEC-08",
          "display_code": "S08",
          "safeguard_id": "16.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Restrict authority to change draft → reviewed → approved → effective → exception/withdrawn → superseded; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-16.6-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "16.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-16.6-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "16.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-16.6-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "16.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-16.6-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "16.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-16.6-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "16.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise secure and insecure design paths, trusted and substituted components, accepted and rejected reports, code-level controls, authenticated abuse, build provenance, rollback, and regression through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 安全与不安全设计路径、可信与被替换组件、接受与拒绝报告、代码级控制、认证后滥用、构建来源、回滚和回归，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-16.6-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "16.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Run the positive control a trusted build that preserves the security invariant through deployment and runtime; exercise negative, stale, duplicate, bypass, and outage controls including a substituted dependency, unreviewed change, poisoned build input, failed security test, bypass path, vulnerable release, rollback, and regression.",
          "zh": "运行正向控制“一个把安全不变量贯穿部署与运行的可信构建”，并执行包含“依赖替换、未评审变更、构建输入污染、安全测试失败、绕过路径、漏洞发布、回滚和回归”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-16.6-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "16.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Run the positive control a known vulnerable artifact repaired and independently retested; exercise negative, stale, duplicate, bypass, and outage controls including credential failure, wrong version match, unavailable fix, mitigation bypass, failed deployment, rollback, recurring finding, and exposed unowned asset.",
          "zh": "运行正向控制“一项已知漏洞制品完成修复并独立复测”，并执行包含“凭据失败、版本误配、无可用修复、缓解绕过、部署失败、回滚、问题复发和外露无主资产”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-16.6-TST-08",
          "local_code": "TST-08",
          "display_code": "V08",
          "safeguard_id": "16.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Run the positive control an approved current process used for a representative decision; exercise negative, stale, duplicate, bypass, and outage controls including an obsolete version, missing approver, undocumented deviation, overdue review, and bypassed workflow.",
          "zh": "运行正向控制“使用当前获批流程完成一项代表性决策”，并执行包含“旧版本、审批人缺失、未记录偏离、逾期复核和绕过流程”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-16.6-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "16.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-16.6-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "16.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-16.6-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "16.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-16.6-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "16.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-16.6-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "16.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever repositories, issue trackers, CI/CD, artifact registries, SBOMs, dependency sources, architecture models, scanners, tests, reports, deployments, and runtime telemetry change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 代码库、问题系统、CI/CD、制品库、SBOM、依赖来源、架构模型、扫描器、测试、报告、部署和运行遥测 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-16.6-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "16.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Use reviewed, unreviewed, reproducible, provenance-bound, vulnerable, test-failed, exception, deployed-unverified, drifted, rolled-back, and regression-protected releases to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已评审、未评审、可复现、来源绑定、存在漏洞、测试失败、例外、已部署未验证、漂移、已回滚和受回归保护发布物 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-16.6-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "16.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Use open, validated, false-positive, overdue, mitigated, excepted, deployed-unverified, retest-failed, reopened, and exposure-weighted findings to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 开放、已验证、误报、逾期、已缓解、例外、已部署未验证、复测失败、重开和暴露加权发现 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-16.6-OPS-08",
          "local_code": "OPS-08",
          "display_code": "R08",
          "safeguard_id": "16.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Use clause coverage, owner and reviewer completeness, approval age, triggered reviews, deviations, overdue actions, and superseded versions still in use to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 条款覆盖、责任人与复核人完整性、批准年龄、触发式复核、偏离、逾期行动及仍在使用的旧版本 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "16.7",
      "control": 16,
      "title_en": "Use Standard Hardening Configuration Templates for Application Infrastructure",
      "title_zh": "应用基础设施硬化模板",
      "first_ig": 2,
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Software",
      "security_function": "Protect",
      "patterns": [
        "software_dev"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "4.1",
          "4.2"
        ],
        "variables": [
          "GV1",
          "GV37",
          "GV50",
          "M1",
          "M2",
          "M3"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "Scope servers, web/app/database platforms, containers, orchestration, PaaS and tenant-configurable SaaS components supporting each application.",
          "build": "Use versioned, tested templates from authoritative hardening guidance, deploy through images/IaC/policy, add application-specific deltas and prevent drift in CI/CD and runtime.",
          "proof": "Build and deploy a representative stack, scan effective settings, exercise business functions and inject application configuration that weakens a baseline control.",
          "boundary": "CAS inputs only asset and network standards, omitting application/software baseline context."
        },
        "zh": {
          "scope": "覆盖支撑应用的服务器、Web/App/DB 平台、容器、编排、PaaS 和租户可配置 SaaS；应用不能在 Base Image 合规后又重新打开不安全端口、账户、权限或设置。",
          "build": "用权威加固的版本化测试模板，经镜像/IaC/策略部署，叠加应用特定 Delta，在 CI/CD 和运行时防漂移；固定服务/版本/Profile，尽量把 SaaS 设置与共享责任也变成代码/证据。",
          "proof": "构建部署代表 Stack，扫描有效设置，跑业务并注入会削弱基线的应用配置，验证发布拒绝或显式例外与运行漂移修复；把组件与模板对账。",
          "boundary": "CAS 只用资产和网络标准输入，漏应用/软件基线上下文。"
        }
      },
      "category_counts": {
        "outcome": 6,
        "scope": 6,
        "ownership": 6,
        "data": 6,
        "integration": 6,
        "control": 6,
        "timing": 6,
        "exception": 6,
        "evidence": 6,
        "security": 6,
        "testing": 6,
        "operations": 6
      },
      "requirement_count": 72,
      "requirements": [
        {
          "code": "CIS-16.7-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "16.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Use Standard Hardening Configuration Templates for Application Infrastructure; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“应用基础设施硬化模板”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-16.7-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "16.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 16.7, official Asset Class Software, Security Function Protect, and IG2 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 16.7、官方资产类别“软件”、安全功能“保护”和首次出现的 IG2，并保存来源抓取日期。"
        },
        {
          "code": "CIS-16.7-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "16.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Scope servers, web/app/database platforms, containers, orchestration, PaaS and tenant-configurable SaaS components supporting each application.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“覆盖支撑应用的服务器、Web/App/DB 平台、容器、编排、PaaS 和租户可配置 SaaS；应用不能在 Base Image 合规后又重新打开不安全端口、账户、权限或设置。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-16.7-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "16.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-16.7-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "16.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Use Standard Hardening Configuration Templates for Application Infrastructure to its operating object—applications, services, APIs, code, dependencies, build and deployment systems, design invariants, vulnerability reports, tests, and production behavior—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“应用基础设施硬化模板”连接到其运营对象——应用、服务、API、代码、依赖、构建与部署系统、设计不变量、漏洞报告、测试和生产行为——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-16.7-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "16.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "For Use Standard Hardening Configuration Templates for Application Infrastructure, express success as an observable decision over source-to-production software identity, design invariant, component trust, build provenance, test result, deployment state, runtime outcome, and vulnerability response; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“应用基础设施硬化模板”，以 从源码到生产的软件身份、设计不变量、组件信任、构建来源、测试结果、部署状态、运行结果和漏洞响应 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-16.7-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "16.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-16.7-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "16.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-16.7-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "16.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-16.7-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "16.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-16.7-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "16.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across generated code, forks, vendoring, transitive and mutable dependencies, build compromise, feature flags, tenant logic, business-logic flaws, secrets, emergency release, and provider components; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 生成代码、分叉、vendoring、传递与可变依赖、构建失陷、功能开关、租户逻辑、业务逻辑缺陷、秘密、紧急发布和提供商组件 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-16.7-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "16.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Include generated and copied code, forks, vendoring, transitive dependencies, mutable tags, build plugins, feature flags, tenant logic, secrets, emergency release, and provider components in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 生成与复制代码、分叉、vendoring、传递依赖、可变标签、构建插件、功能开关、租户逻辑、秘密、紧急发布和提供商组件 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-16.7-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "16.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-16.7-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "16.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-16.7-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "16.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-16.7-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "16.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-16.7-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "16.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind product and engineering owners, developers, security champions, application security, platform engineering, vulnerability response, architecture, and operations to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 产品与工程责任人、开发者、安全负责人、应用安全、平台工程、漏洞响应、架构和运营 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-16.7-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "16.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Name who may transition designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-16.7-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "16.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-16.7-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "16.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-16.7-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "16.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV1, GV37, GV50, M1, M2, M3) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV1, GV37, GV50, M1, M2, M3）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-16.7-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "16.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-16.7-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "16.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the secure-development, component, vulnerability, threat-model, build, release, and exception authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把安全开发、组件、漏洞、威胁模型、构建、发布与例外权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-16.7-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "16.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired.",
          "zh": "对生命周期“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-16.7-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "16.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 4.1, Safeguard 4.2; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 4.1、Safeguard 4.2 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-16.7-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "16.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-16.7-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "16.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-16.7-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "16.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-16.7-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "16.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile repositories, issue trackers, CI/CD, artifact registries, SBOMs, dependency sources, architecture models, scanners, tests, reports, deployments, and runtime telemetry and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 代码库、问题系统、CI/CD、制品库、SBOM、依赖来源、架构模型、扫描器、测试、报告、部署和运行遥测，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-16.7-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "16.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Require every connector carrying source-to-production software identity, design invariant, component trust, build provenance, test result, deployment state, runtime outcome, and vulnerability response to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 从源码到生产的软件身份、设计不变量、组件信任、构建来源、测试结果、部署状态、运行结果和漏洞响应 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-16.7-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "16.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Use versioned, tested templates from authoritative hardening guidance, deploy through images/IaC/policy, add application-specific deltas and prevent drift in CI/CD and runtime.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“用权威加固的版本化测试模板，经镜像/IaC/策略部署，叠加应用特定 Delta，在 CI/CD 和运行时防漂移；固定服务/版本/Profile，尽量把 SaaS 设置与共享责任也变成代码/证据。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-16.7-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "16.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-16.7-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "16.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-16.7-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "16.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-16.7-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "16.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the secure-development, component, vulnerability, threat-model, build, release, and exception authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在安全开发、组件、漏洞、威胁模型、构建、发布与例外权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-16.7-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "16.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Implement the explicit state machine designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-16.7-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "16.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-16.7-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "16.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-16.7-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "16.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-16.7-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "16.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-16.7-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "16.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in applications, services, APIs, code, dependencies, build and deployment systems, design invariants, vulnerability reports, tests, and production behavior; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 应用、服务、API、代码、依赖、构建与部署系统、设计不变量、漏洞报告、测试和生产行为 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-16.7-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "16.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; alert before each deadline becomes overdue.",
          "zh": "为“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-16.7-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "16.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “CAS inputs only asset and network standards, omitting application/software baseline context.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“CAS 只用资产和网络标准输入，漏应用/软件基线上下文。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-16.7-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "16.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-16.7-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "16.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-16.7-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "16.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-16.7-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "16.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat generated code, forks, vendoring, transitive and mutable dependencies, build compromise, feature flags, tenant logic, business-logic flaws, secrets, emergency release, and provider components as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 生成代码、分叉、vendoring、传递与可变依赖、构建失陷、功能开关、租户逻辑、业务逻辑缺陷、秘密、紧急发布和提供商组件 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-16.7-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "16.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Treat generated and copied code, forks, vendoring, transitive dependencies, mutable tags, build plugins, feature flags, tenant logic, secrets, emergency release, and provider components as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 生成与复制代码、分叉、vendoring、传递依赖、可变标签、构建插件、功能开关、租户逻辑、秘密、紧急发布和提供商组件 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-16.7-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "16.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Build and deploy a representative stack, scan effective settings, exercise business functions and inject application configuration that weakens a baseline control.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“构建部署代表 Stack，扫描有效设置，跑业务并注入会削弱基线的应用配置，验证发布拒绝或显式例外与运行漂移修复；把组件与模板对账。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-16.7-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "16.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-16.7-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "16.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 6 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、6 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-16.7-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "16.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-16.7-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "16.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the secure-development, component, vulnerability, threat-model, build, release, and exception authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以安全开发、组件、漏洞、威胁模型、构建、发布与例外权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-16.7-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "16.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Publish reviewed, unreviewed, reproducible, provenance-bound, vulnerable, test-failed, exception, deployed-unverified, drifted, rolled-back, and regression-protected releases with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已评审、未评审、可复现、来源绑定、存在漏洞、测试失败、例外、已部署未验证、漂移、已回滚和受回归保护发布物，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-16.7-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "16.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-16.7-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "16.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-16.7-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "16.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-16.7-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "16.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-16.7-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "16.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the secure-development, component, vulnerability, threat-model, build, release, and exception authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护安全开发、组件、漏洞、威胁模型、构建、发布与例外权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-16.7-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "16.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Restrict authority to change designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-16.7-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "16.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-16.7-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "16.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-16.7-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "16.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-16.7-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "16.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-16.7-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "16.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise secure and insecure design paths, trusted and substituted components, accepted and rejected reports, code-level controls, authenticated abuse, build provenance, rollback, and regression through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 安全与不安全设计路径、可信与被替换组件、接受与拒绝报告、代码级控制、认证后滥用、构建来源、回滚和回归，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-16.7-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "16.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Run the positive control a trusted build that preserves the security invariant through deployment and runtime; exercise negative, stale, duplicate, bypass, and outage controls including a substituted dependency, unreviewed change, poisoned build input, failed security test, bypass path, vulnerable release, rollback, and regression.",
          "zh": "运行正向控制“一个把安全不变量贯穿部署与运行的可信构建”，并执行包含“依赖替换、未评审变更、构建输入污染、安全测试失败、绕过路径、漏洞发布、回滚和回归”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-16.7-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "16.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-16.7-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "16.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-16.7-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "16.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-16.7-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "16.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-16.7-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "16.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever repositories, issue trackers, CI/CD, artifact registries, SBOMs, dependency sources, architecture models, scanners, tests, reports, deployments, and runtime telemetry change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 代码库、问题系统、CI/CD、制品库、SBOM、依赖来源、架构模型、扫描器、测试、报告、部署和运行遥测 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-16.7-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "16.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Use reviewed, unreviewed, reproducible, provenance-bound, vulnerable, test-failed, exception, deployed-unverified, drifted, rolled-back, and regression-protected releases to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已评审、未评审、可复现、来源绑定、存在漏洞、测试失败、例外、已部署未验证、漂移、已回滚和受回归保护发布物 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "16.8",
      "control": 16,
      "title_en": "Separate Production and Non-Production Systems",
      "title_zh": "生产与非生产隔离",
      "first_ig": 2,
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Network",
      "security_function": "Protect",
      "patterns": [
        "software_dev",
        "enforcement"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [],
        "variables": [
          "GV1",
          "M1",
          "M2",
          "M3"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "Separation covers identities, accounts/projects, networks, data, keys/secrets, CI/CD authority, monitoring and administration between production and development/test.",
          "build": "Use separate accounts/tenants/clusters and credentials, controlled artifact promotion, least production access, synthetic/masked test data and explicit one-way deployment.",
          "proof": "Attempt production access with a developer/test identity and secret, push an unsigned/unapproved artifact, and move test/production data across boundaries.",
          "boundary": "CAS merely counts production systems with a non-production counterpart and its metric text reverses the population; it does not test separation."
        },
        "zh": {
          "scope": "分离覆盖生产与开发/测试的身份、账号/项目、网络、数据、密钥/秘密、CI/CD 权力、监测和管理。",
          "build": "使用独立账号/租户/集群和凭据，受控制品晋级，最小生产访问，合成/脱敏测试数据和单向部署；禁止生产秘密/数据进低环境，禁止非生产系统管理生产。",
          "proof": "用开发/测试身份和秘密尝试生产访问，推未签名/未批准制品，跨边界搬测试/生产数据，验证拒绝/审计且批准晋级/诊断正常；检查共享 Runner、Registry、备份与监测。",
          "boundary": "CAS 只数“生产有没有非生产对应”，指标文字还反了，并未测试分离。"
        }
      },
      "category_counts": {
        "outcome": 7,
        "scope": 7,
        "ownership": 7,
        "data": 7,
        "integration": 7,
        "control": 7,
        "timing": 7,
        "exception": 7,
        "evidence": 7,
        "security": 7,
        "testing": 7,
        "operations": 7
      },
      "requirement_count": 84,
      "requirements": [
        {
          "code": "CIS-16.8-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "16.8",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Separate Production and Non-Production Systems; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“生产与非生产隔离”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-16.8-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "16.8",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 16.8, official Asset Class Network, Security Function Protect, and IG2 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 16.8、官方资产类别“网络”、安全功能“保护”和首次出现的 IG2，并保存来源抓取日期。"
        },
        {
          "code": "CIS-16.8-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "16.8",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Separation covers identities, accounts/projects, networks, data, keys/secrets, CI/CD authority, monitoring and administration between production and development/test.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“分离覆盖生产与开发/测试的身份、账号/项目、网络、数据、密钥/秘密、CI/CD 权力、监测和管理。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-16.8-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "16.8",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-16.8-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "16.8",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Separate Production and Non-Production Systems to its operating object—applications, services, APIs, code, dependencies, build and deployment systems, design invariants, vulnerability reports, tests, and production behavior—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“生产与非生产隔离”连接到其运营对象——应用、服务、API、代码、依赖、构建与部署系统、设计不变量、漏洞报告、测试和生产行为——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-16.8-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "16.8",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "For Separate Production and Non-Production Systems, express success as an observable decision over source-to-production software identity, design invariant, component trust, build provenance, test result, deployment state, runtime outcome, and vulnerability response; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“生产与非生产隔离”，以 从源码到生产的软件身份、设计不变量、组件信任、构建来源、测试结果、部署状态、运行结果和漏洞响应 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-16.8-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "16.8",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "For Separate Production and Non-Production Systems, express success as an observable decision over an enforceable allow, deny, contain, quarantine, require, remove, or transform decision at the closest reliable control point; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“生产与非生产隔离”，以 在最近可靠控制点执行允许、拒绝、遏制、隔离、强制、移除或转换决策 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-16.8-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "16.8",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-16.8-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "16.8",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-16.8-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "16.8",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-16.8-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "16.8",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-16.8-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "16.8",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across generated code, forks, vendoring, transitive and mutable dependencies, build compromise, feature flags, tenant logic, business-logic flaws, secrets, emergency release, and provider components; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 生成代码、分叉、vendoring、传递与可变依赖、构建失陷、功能开关、租户逻辑、业务逻辑缺陷、秘密、紧急发布和提供商组件 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-16.8-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "16.8",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Include generated and copied code, forks, vendoring, transitive dependencies, mutable tags, build plugins, feature flags, tenant logic, secrets, emergency release, and provider components in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 生成与复制代码、分叉、vendoring、传递依赖、可变标签、构建插件、功能开关、租户逻辑、秘密、紧急发布和提供商组件 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-16.8-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "16.8",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Include audit-only mode, unsupported platforms, local overrides, race conditions, cached state, alternate paths, fail-open behavior, and emergency bypass in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 仅审计模式、不支持平台、本地覆盖、竞态、缓存状态、替代路径、故障开放和紧急绕过 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-16.8-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "16.8",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-16.8-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "16.8",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-16.8-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "16.8",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-16.8-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "16.8",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-16.8-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "16.8",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind product and engineering owners, developers, security champions, application security, platform engineering, vulnerability response, architecture, and operations to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 产品与工程责任人、开发者、安全负责人、应用安全、平台工程、漏洞响应、架构和运营 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-16.8-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "16.8",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Name who may transition designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-16.8-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "16.8",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Name who may transition observe → evaluate → decide → enforce → verify outcome → rollback/close, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-16.8-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "16.8",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-16.8-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "16.8",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-16.8-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "16.8",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV1, M1, M2, M3) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV1, M1, M2, M3）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-16.8-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "16.8",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-16.8-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "16.8",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the secure-development, component, vulnerability, threat-model, build, release, and exception authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把安全开发、组件、漏洞、威胁模型、构建、发布与例外权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-16.8-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "16.8",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired.",
          "zh": "对生命周期“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-16.8-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "16.8",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle observe → evaluate → decide → enforce → verify outcome → rollback/close.",
          "zh": "对生命周期“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-16.8-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "16.8",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for no explicit predecessor in the pinned CAS page; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 固定 CAS 页面没有列出显式前置项 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-16.8-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "16.8",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-16.8-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "16.8",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-16.8-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "16.8",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-16.8-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "16.8",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile repositories, issue trackers, CI/CD, artifact registries, SBOMs, dependency sources, architecture models, scanners, tests, reports, deployments, and runtime telemetry and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 代码库、问题系统、CI/CD、制品库、SBOM、依赖来源、架构模型、扫描器、测试、报告、部署和运行遥测，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-16.8-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "16.8",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Require every connector carrying source-to-production software identity, design invariant, component trust, build provenance, test result, deployment state, runtime outcome, and vulnerability response to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 从源码到生产的软件身份、设计不变量、组件信任、构建来源、测试结果、部署状态、运行结果和漏洞响应 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-16.8-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "16.8",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Require every connector carrying an enforceable allow, deny, contain, quarantine, require, remove, or transform decision at the closest reliable control point to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 在最近可靠控制点执行允许、拒绝、遏制、隔离、强制、移除或转换决策 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-16.8-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "16.8",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Use separate accounts/tenants/clusters and credentials, controlled artifact promotion, least production access, synthetic/masked test data and explicit one-way deployment.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“使用独立账号/租户/集群和凭据，受控制品晋级，最小生产访问，合成/脱敏测试数据和单向部署；禁止生产秘密/数据进低环境，禁止非生产系统管理生产。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-16.8-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "16.8",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-16.8-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "16.8",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-16.8-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "16.8",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-16.8-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "16.8",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the secure-development, component, vulnerability, threat-model, build, release, and exception authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在安全开发、组件、漏洞、威胁模型、构建、发布与例外权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-16.8-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "16.8",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Implement the explicit state machine designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-16.8-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "16.8",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Implement the explicit state machine observe → evaluate → decide → enforce → verify outcome → rollback/close; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-16.8-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "16.8",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-16.8-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "16.8",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-16.8-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "16.8",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-16.8-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "16.8",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-16.8-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "16.8",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in applications, services, APIs, code, dependencies, build and deployment systems, design invariants, vulnerability reports, tests, and production behavior; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 应用、服务、API、代码、依赖、构建与部署系统、设计不变量、漏洞报告、测试和生产行为 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-16.8-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "16.8",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; alert before each deadline becomes overdue.",
          "zh": "为“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-16.8-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "16.8",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for observe → evaluate → decide → enforce → verify outcome → rollback/close; alert before each deadline becomes overdue.",
          "zh": "为“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-16.8-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "16.8",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “CAS merely counts production systems with a non-production counterpart and its metric text reverses the population; it does not test separation.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“CAS 只数“生产有没有非生产对应”，指标文字还反了，并未测试分离。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-16.8-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "16.8",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-16.8-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "16.8",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-16.8-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "16.8",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-16.8-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "16.8",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat generated code, forks, vendoring, transitive and mutable dependencies, build compromise, feature flags, tenant logic, business-logic flaws, secrets, emergency release, and provider components as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 生成代码、分叉、vendoring、传递与可变依赖、构建失陷、功能开关、租户逻辑、业务逻辑缺陷、秘密、紧急发布和提供商组件 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-16.8-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "16.8",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Treat generated and copied code, forks, vendoring, transitive dependencies, mutable tags, build plugins, feature flags, tenant logic, secrets, emergency release, and provider components as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 生成与复制代码、分叉、vendoring、传递依赖、可变标签、构建插件、功能开关、租户逻辑、秘密、紧急发布和提供商组件 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-16.8-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "16.8",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Treat audit-only mode, unsupported platforms, local overrides, race conditions, cached state, alternate paths, fail-open behavior, and emergency bypass as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 仅审计模式、不支持平台、本地覆盖、竞态、缓存状态、替代路径、故障开放和紧急绕过 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-16.8-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "16.8",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Attempt production access with a developer/test identity and secret, push an unsigned/unapproved artifact, and move test/production data across boundaries.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“用开发/测试身份和秘密尝试生产访问，推未签名/未批准制品，跨边界搬测试/生产数据，验证拒绝/审计且批准晋级/诊断正常；检查共享 Runner、Registry、备份与监测。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-16.8-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "16.8",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-16.8-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "16.8",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 4 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、4 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-16.8-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "16.8",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-16.8-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "16.8",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the secure-development, component, vulnerability, threat-model, build, release, and exception authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以安全开发、组件、漏洞、威胁模型、构建、发布与例外权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-16.8-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "16.8",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Publish reviewed, unreviewed, reproducible, provenance-bound, vulnerable, test-failed, exception, deployed-unverified, drifted, rolled-back, and regression-protected releases with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已评审、未评审、可复现、来源绑定、存在漏洞、测试失败、例外、已部署未验证、漂移、已回滚和受回归保护发布物，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-16.8-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "16.8",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Publish eligible, enforcing, audit-only, failed, bypassed, excepted, rolled-back, and outcome-verified populations with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 适用、已执行、仅审计、失败、被绕过、例外、已回滚和结果已验证总体，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-16.8-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "16.8",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-16.8-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "16.8",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-16.8-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "16.8",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-16.8-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "16.8",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-16.8-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "16.8",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the secure-development, component, vulnerability, threat-model, build, release, and exception authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护安全开发、组件、漏洞、威胁模型、构建、发布与例外权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-16.8-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "16.8",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Restrict authority to change designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-16.8-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "16.8",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Restrict authority to change observe → evaluate → decide → enforce → verify outcome → rollback/close; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“观察 → 评估 → 决策 → 执行 → 验证结果 → 回滚/关闭”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-16.8-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "16.8",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-16.8-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "16.8",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-16.8-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "16.8",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-16.8-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "16.8",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-16.8-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "16.8",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise secure and insecure design paths, trusted and substituted components, accepted and rejected reports, code-level controls, authenticated abuse, build provenance, rollback, and regression through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 安全与不安全设计路径、可信与被替换组件、接受与拒绝报告、代码级控制、认证后滥用、构建来源、回滚和回归，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-16.8-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "16.8",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Run the positive control a trusted build that preserves the security invariant through deployment and runtime; exercise negative, stale, duplicate, bypass, and outage controls including a substituted dependency, unreviewed change, poisoned build input, failed security test, bypass path, vulnerable release, rollback, and regression.",
          "zh": "运行正向控制“一个把安全不变量贯穿部署与运行的可信构建”，并执行包含“依赖替换、未评审变更、构建输入污染、安全测试失败、绕过路径、漏洞发布、回滚和回归”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-16.8-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "16.8",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Run the positive control an approved business action that completes through the enforced path; exercise negative, stale, duplicate, bypass, and outage controls including a prohibited action, alternate path, local override, stale policy, control outage, emergency bypass, and rollback failure.",
          "zh": "运行正向控制“通过受控路径完成的一项获批业务动作”，并执行包含“禁止动作、替代路径、本地覆盖、陈旧策略、控制中断、紧急绕过和回滚失败”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-16.8-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "16.8",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-16.8-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "16.8",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-16.8-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "16.8",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-16.8-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "16.8",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-16.8-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "16.8",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever repositories, issue trackers, CI/CD, artifact registries, SBOMs, dependency sources, architecture models, scanners, tests, reports, deployments, and runtime telemetry change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 代码库、问题系统、CI/CD、制品库、SBOM、依赖来源、架构模型、扫描器、测试、报告、部署和运行遥测 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-16.8-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "16.8",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Use reviewed, unreviewed, reproducible, provenance-bound, vulnerable, test-failed, exception, deployed-unverified, drifted, rolled-back, and regression-protected releases to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已评审、未评审、可复现、来源绑定、存在漏洞、测试失败、例外、已部署未验证、漂移、已回滚和受回归保护发布物 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-16.8-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "16.8",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original enforcement pattern analysis",
          "basis_zh": "SOSEC 原创 enforcement 模式分析",
          "en": "Use eligible, enforcing, audit-only, failed, bypassed, excepted, rolled-back, and outcome-verified populations to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 适用、已执行、仅审计、失败、被绕过、例外、已回滚和结果已验证总体 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "16.9",
      "control": 16,
      "title_en": "Train Developers in Application Security Concepts and Secure Coding",
      "title_zh": "开发人员安全技能",
      "first_ig": 2,
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Users",
      "security_function": "Protect",
      "patterns": [
        "software_dev",
        "training"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [],
        "variables": [
          "M1",
          "M2",
          "M3",
          "M4",
          "M5"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [
        "annually",
        "at least annually"
      ],
      "implementation_contract": {
        "en": {
          "scope": "The population includes developers, testers, architects, DevOps/SRE, data/ML and low-code builders according to languages, frameworks, platforms, roles and product risks.",
          "build": "Map role/environment to secure design, coding, dependency, secrets, testing and response skills; train at least annually and on major platform change using local examples and labs.",
          "proof": "Use practical tasks such as fixing authz, injection, secret, dependency or cloud-policy flaws in the actual stack, and review subsequent code outcomes.",
          "boundary": "Training cannot compensate for unsafe frameworks, impossible deadlines or missing review."
        },
        "zh": {
          "scope": "包括开发、测试、架构、DevOps/SRE、数据/ML 和低代码人员，按语言、框架、平台、职责和产品风险配课；一年一次通用 OWASP 课不能让人掌握陌生本地栈。",
          "build": "把角色/环境映射安全设计、编码、依赖、秘密、测试与响应技能，至少每年和平台大变时训练，用本地案例/实验；提供安全库、Reviewer 和 Just-in-time 指导，使知识能落地。",
          "proof": "在真实技术栈做授权、注入、秘密、依赖或云策略修复实操，并看后续代码结果；把人员/角色与当前训练对账，含承包商，发现能力缺口就补而非只数出席。",
          "boundary": "培训补不了危险 Framework、不可能期限和缺失评审。"
        }
      },
      "category_counts": {
        "outcome": 7,
        "scope": 7,
        "ownership": 7,
        "data": 7,
        "integration": 7,
        "control": 7,
        "timing": 7,
        "exception": 7,
        "evidence": 7,
        "security": 7,
        "testing": 7,
        "operations": 7
      },
      "requirement_count": 84,
      "requirements": [
        {
          "code": "CIS-16.9-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "16.9",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Train Developers in Application Security Concepts and Secure Coding; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“开发人员安全技能”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-16.9-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "16.9",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 16.9, official Asset Class Users, Security Function Protect, and IG2 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 16.9、官方资产类别“用户与身份”、安全功能“保护”和首次出现的 IG2，并保存来源抓取日期。"
        },
        {
          "code": "CIS-16.9-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "16.9",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “The population includes developers, testers, architects, DevOps/SRE, data/ML and low-code builders according to languages, frameworks, platforms, roles and product risks.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“包括开发、测试、架构、DevOps/SRE、数据/ML 和低代码人员，按语言、框架、平台、职责和产品风险配课；一年一次通用 OWASP 课不能让人掌握陌生本地栈。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-16.9-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "16.9",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-16.9-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "16.9",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Train Developers in Application Security Concepts and Secure Coding to its operating object—applications, services, APIs, code, dependencies, build and deployment systems, design invariants, vulnerability reports, tests, and production behavior—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“开发人员安全技能”连接到其运营对象——应用、服务、API、代码、依赖、构建与部署系统、设计不变量、漏洞报告、测试和生产行为——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-16.9-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "16.9",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "For Train Developers in Application Security Concepts and Secure Coding, express success as an observable decision over source-to-production software identity, design invariant, component trust, build provenance, test result, deployment state, runtime outcome, and vulnerability response; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“开发人员安全技能”，以 从源码到生产的软件身份、设计不变量、组件信任、构建来源、测试结果、部署状态、运行结果和漏洞响应 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-16.9-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "16.9",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "For Train Developers in Application Security Concepts and Secure Coding, express success as an observable decision over role-specific knowledge, practiced decision, reporting behavior, measurable comprehension, and retraining outcome; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“开发人员安全技能”，以 岗位相关知识、练习过的决策、报告行为、可测理解和再培训结果 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-16.9-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "16.9",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-16.9-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "16.9",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-16.9-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "16.9",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-16.9-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "16.9",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-16.9-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "16.9",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across generated code, forks, vendoring, transitive and mutable dependencies, build compromise, feature flags, tenant logic, business-logic flaws, secrets, emergency release, and provider components; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 生成代码、分叉、vendoring、传递与可变依赖、构建失陷、功能开关、租户逻辑、业务逻辑缺陷、秘密、紧急发布和提供商组件 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-16.9-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "16.9",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Include generated and copied code, forks, vendoring, transitive dependencies, mutable tags, build plugins, feature flags, tenant logic, secrets, emergency release, and provider components in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 生成与复制代码、分叉、vendoring、传递依赖、可变标签、构建插件、功能开关、租户逻辑、秘密、紧急发布和提供商组件 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-16.9-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "16.9",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Include new hires, contractors, temporary and privileged roles, role changes, accessibility and language needs, absence, remote work, simulation harm, and completion without comprehension in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 新员工、承包商、临时与特权角色、角色变化、无障碍和语言需求、缺席、远程工作、模拟伤害及完成却未理解 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-16.9-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "16.9",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-16.9-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "16.9",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-16.9-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "16.9",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-16.9-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "16.9",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-16.9-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "16.9",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind product and engineering owners, developers, security champions, application security, platform engineering, vulnerability response, architecture, and operations to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 产品与工程责任人、开发者、安全负责人、应用安全、平台工程、漏洞响应、架构和运营 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-16.9-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "16.9",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Name who may transition designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-16.9-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "16.9",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Name who may transition need identified → objective and scenario designed → assigned → practiced/assessed → remediated → behavior reviewed → content renewed, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 识别需要 → 设计目标与情境 → 分配 → 练习/评估 → 补救 → 复核行为 → 更新内容，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-16.9-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "16.9",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-16.9-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "16.9",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-16.9-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "16.9",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (M1, M2, M3, M4, M5) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（M1, M2, M3, M4, M5）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-16.9-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "16.9",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-16.9-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "16.9",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the secure-development, component, vulnerability, threat-model, build, release, and exception authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把安全开发、组件、漏洞、威胁模型、构建、发布与例外权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-16.9-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "16.9",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired.",
          "zh": "对生命周期“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-16.9-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "16.9",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle need identified → objective and scenario designed → assigned → practiced/assessed → remediated → behavior reviewed → content renewed.",
          "zh": "对生命周期“识别需要 → 设计目标与情境 → 分配 → 练习/评估 → 补救 → 复核行为 → 更新内容”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-16.9-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "16.9",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for no explicit predecessor in the pinned CAS page; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 固定 CAS 页面没有列出显式前置项 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-16.9-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "16.9",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-16.9-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "16.9",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-16.9-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "16.9",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-16.9-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "16.9",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile repositories, issue trackers, CI/CD, artifact registries, SBOMs, dependency sources, architecture models, scanners, tests, reports, deployments, and runtime telemetry and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 代码库、问题系统、CI/CD、制品库、SBOM、依赖来源、架构模型、扫描器、测试、报告、部署和运行遥测，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-16.9-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "16.9",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Require every connector carrying source-to-production software identity, design invariant, component trust, build provenance, test result, deployment state, runtime outcome, and vulnerability response to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 从源码到生产的软件身份、设计不变量、组件信任、构建来源、测试结果、部署状态、运行结果和漏洞响应 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-16.9-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "16.9",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Require every connector carrying role-specific knowledge, practiced decision, reporting behavior, measurable comprehension, and retraining outcome to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 岗位相关知识、练习过的决策、报告行为、可测理解和再培训结果 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-16.9-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "16.9",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Map role/environment to secure design, coding, dependency, secrets, testing and response skills; train at least annually and on major platform change using local examples and labs.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“把角色/环境映射安全设计、编码、依赖、秘密、测试与响应技能，至少每年和平台大变时训练，用本地案例/实验；提供安全库、Reviewer 和 Just-in-time 指导，使知识能落地。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-16.9-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "16.9",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-16.9-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "16.9",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-16.9-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "16.9",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-16.9-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "16.9",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the secure-development, component, vulnerability, threat-model, build, release, and exception authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在安全开发、组件、漏洞、威胁模型、构建、发布与例外权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-16.9-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "16.9",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Implement the explicit state machine designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-16.9-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "16.9",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Implement the explicit state machine need identified → objective and scenario designed → assigned → practiced/assessed → remediated → behavior reviewed → content renewed; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“识别需要 → 设计目标与情境 → 分配 → 练习/评估 → 补救 → 复核行为 → 更新内容”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-16.9-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "16.9",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (annually, at least annually); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（annually, at least annually）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-16.9-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "16.9",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-16.9-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "16.9",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-16.9-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "16.9",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-16.9-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "16.9",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in applications, services, APIs, code, dependencies, build and deployment systems, design invariants, vulnerability reports, tests, and production behavior; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 应用、服务、API、代码、依赖、构建与部署系统、设计不变量、漏洞报告、测试和生产行为 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-16.9-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "16.9",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; alert before each deadline becomes overdue.",
          "zh": "为“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-16.9-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "16.9",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for need identified → objective and scenario designed → assigned → practiced/assessed → remediated → behavior reviewed → content renewed; alert before each deadline becomes overdue.",
          "zh": "为“识别需要 → 设计目标与情境 → 分配 → 练习/评估 → 补救 → 复核行为 → 更新内容”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-16.9-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "16.9",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “Training cannot compensate for unsafe frameworks, impossible deadlines or missing review.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“培训补不了危险 Framework、不可能期限和缺失评审。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-16.9-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "16.9",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-16.9-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "16.9",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-16.9-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "16.9",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-16.9-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "16.9",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat generated code, forks, vendoring, transitive and mutable dependencies, build compromise, feature flags, tenant logic, business-logic flaws, secrets, emergency release, and provider components as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 生成代码、分叉、vendoring、传递与可变依赖、构建失陷、功能开关、租户逻辑、业务逻辑缺陷、秘密、紧急发布和提供商组件 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-16.9-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "16.9",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Treat generated and copied code, forks, vendoring, transitive dependencies, mutable tags, build plugins, feature flags, tenant logic, secrets, emergency release, and provider components as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 生成与复制代码、分叉、vendoring、传递依赖、可变标签、构建插件、功能开关、租户逻辑、秘密、紧急发布和提供商组件 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-16.9-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "16.9",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Treat new hires, contractors, temporary and privileged roles, role changes, accessibility and language needs, absence, remote work, simulation harm, and completion without comprehension as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 新员工、承包商、临时与特权角色、角色变化、无障碍和语言需求、缺席、远程工作、模拟伤害及完成却未理解 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-16.9-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "16.9",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Use practical tasks such as fixing authz, injection, secret, dependency or cloud-policy flaws in the actual stack, and review subsequent code outcomes.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“在真实技术栈做授权、注入、秘密、依赖或云策略修复实操，并看后续代码结果；把人员/角色与当前训练对账，含承包商，发现能力缺口就补而非只数出席。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-16.9-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "16.9",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-16.9-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "16.9",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 5 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、5 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-16.9-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "16.9",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-16.9-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "16.9",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the secure-development, component, vulnerability, threat-model, build, release, and exception authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以安全开发、组件、漏洞、威胁模型、构建、发布与例外权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-16.9-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "16.9",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Publish reviewed, unreviewed, reproducible, provenance-bound, vulnerable, test-failed, exception, deployed-unverified, drifted, rolled-back, and regression-protected releases with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已评审、未评审、可复现、来源绑定、存在漏洞、测试失败、例外、已部署未验证、漂移、已回滚和受回归保护发布物，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-16.9-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "16.9",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Publish assigned, started, completed, passed, failed, overdue, exempted, role-mismatched, retrained, reported, and behavior-improved learners with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已分配、已开始、已完成、通过、失败、逾期、豁免、岗位不匹配、再培训、已报告和行为改善人员，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-16.9-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "16.9",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-16.9-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "16.9",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-16.9-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "16.9",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-16.9-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "16.9",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-16.9-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "16.9",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the secure-development, component, vulnerability, threat-model, build, release, and exception authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护安全开发、组件、漏洞、威胁模型、构建、发布与例外权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-16.9-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "16.9",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Restrict authority to change designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-16.9-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "16.9",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Restrict authority to change need identified → objective and scenario designed → assigned → practiced/assessed → remediated → behavior reviewed → content renewed; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“识别需要 → 设计目标与情境 → 分配 → 练习/评估 → 补救 → 复核行为 → 更新内容”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-16.9-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "16.9",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-16.9-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "16.9",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-16.9-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "16.9",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-16.9-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "16.9",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-16.9-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "16.9",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise secure and insecure design paths, trusted and substituted components, accepted and rejected reports, code-level controls, authenticated abuse, build provenance, rollback, and regression through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 安全与不安全设计路径、可信与被替换组件、接受与拒绝报告、代码级控制、认证后滥用、构建来源、回滚和回归，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-16.9-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "16.9",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Run the positive control a trusted build that preserves the security invariant through deployment and runtime; exercise negative, stale, duplicate, bypass, and outage controls including a substituted dependency, unreviewed change, poisoned build input, failed security test, bypass path, vulnerable release, rollback, and regression.",
          "zh": "运行正向控制“一个把安全不变量贯穿部署与运行的可信构建”，并执行包含“依赖替换、未评审变更、构建输入污染、安全测试失败、绕过路径、漏洞发布、回滚和回归”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-16.9-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "16.9",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Run the positive control a representative learner making and reporting the secure decision in a realistic scenario; exercise negative, stale, duplicate, bypass, and outage controls including a missed assignment, incorrect decision, inaccessible content, stale scenario, role mismatch, failed report channel, and ineffective retraining.",
          "zh": "运行正向控制“代表性人员在真实情境中作出并报告安全决策”，并执行包含“漏分配、错误决策、内容不可访问、情境陈旧、岗位不匹配、报告通道失败和再培训无效”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-16.9-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "16.9",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-16.9-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "16.9",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-16.9-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "16.9",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-16.9-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "16.9",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-16.9-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "16.9",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever repositories, issue trackers, CI/CD, artifact registries, SBOMs, dependency sources, architecture models, scanners, tests, reports, deployments, and runtime telemetry change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 代码库、问题系统、CI/CD、制品库、SBOM、依赖来源、架构模型、扫描器、测试、报告、部署和运行遥测 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-16.9-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "16.9",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Use reviewed, unreviewed, reproducible, provenance-bound, vulnerable, test-failed, exception, deployed-unverified, drifted, rolled-back, and regression-protected releases to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已评审、未评审、可复现、来源绑定、存在漏洞、测试失败、例外、已部署未验证、漂移、已回滚和受回归保护发布物 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-16.9-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "16.9",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Use assigned, started, completed, passed, failed, overdue, exempted, role-mismatched, retrained, reported, and behavior-improved learners to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已分配、已开始、已完成、通过、失败、逾期、豁免、岗位不匹配、再培训、已报告和行为改善人员 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "16.10",
      "control": 16,
      "title_en": "Apply Secure Design Principles in Application Architectures",
      "title_zh": "安全设计原则",
      "first_ig": 2,
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Software",
      "security_function": "Protect",
      "patterns": [
        "software_dev",
        "governance"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "16.1"
        ],
        "variables": [
          "GV49",
          "GV50",
          "M1",
          "M2",
          "M3",
          "M4"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "Apply least privilege, complete mediation, deny-by-default, trust-boundary validation, safe failure, separation, minimization and attack-surface reduction to application architecture and every sensitive operation.",
          "build": "Record security invariants and trust/data flows, centralize authorization at each object/action, validate size/type/range/state, design abuse limits and failure modes, remove unnecessary interfaces and review material design changes before code.",
          "proof": "Test allowed and denied actions at API, object, tenant, workflow and alternate paths; fuzz/state-test inputs and fail dependencies to observe safe behavior.",
          "boundary": "CAS counts application infrastructure components said to apply principles, an unverifiable unit."
        },
        "zh": {
          "scope": "把最小权限、完全中介、默认拒绝、信任边界校验、安全失败、职责分离、最小化和攻击面缩减应用到架构和每个敏感操作。",
          "build": "记录安全不变量和信任/数据流，在每个对象/动作做授权，校验大小/类型/范围/状态，设计滥用限制与故障模式，去掉无必要接口，并在编码前审重大设计；威胁模型连接测试/遥测。",
          "proof": "在 API、对象、租户、流程和替代路径测试允许/拒绝，Fuzz/状态测试输入并故障依赖观察安全行为；抽样高风险操作须追到不变量、强制点、负测和告警。",
          "boundary": "CAS 数“应用基础组件应用了原则”，单位无法验证。"
        }
      },
      "category_counts": {
        "outcome": 7,
        "scope": 7,
        "ownership": 7,
        "data": 7,
        "integration": 7,
        "control": 7,
        "timing": 7,
        "exception": 7,
        "evidence": 7,
        "security": 7,
        "testing": 7,
        "operations": 7
      },
      "requirement_count": 84,
      "requirements": [
        {
          "code": "CIS-16.10-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "16.10",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Apply Secure Design Principles in Application Architectures; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“安全设计原则”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-16.10-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "16.10",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 16.10, official Asset Class Software, Security Function Protect, and IG2 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 16.10、官方资产类别“软件”、安全功能“保护”和首次出现的 IG2，并保存来源抓取日期。"
        },
        {
          "code": "CIS-16.10-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "16.10",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Apply least privilege, complete mediation, deny-by-default, trust-boundary validation, safe failure, separation, minimization and attack-surface reduction to application architecture and every sensitive operation.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“把最小权限、完全中介、默认拒绝、信任边界校验、安全失败、职责分离、最小化和攻击面缩减应用到架构和每个敏感操作。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-16.10-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "16.10",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-16.10-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "16.10",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Apply Secure Design Principles in Application Architectures to its operating object—applications, services, APIs, code, dependencies, build and deployment systems, design invariants, vulnerability reports, tests, and production behavior—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“安全设计原则”连接到其运营对象——应用、服务、API、代码、依赖、构建与部署系统、设计不变量、漏洞报告、测试和生产行为——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-16.10-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "16.10",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "For Apply Secure Design Principles in Application Architectures, express success as an observable decision over source-to-production software identity, design invariant, component trust, build provenance, test result, deployment state, runtime outcome, and vulnerability response; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“安全设计原则”，以 从源码到生产的软件身份、设计不变量、组件信任、构建来源、测试结果、部署状态、运行结果和漏洞响应 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-16.10-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "16.10",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "For Apply Secure Design Principles in Application Architectures, express success as an observable decision over a documented decision system with policy, process, procedure, accountable owner, approval, and review; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“安全设计原则”，以 包含策略、流程、程序、责任人、审批和复核的文档化决策系统 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-16.10-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "16.10",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-16.10-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "16.10",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-16.10-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "16.10",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-16.10-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "16.10",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-16.10-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "16.10",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across generated code, forks, vendoring, transitive and mutable dependencies, build compromise, feature flags, tenant logic, business-logic flaws, secrets, emergency release, and provider components; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 生成代码、分叉、vendoring、传递与可变依赖、构建失陷、功能开关、租户逻辑、业务逻辑缺陷、秘密、紧急发布和提供商组件 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-16.10-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "16.10",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Include generated and copied code, forks, vendoring, transitive dependencies, mutable tags, build plugins, feature flags, tenant logic, secrets, emergency release, and provider components in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 生成与复制代码、分叉、vendoring、传递依赖、可变标签、构建插件、功能开关、租户逻辑、秘密、紧急发布和提供商组件 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-16.10-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "16.10",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Include missing policy clauses, conflicting authorities, local deviations, obsolete documentation, and decisions made outside the governed workflow in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 策略条款缺失、权限冲突、本地偏离、文档过期及绕过治理流程的决策 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-16.10-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "16.10",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-16.10-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "16.10",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-16.10-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "16.10",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-16.10-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "16.10",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-16.10-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "16.10",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind product and engineering owners, developers, security champions, application security, platform engineering, vulnerability response, architecture, and operations to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 产品与工程责任人、开发者、安全负责人、应用安全、平台工程、漏洞响应、架构和运营 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-16.10-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "16.10",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Name who may transition designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-16.10-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "16.10",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Name who may transition draft → reviewed → approved → effective → exception/withdrawn → superseded, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-16.10-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "16.10",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-16.10-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "16.10",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-16.10-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "16.10",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV49, GV50, M1, M2, M3, M4) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV49, GV50, M1, M2, M3, M4）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-16.10-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "16.10",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-16.10-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "16.10",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the secure-development, component, vulnerability, threat-model, build, release, and exception authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把安全开发、组件、漏洞、威胁模型、构建、发布与例外权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-16.10-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "16.10",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired.",
          "zh": "对生命周期“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-16.10-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "16.10",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle draft → reviewed → approved → effective → exception/withdrawn → superseded.",
          "zh": "对生命周期“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-16.10-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "16.10",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 16.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 16.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-16.10-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "16.10",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-16.10-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "16.10",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-16.10-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "16.10",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-16.10-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "16.10",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile repositories, issue trackers, CI/CD, artifact registries, SBOMs, dependency sources, architecture models, scanners, tests, reports, deployments, and runtime telemetry and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 代码库、问题系统、CI/CD、制品库、SBOM、依赖来源、架构模型、扫描器、测试、报告、部署和运行遥测，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-16.10-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "16.10",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Require every connector carrying source-to-production software identity, design invariant, component trust, build provenance, test result, deployment state, runtime outcome, and vulnerability response to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 从源码到生产的软件身份、设计不变量、组件信任、构建来源、测试结果、部署状态、运行结果和漏洞响应 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-16.10-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "16.10",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Require every connector carrying a documented decision system with policy, process, procedure, accountable owner, approval, and review to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 包含策略、流程、程序、责任人、审批和复核的文档化决策系统 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-16.10-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "16.10",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Record security invariants and trust/data flows, centralize authorization at each object/action, validate size/type/range/state, design abuse limits and failure modes, remove unnecessary interfaces and review material design changes before code.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“记录安全不变量和信任/数据流，在每个对象/动作做授权，校验大小/类型/范围/状态，设计滥用限制与故障模式，去掉无必要接口，并在编码前审重大设计；威胁模型连接测试/遥测。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-16.10-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "16.10",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-16.10-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "16.10",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-16.10-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "16.10",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-16.10-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "16.10",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the secure-development, component, vulnerability, threat-model, build, release, and exception authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在安全开发、组件、漏洞、威胁模型、构建、发布与例外权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-16.10-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "16.10",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Implement the explicit state machine designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-16.10-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "16.10",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Implement the explicit state machine draft → reviewed → approved → effective → exception/withdrawn → superseded; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-16.10-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "16.10",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-16.10-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "16.10",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-16.10-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "16.10",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-16.10-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "16.10",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-16.10-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "16.10",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in applications, services, APIs, code, dependencies, build and deployment systems, design invariants, vulnerability reports, tests, and production behavior; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 应用、服务、API、代码、依赖、构建与部署系统、设计不变量、漏洞报告、测试和生产行为 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-16.10-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "16.10",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; alert before each deadline becomes overdue.",
          "zh": "为“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-16.10-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "16.10",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for draft → reviewed → approved → effective → exception/withdrawn → superseded; alert before each deadline becomes overdue.",
          "zh": "为“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-16.10-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "16.10",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “CAS counts application infrastructure components said to apply principles, an unverifiable unit.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“CAS 数“应用基础组件应用了原则”，单位无法验证。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-16.10-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "16.10",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-16.10-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "16.10",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-16.10-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "16.10",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-16.10-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "16.10",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat generated code, forks, vendoring, transitive and mutable dependencies, build compromise, feature flags, tenant logic, business-logic flaws, secrets, emergency release, and provider components as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 生成代码、分叉、vendoring、传递与可变依赖、构建失陷、功能开关、租户逻辑、业务逻辑缺陷、秘密、紧急发布和提供商组件 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-16.10-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "16.10",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Treat generated and copied code, forks, vendoring, transitive dependencies, mutable tags, build plugins, feature flags, tenant logic, secrets, emergency release, and provider components as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 生成与复制代码、分叉、vendoring、传递依赖、可变标签、构建插件、功能开关、租户逻辑、秘密、紧急发布和提供商组件 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-16.10-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "16.10",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Treat missing policy clauses, conflicting authorities, local deviations, obsolete documentation, and decisions made outside the governed workflow as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 策略条款缺失、权限冲突、本地偏离、文档过期及绕过治理流程的决策 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-16.10-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "16.10",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Test allowed and denied actions at API, object, tenant, workflow and alternate paths; fuzz/state-test inputs and fail dependencies to observe safe behavior.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“在 API、对象、租户、流程和替代路径测试允许/拒绝，Fuzz/状态测试输入并故障依赖观察安全行为；抽样高风险操作须追到不变量、强制点、负测和告警。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-16.10-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "16.10",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-16.10-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "16.10",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 6 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、6 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-16.10-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "16.10",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-16.10-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "16.10",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the secure-development, component, vulnerability, threat-model, build, release, and exception authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以安全开发、组件、漏洞、威胁模型、构建、发布与例外权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-16.10-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "16.10",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Publish reviewed, unreviewed, reproducible, provenance-bound, vulnerable, test-failed, exception, deployed-unverified, drifted, rolled-back, and regression-protected releases with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已评审、未评审、可复现、来源绑定、存在漏洞、测试失败、例外、已部署未验证、漂移、已回滚和受回归保护发布物，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-16.10-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "16.10",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Publish clause coverage, owner and reviewer completeness, approval age, triggered reviews, deviations, overdue actions, and superseded versions still in use with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 条款覆盖、责任人与复核人完整性、批准年龄、触发式复核、偏离、逾期行动及仍在使用的旧版本，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-16.10-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "16.10",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-16.10-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "16.10",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-16.10-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "16.10",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-16.10-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "16.10",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-16.10-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "16.10",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the secure-development, component, vulnerability, threat-model, build, release, and exception authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护安全开发、组件、漏洞、威胁模型、构建、发布与例外权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-16.10-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "16.10",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Restrict authority to change designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-16.10-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "16.10",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Restrict authority to change draft → reviewed → approved → effective → exception/withdrawn → superseded; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-16.10-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "16.10",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-16.10-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "16.10",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-16.10-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "16.10",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-16.10-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "16.10",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-16.10-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "16.10",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise secure and insecure design paths, trusted and substituted components, accepted and rejected reports, code-level controls, authenticated abuse, build provenance, rollback, and regression through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 安全与不安全设计路径、可信与被替换组件、接受与拒绝报告、代码级控制、认证后滥用、构建来源、回滚和回归，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-16.10-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "16.10",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Run the positive control a trusted build that preserves the security invariant through deployment and runtime; exercise negative, stale, duplicate, bypass, and outage controls including a substituted dependency, unreviewed change, poisoned build input, failed security test, bypass path, vulnerable release, rollback, and regression.",
          "zh": "运行正向控制“一个把安全不变量贯穿部署与运行的可信构建”，并执行包含“依赖替换、未评审变更、构建输入污染、安全测试失败、绕过路径、漏洞发布、回滚和回归”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-16.10-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "16.10",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Run the positive control an approved current process used for a representative decision; exercise negative, stale, duplicate, bypass, and outage controls including an obsolete version, missing approver, undocumented deviation, overdue review, and bypassed workflow.",
          "zh": "运行正向控制“使用当前获批流程完成一项代表性决策”，并执行包含“旧版本、审批人缺失、未记录偏离、逾期复核和绕过流程”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-16.10-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "16.10",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-16.10-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "16.10",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-16.10-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "16.10",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-16.10-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "16.10",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-16.10-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "16.10",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever repositories, issue trackers, CI/CD, artifact registries, SBOMs, dependency sources, architecture models, scanners, tests, reports, deployments, and runtime telemetry change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 代码库、问题系统、CI/CD、制品库、SBOM、依赖来源、架构模型、扫描器、测试、报告、部署和运行遥测 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-16.10-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "16.10",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Use reviewed, unreviewed, reproducible, provenance-bound, vulnerable, test-failed, exception, deployed-unverified, drifted, rolled-back, and regression-protected releases to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已评审、未评审、可复现、来源绑定、存在漏洞、测试失败、例外、已部署未验证、漂移、已回滚和受回归保护发布物 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-16.10-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "16.10",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Use clause coverage, owner and reviewer completeness, approval age, triggered reviews, deviations, overdue actions, and superseded versions still in use to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 条款覆盖、责任人与复核人完整性、批准年龄、触发式复核、偏离、逾期行动及仍在使用的旧版本 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "16.11",
      "control": 16,
      "title_en": "Leverage Vetted Modules or Services for Application Security Components",
      "title_zh": "采用审查过的安全模块",
      "first_ig": 2,
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Software",
      "security_function": "Protect",
      "patterns": [
        "software_dev"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "2.1"
        ],
        "variables": [
          "GV5",
          "M1",
          "M2",
          "M3",
          "M4",
          "M5"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "Scope security-critical functions such as identity, authorization, cryptography, secrets, session, validation, logging, payments and updates.",
          "build": "Default to mature maintained modules/services, pin and configure safely, review source/provider and threat assumptions, wrap them through a paved interface and prohibit ad-hoc cryptography/auth.",
          "proof": "Inventory security components and identify custom logic, then exercise algorithm/config downgrade, key/session misuse, authorization bypass and logging failure around the vetted module.",
          "boundary": "“Vetted” is contextual and can age or be misconfigured."
        },
        "zh": {
          "scope": "包括身份、授权、加密、秘密、会话、校验、日志、支付和更新等安全关键功能；选型比较审查过的标准/平台服务与自研，并记录继承的保证和配置。",
          "build": "默认用成熟维护模块/服务，固定且安全配置，审来源/服务商和威胁假设，经 Paved Interface 封装，禁止随手自创加密/认证；确需自研则专家设计审查、测试和维护责任。",
          "proof": "清点安全组件/自研逻辑，测试算法/配置降级、密钥/会话误用、授权绕过和日志故障；验证版本/来源和应用胶水没有破坏模块保证。",
          "boundary": "“Vetted”有上下文且会过时/误配。"
        }
      },
      "category_counts": {
        "outcome": 6,
        "scope": 6,
        "ownership": 6,
        "data": 6,
        "integration": 6,
        "control": 6,
        "timing": 6,
        "exception": 6,
        "evidence": 6,
        "security": 6,
        "testing": 6,
        "operations": 6
      },
      "requirement_count": 72,
      "requirements": [
        {
          "code": "CIS-16.11-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "16.11",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Leverage Vetted Modules or Services for Application Security Components; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“采用审查过的安全模块”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-16.11-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "16.11",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 16.11, official Asset Class Software, Security Function Protect, and IG2 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 16.11、官方资产类别“软件”、安全功能“保护”和首次出现的 IG2，并保存来源抓取日期。"
        },
        {
          "code": "CIS-16.11-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "16.11",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Scope security-critical functions such as identity, authorization, cryptography, secrets, session, validation, logging, payments and updates.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“包括身份、授权、加密、秘密、会话、校验、日志、支付和更新等安全关键功能；选型比较审查过的标准/平台服务与自研，并记录继承的保证和配置。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-16.11-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "16.11",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-16.11-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "16.11",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Leverage Vetted Modules or Services for Application Security Components to its operating object—applications, services, APIs, code, dependencies, build and deployment systems, design invariants, vulnerability reports, tests, and production behavior—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“采用审查过的安全模块”连接到其运营对象——应用、服务、API、代码、依赖、构建与部署系统、设计不变量、漏洞报告、测试和生产行为——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-16.11-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "16.11",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "For Leverage Vetted Modules or Services for Application Security Components, express success as an observable decision over source-to-production software identity, design invariant, component trust, build provenance, test result, deployment state, runtime outcome, and vulnerability response; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“采用审查过的安全模块”，以 从源码到生产的软件身份、设计不变量、组件信任、构建来源、测试结果、部署状态、运行结果和漏洞响应 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-16.11-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "16.11",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-16.11-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "16.11",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-16.11-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "16.11",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-16.11-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "16.11",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-16.11-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "16.11",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across generated code, forks, vendoring, transitive and mutable dependencies, build compromise, feature flags, tenant logic, business-logic flaws, secrets, emergency release, and provider components; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 生成代码、分叉、vendoring、传递与可变依赖、构建失陷、功能开关、租户逻辑、业务逻辑缺陷、秘密、紧急发布和提供商组件 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-16.11-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "16.11",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Include generated and copied code, forks, vendoring, transitive dependencies, mutable tags, build plugins, feature flags, tenant logic, secrets, emergency release, and provider components in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 生成与复制代码、分叉、vendoring、传递依赖、可变标签、构建插件、功能开关、租户逻辑、秘密、紧急发布和提供商组件 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-16.11-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "16.11",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-16.11-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "16.11",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-16.11-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "16.11",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-16.11-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "16.11",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-16.11-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "16.11",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind product and engineering owners, developers, security champions, application security, platform engineering, vulnerability response, architecture, and operations to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 产品与工程责任人、开发者、安全负责人、应用安全、平台工程、漏洞响应、架构和运营 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-16.11-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "16.11",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Name who may transition designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-16.11-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "16.11",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-16.11-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "16.11",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-16.11-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "16.11",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV5, M1, M2, M3, M4, M5) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV5, M1, M2, M3, M4, M5）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-16.11-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "16.11",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-16.11-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "16.11",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the secure-development, component, vulnerability, threat-model, build, release, and exception authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把安全开发、组件、漏洞、威胁模型、构建、发布与例外权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-16.11-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "16.11",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired.",
          "zh": "对生命周期“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-16.11-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "16.11",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 2.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 2.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-16.11-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "16.11",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-16.11-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "16.11",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-16.11-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "16.11",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-16.11-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "16.11",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile repositories, issue trackers, CI/CD, artifact registries, SBOMs, dependency sources, architecture models, scanners, tests, reports, deployments, and runtime telemetry and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 代码库、问题系统、CI/CD、制品库、SBOM、依赖来源、架构模型、扫描器、测试、报告、部署和运行遥测，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-16.11-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "16.11",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Require every connector carrying source-to-production software identity, design invariant, component trust, build provenance, test result, deployment state, runtime outcome, and vulnerability response to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 从源码到生产的软件身份、设计不变量、组件信任、构建来源、测试结果、部署状态、运行结果和漏洞响应 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-16.11-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "16.11",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Default to mature maintained modules/services, pin and configure safely, review source/provider and threat assumptions, wrap them through a paved interface and prohibit ad-hoc cryptography/auth.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“默认用成熟维护模块/服务，固定且安全配置，审来源/服务商和威胁假设，经 Paved Interface 封装，禁止随手自创加密/认证；确需自研则专家设计审查、测试和维护责任。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-16.11-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "16.11",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-16.11-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "16.11",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-16.11-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "16.11",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-16.11-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "16.11",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the secure-development, component, vulnerability, threat-model, build, release, and exception authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在安全开发、组件、漏洞、威胁模型、构建、发布与例外权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-16.11-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "16.11",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Implement the explicit state machine designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-16.11-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "16.11",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-16.11-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "16.11",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-16.11-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "16.11",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-16.11-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "16.11",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-16.11-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "16.11",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in applications, services, APIs, code, dependencies, build and deployment systems, design invariants, vulnerability reports, tests, and production behavior; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 应用、服务、API、代码、依赖、构建与部署系统、设计不变量、漏洞报告、测试和生产行为 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-16.11-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "16.11",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; alert before each deadline becomes overdue.",
          "zh": "为“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-16.11-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "16.11",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: ““Vetted” is contextual and can age or be misconfigured.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：““Vetted”有上下文且会过时/误配。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-16.11-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "16.11",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-16.11-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "16.11",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-16.11-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "16.11",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-16.11-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "16.11",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat generated code, forks, vendoring, transitive and mutable dependencies, build compromise, feature flags, tenant logic, business-logic flaws, secrets, emergency release, and provider components as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 生成代码、分叉、vendoring、传递与可变依赖、构建失陷、功能开关、租户逻辑、业务逻辑缺陷、秘密、紧急发布和提供商组件 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-16.11-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "16.11",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Treat generated and copied code, forks, vendoring, transitive dependencies, mutable tags, build plugins, feature flags, tenant logic, secrets, emergency release, and provider components as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 生成与复制代码、分叉、vendoring、传递依赖、可变标签、构建插件、功能开关、租户逻辑、秘密、紧急发布和提供商组件 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-16.11-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "16.11",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Inventory security components and identify custom logic, then exercise algorithm/config downgrade, key/session misuse, authorization bypass and logging failure around the vetted module.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“清点安全组件/自研逻辑，测试算法/配置降级、密钥/会话误用、授权绕过和日志故障；验证版本/来源和应用胶水没有破坏模块保证。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-16.11-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "16.11",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-16.11-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "16.11",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 6 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、6 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-16.11-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "16.11",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-16.11-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "16.11",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the secure-development, component, vulnerability, threat-model, build, release, and exception authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以安全开发、组件、漏洞、威胁模型、构建、发布与例外权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-16.11-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "16.11",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Publish reviewed, unreviewed, reproducible, provenance-bound, vulnerable, test-failed, exception, deployed-unverified, drifted, rolled-back, and regression-protected releases with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已评审、未评审、可复现、来源绑定、存在漏洞、测试失败、例外、已部署未验证、漂移、已回滚和受回归保护发布物，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-16.11-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "16.11",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-16.11-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "16.11",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-16.11-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "16.11",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-16.11-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "16.11",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-16.11-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "16.11",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the secure-development, component, vulnerability, threat-model, build, release, and exception authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护安全开发、组件、漏洞、威胁模型、构建、发布与例外权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-16.11-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "16.11",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Restrict authority to change designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-16.11-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "16.11",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-16.11-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "16.11",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-16.11-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "16.11",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-16.11-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "16.11",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-16.11-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "16.11",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise secure and insecure design paths, trusted and substituted components, accepted and rejected reports, code-level controls, authenticated abuse, build provenance, rollback, and regression through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 安全与不安全设计路径、可信与被替换组件、接受与拒绝报告、代码级控制、认证后滥用、构建来源、回滚和回归，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-16.11-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "16.11",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Run the positive control a trusted build that preserves the security invariant through deployment and runtime; exercise negative, stale, duplicate, bypass, and outage controls including a substituted dependency, unreviewed change, poisoned build input, failed security test, bypass path, vulnerable release, rollback, and regression.",
          "zh": "运行正向控制“一个把安全不变量贯穿部署与运行的可信构建”，并执行包含“依赖替换、未评审变更、构建输入污染、安全测试失败、绕过路径、漏洞发布、回滚和回归”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-16.11-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "16.11",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-16.11-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "16.11",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-16.11-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "16.11",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-16.11-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "16.11",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-16.11-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "16.11",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever repositories, issue trackers, CI/CD, artifact registries, SBOMs, dependency sources, architecture models, scanners, tests, reports, deployments, and runtime telemetry change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 代码库、问题系统、CI/CD、制品库、SBOM、依赖来源、架构模型、扫描器、测试、报告、部署和运行遥测 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-16.11-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "16.11",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Use reviewed, unreviewed, reproducible, provenance-bound, vulnerable, test-failed, exception, deployed-unverified, drifted, rolled-back, and regression-protected releases to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已评审、未评审、可复现、来源绑定、存在漏洞、测试失败、例外、已部署未验证、漂移、已回滚和受回归保护发布物 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "16.12",
      "control": 16,
      "title_en": "Implement Code-Level Security Checks",
      "title_zh": "代码级安全检查",
      "first_ig": 3,
      "implementation_groups": [
        3
      ],
      "asset_class": "Software",
      "security_function": "Protect",
      "patterns": [
        "software_dev",
        "adversarial"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "2.1"
        ],
        "variables": [
          "GV5",
          "M1",
          "M2",
          "M3",
          "M4",
          "M5"
        ],
        "metric_branches": 2,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "The testing portfolio covers source, bytecode/binary, dependencies, infrastructure code, APIs and running application behavior according to language and architecture.",
          "build": "Run fast checks on changes and deeper SAST/DAST/IAST/fuzz/secret/dependency tests in CI/CD or controlled environments, tune rules, protect baselines and gate by verified risk.",
          "proof": "Seed safe known flaws and clean controls for each tool/class, verify detection, triage, gate and fix/retest.",
          "boundary": "Tools cannot prove absence and may miss runtime generation, business logic or unreachable context."
        },
        "zh": {
          "scope": "测试组合覆盖源码、字节码/二进制、依赖、IaC、API 和运行行为，按语言/架构选择；生成代码、低代码和配置需适当等效物，SAST 与 DAST 看不同缺陷。",
          "build": "变更时跑快速检查，CI/CD 或受控环境跑更深 SAST/DAST/IAST/Fuzz/秘密/依赖，调规则、保护 Baseline，并按已验证风险 Gate；动态测试要有认证、覆盖 API/角色，抑制和工具健康受管。",
          "proof": "为每工具/类别植入安全已知缺陷和干净对照，验证发现、分诊、Gate 和修复/复测；指标看合格仓库/发布和可执行路径是否用当前规则实测，还要有误报/漏报控制。",
          "boundary": "工具不能证明不存在，也会漏运行生成、业务逻辑或上下文不可达。"
        }
      },
      "category_counts": {
        "outcome": 7,
        "scope": 7,
        "ownership": 7,
        "data": 7,
        "integration": 7,
        "control": 7,
        "timing": 7,
        "exception": 7,
        "evidence": 7,
        "security": 7,
        "testing": 7,
        "operations": 7
      },
      "requirement_count": 84,
      "requirements": [
        {
          "code": "CIS-16.12-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "16.12",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Implement Code-Level Security Checks; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“代码级安全检查”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-16.12-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "16.12",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 16.12, official Asset Class Software, Security Function Protect, and IG3 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 16.12、官方资产类别“软件”、安全功能“保护”和首次出现的 IG3，并保存来源抓取日期。"
        },
        {
          "code": "CIS-16.12-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "16.12",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “The testing portfolio covers source, bytecode/binary, dependencies, infrastructure code, APIs and running application behavior according to language and architecture.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“测试组合覆盖源码、字节码/二进制、依赖、IaC、API 和运行行为，按语言/架构选择；生成代码、低代码和配置需适当等效物，SAST 与 DAST 看不同缺陷。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-16.12-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "16.12",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-16.12-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "16.12",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Implement Code-Level Security Checks to its operating object—applications, services, APIs, code, dependencies, build and deployment systems, design invariants, vulnerability reports, tests, and production behavior—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“代码级安全检查”连接到其运营对象——应用、服务、API、代码、依赖、构建与部署系统、设计不变量、漏洞报告、测试和生产行为——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-16.12-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "16.12",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "For Implement Code-Level Security Checks, express success as an observable decision over source-to-production software identity, design invariant, component trust, build provenance, test result, deployment state, runtime outcome, and vulnerability response; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“代码级安全检查”，以 从源码到生产的软件身份、设计不变量、组件信任、构建来源、测试结果、部署状态、运行结果和漏洞响应 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-16.12-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "16.12",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "For Implement Code-Level Security Checks, express success as an observable decision over authorized attack hypothesis, realistic path, controlled objective, observable defense response, finding, remediation, independent retest, and regression; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“代码级安全检查”，以 授权攻击假设、真实路径、受控目标、可观察防御响应、发现、修复、独立复测和回归 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-16.12-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "16.12",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-16.12-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "16.12",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-16.12-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "16.12",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-16.12-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "16.12",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-16.12-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "16.12",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across generated code, forks, vendoring, transitive and mutable dependencies, build compromise, feature flags, tenant logic, business-logic flaws, secrets, emergency release, and provider components; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 生成代码、分叉、vendoring、传递与可变依赖、构建失陷、功能开关、租户逻辑、业务逻辑缺陷、秘密、紧急发布和提供商组件 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-16.12-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "16.12",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Include generated and copied code, forks, vendoring, transitive dependencies, mutable tags, build plugins, feature flags, tenant logic, secrets, emergency release, and provider components in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 生成与复制代码、分叉、vendoring、传递依赖、可变标签、构建插件、功能开关、租户逻辑、秘密、紧急发布和提供商组件 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-16.12-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "16.12",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Include scope drift, unsafe techniques, shared tenants, third-party systems, production impact, incomplete credentials, newly discovered critical paths, sensitive test data, and undetected activity in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 范围漂移、不安全技术、共享租户、第三方系统、生产影响、凭据不完整、新发现关键路径、敏感测试数据和未检测活动 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-16.12-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "16.12",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-16.12-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "16.12",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-16.12-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "16.12",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-16.12-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "16.12",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-16.12-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "16.12",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind product and engineering owners, developers, security champions, application security, platform engineering, vulnerability response, architecture, and operations to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 产品与工程责任人、开发者、安全负责人、应用安全、平台工程、漏洞响应、架构和运营 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-16.12-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "16.12",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Name who may transition designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-16.12-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "16.12",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Name who may transition authorized → scoped → rehearsed → executed with stop conditions → evidenced → triaged → remediated → independently retested → regression monitored, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 授权 → 定范围 → 预演 → 带停止条件执行 → 取证 → 分流 → 修复 → 独立复测 → 回归监测，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-16.12-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "16.12",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-16.12-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "16.12",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-16.12-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "16.12",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV5, M1, M2, M3, M4, M5) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV5, M1, M2, M3, M4, M5）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-16.12-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "16.12",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-16.12-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "16.12",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the secure-development, component, vulnerability, threat-model, build, release, and exception authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把安全开发、组件、漏洞、威胁模型、构建、发布与例外权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-16.12-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "16.12",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired.",
          "zh": "对生命周期“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-16.12-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "16.12",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle authorized → scoped → rehearsed → executed with stop conditions → evidenced → triaged → remediated → independently retested → regression monitored.",
          "zh": "对生命周期“授权 → 定范围 → 预演 → 带停止条件执行 → 取证 → 分流 → 修复 → 独立复测 → 回归监测”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-16.12-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "16.12",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 2.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 2.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-16.12-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "16.12",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-16.12-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "16.12",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-16.12-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "16.12",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-16.12-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "16.12",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile repositories, issue trackers, CI/CD, artifact registries, SBOMs, dependency sources, architecture models, scanners, tests, reports, deployments, and runtime telemetry and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 代码库、问题系统、CI/CD、制品库、SBOM、依赖来源、架构模型、扫描器、测试、报告、部署和运行遥测，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-16.12-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "16.12",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Require every connector carrying source-to-production software identity, design invariant, component trust, build provenance, test result, deployment state, runtime outcome, and vulnerability response to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 从源码到生产的软件身份、设计不变量、组件信任、构建来源、测试结果、部署状态、运行结果和漏洞响应 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-16.12-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "16.12",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Require every connector carrying authorized attack hypothesis, realistic path, controlled objective, observable defense response, finding, remediation, independent retest, and regression to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 授权攻击假设、真实路径、受控目标、可观察防御响应、发现、修复、独立复测和回归 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-16.12-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "16.12",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Run fast checks on changes and deeper SAST/DAST/IAST/fuzz/secret/dependency tests in CI/CD or controlled environments, tune rules, protect baselines and gate by verified risk.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“变更时跑快速检查，CI/CD 或受控环境跑更深 SAST/DAST/IAST/Fuzz/秘密/依赖，调规则、保护 Baseline，并按已验证风险 Gate；动态测试要有认证、覆盖 API/角色，抑制和工具健康受管。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-16.12-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "16.12",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-16.12-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "16.12",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-16.12-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "16.12",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-16.12-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "16.12",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the secure-development, component, vulnerability, threat-model, build, release, and exception authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在安全开发、组件、漏洞、威胁模型、构建、发布与例外权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-16.12-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "16.12",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Implement the explicit state machine designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-16.12-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "16.12",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Implement the explicit state machine authorized → scoped → rehearsed → executed with stop conditions → evidenced → triaged → remediated → independently retested → regression monitored; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“授权 → 定范围 → 预演 → 带停止条件执行 → 取证 → 分流 → 修复 → 独立复测 → 回归监测”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-16.12-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "16.12",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-16.12-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "16.12",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-16.12-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "16.12",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-16.12-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "16.12",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-16.12-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "16.12",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in applications, services, APIs, code, dependencies, build and deployment systems, design invariants, vulnerability reports, tests, and production behavior; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 应用、服务、API、代码、依赖、构建与部署系统、设计不变量、漏洞报告、测试和生产行为 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-16.12-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "16.12",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; alert before each deadline becomes overdue.",
          "zh": "为“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-16.12-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "16.12",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for authorized → scoped → rehearsed → executed with stop conditions → evidenced → triaged → remediated → independently retested → regression monitored; alert before each deadline becomes overdue.",
          "zh": "为“授权 → 定范围 → 预演 → 带停止条件执行 → 取证 → 分流 → 修复 → 独立复测 → 回归监测”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-16.12-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "16.12",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “Tools cannot prove absence and may miss runtime generation, business logic or unreachable context.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“工具不能证明不存在，也会漏运行生成、业务逻辑或上下文不可达。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-16.12-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "16.12",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-16.12-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "16.12",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-16.12-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "16.12",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-16.12-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "16.12",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat generated code, forks, vendoring, transitive and mutable dependencies, build compromise, feature flags, tenant logic, business-logic flaws, secrets, emergency release, and provider components as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 生成代码、分叉、vendoring、传递与可变依赖、构建失陷、功能开关、租户逻辑、业务逻辑缺陷、秘密、紧急发布和提供商组件 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-16.12-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "16.12",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Treat generated and copied code, forks, vendoring, transitive dependencies, mutable tags, build plugins, feature flags, tenant logic, secrets, emergency release, and provider components as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 生成与复制代码、分叉、vendoring、传递依赖、可变标签、构建插件、功能开关、租户逻辑、秘密、紧急发布和提供商组件 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-16.12-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "16.12",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Treat scope drift, unsafe techniques, shared tenants, third-party systems, production impact, incomplete credentials, newly discovered critical paths, sensitive test data, and undetected activity as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 范围漂移、不安全技术、共享租户、第三方系统、生产影响、凭据不完整、新发现关键路径、敏感测试数据和未检测活动 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-16.12-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "16.12",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Seed safe known flaws and clean controls for each tool/class, verify detection, triage, gate and fix/retest.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“为每工具/类别植入安全已知缺陷和干净对照，验证发现、分诊、Gate 和修复/复测；指标看合格仓库/发布和可执行路径是否用当前规则实测，还要有误报/漏报控制。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-16.12-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "16.12",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-16.12-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "16.12",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 2 pinned CAS metric branch(es), 6 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 2 个指标分支、6 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-16.12-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "16.12",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-16.12-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "16.12",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the secure-development, component, vulnerability, threat-model, build, release, and exception authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以安全开发、组件、漏洞、威胁模型、构建、发布与例外权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-16.12-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "16.12",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Publish reviewed, unreviewed, reproducible, provenance-bound, vulnerable, test-failed, exception, deployed-unverified, drifted, rolled-back, and regression-protected releases with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已评审、未评审、可复现、来源绑定、存在漏洞、测试失败、例外、已部署未验证、漂移、已回滚和受回归保护发布物，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-16.12-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "16.12",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Publish planned, executed, stopped, out-of-scope, prevented, detected, contained, missed, found, fixed, retest-passed, recurrent, and untested attack paths with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 计划、执行、停止、越界、已阻断、已检测、已遏制、漏检、发现、修复、复测通过、复发和未测试攻击路径，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-16.12-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "16.12",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-16.12-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "16.12",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-16.12-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "16.12",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-16.12-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "16.12",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-16.12-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "16.12",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the secure-development, component, vulnerability, threat-model, build, release, and exception authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护安全开发、组件、漏洞、威胁模型、构建、发布与例外权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-16.12-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "16.12",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Restrict authority to change designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-16.12-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "16.12",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Restrict authority to change authorized → scoped → rehearsed → executed with stop conditions → evidenced → triaged → remediated → independently retested → regression monitored; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“授权 → 定范围 → 预演 → 带停止条件执行 → 取证 → 分流 → 修复 → 独立复测 → 回归监测”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-16.12-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "16.12",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-16.12-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "16.12",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-16.12-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "16.12",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-16.12-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "16.12",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-16.12-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "16.12",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise secure and insecure design paths, trusted and substituted components, accepted and rejected reports, code-level controls, authenticated abuse, build provenance, rollback, and regression through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 安全与不安全设计路径、可信与被替换组件、接受与拒绝报告、代码级控制、认证后滥用、构建来源、回滚和回归，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-16.12-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "16.12",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Run the positive control a trusted build that preserves the security invariant through deployment and runtime; exercise negative, stale, duplicate, bypass, and outage controls including a substituted dependency, unreviewed change, poisoned build input, failed security test, bypass path, vulnerable release, rollback, and regression.",
          "zh": "运行正向控制“一个把安全不变量贯穿部署与运行的可信构建”，并执行包含“依赖替换、未评审变更、构建输入污染、安全测试失败、绕过路径、漏洞发布、回滚和回归”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-16.12-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "16.12",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Run the positive control a controlled objective that exercises prevention, detection, response, and safe recovery; exercise negative, stale, duplicate, bypass, and outage controls including an unauthorized path, scope ambiguity, missed detection, unsafe impact, incomplete evidence, failed remediation, transferred discovery method, and regression.",
          "zh": "运行正向控制“一项同时检验预防、检测、响应和安全恢复的受控目标”，并执行包含“未授权路径、范围歧义、漏检、不安全影响、证据不完整、修复失败、旧发现方法迁移和回归”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-16.12-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "16.12",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-16.12-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "16.12",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-16.12-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "16.12",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-16.12-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "16.12",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-16.12-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "16.12",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever repositories, issue trackers, CI/CD, artifact registries, SBOMs, dependency sources, architecture models, scanners, tests, reports, deployments, and runtime telemetry change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 代码库、问题系统、CI/CD、制品库、SBOM、依赖来源、架构模型、扫描器、测试、报告、部署和运行遥测 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-16.12-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "16.12",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Use reviewed, unreviewed, reproducible, provenance-bound, vulnerable, test-failed, exception, deployed-unverified, drifted, rolled-back, and regression-protected releases to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已评审、未评审、可复现、来源绑定、存在漏洞、测试失败、例外、已部署未验证、漂移、已回滚和受回归保护发布物 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-16.12-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "16.12",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Use planned, executed, stopped, out-of-scope, prevented, detected, contained, missed, found, fixed, retest-passed, recurrent, and untested attack paths to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 计划、执行、停止、越界、已阻断、已检测、已遏制、漏检、发现、修复、复测通过、复发和未测试攻击路径 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "16.13",
      "control": 16,
      "title_en": "Conduct Application Penetration Testing",
      "title_zh": "应用渗透测试",
      "first_ig": 3,
      "implementation_groups": [
        3
      ],
      "asset_class": "Software",
      "security_function": "Detect",
      "patterns": [
        "software_dev",
        "adversarial"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "2.1"
        ],
        "variables": [
          "GV5",
          "M1",
          "M2",
          "M3",
          "M4",
          "M5",
          "M6",
          "M7"
        ],
        "metric_branches": 2,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "Scope critical applications and material releases across unauthenticated and authenticated roles, APIs, business workflows, integrations, tenants and provider boundaries.",
          "build": "Define risk-based cadence/change triggers, rules of engagement, test identities/data, source/design access level and coordinated response.",
          "proof": "Exercise anonymous, ordinary, privileged, cross-tenant and abuse workflows, validate chained impact safely and retest fixes with positive controls.",
          "boundary": "A broad annual black-box test may miss new high-risk releases; targeted tests trigger on change."
        },
        "zh": {
          "scope": "覆盖关键应用和重大发布的匿名/认证角色、API、业务流、集成、租户与服务商边界；依靠有能力的对抗推理，重点发现授权/逻辑问题，超出自动扫描。",
          "build": "按风险定周期/变更触发、规则、测试身份/数据和源码/设计可见度，使用独立合格测试者，保护生产与证据，把发现接漏洞/RCA 流程。",
          "proof": "从匿名、普通、高权、跨租户和滥用流程安全验证串链影响，并复测修复和正常正控；记录角色、端点、版本、限制与未测路径，以关键范围/发现关闭为指标。",
          "boundary": "年度宽泛黑盒会漏新高风险发布，重大变化需目标测试。"
        }
      },
      "category_counts": {
        "outcome": 7,
        "scope": 7,
        "ownership": 7,
        "data": 7,
        "integration": 7,
        "control": 7,
        "timing": 7,
        "exception": 7,
        "evidence": 7,
        "security": 7,
        "testing": 7,
        "operations": 7
      },
      "requirement_count": 84,
      "requirements": [
        {
          "code": "CIS-16.13-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "16.13",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Conduct Application Penetration Testing; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“应用渗透测试”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-16.13-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "16.13",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 16.13, official Asset Class Software, Security Function Detect, and IG3 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 16.13、官方资产类别“软件”、安全功能“检测”和首次出现的 IG3，并保存来源抓取日期。"
        },
        {
          "code": "CIS-16.13-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "16.13",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Scope critical applications and material releases across unauthenticated and authenticated roles, APIs, business workflows, integrations, tenants and provider boundaries.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“覆盖关键应用和重大发布的匿名/认证角色、API、业务流、集成、租户与服务商边界；依靠有能力的对抗推理，重点发现授权/逻辑问题，超出自动扫描。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-16.13-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "16.13",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-16.13-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "16.13",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Conduct Application Penetration Testing to its operating object—applications, services, APIs, code, dependencies, build and deployment systems, design invariants, vulnerability reports, tests, and production behavior—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“应用渗透测试”连接到其运营对象——应用、服务、API、代码、依赖、构建与部署系统、设计不变量、漏洞报告、测试和生产行为——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-16.13-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "16.13",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "For Conduct Application Penetration Testing, express success as an observable decision over source-to-production software identity, design invariant, component trust, build provenance, test result, deployment state, runtime outcome, and vulnerability response; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“应用渗透测试”，以 从源码到生产的软件身份、设计不变量、组件信任、构建来源、测试结果、部署状态、运行结果和漏洞响应 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-16.13-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "16.13",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "For Conduct Application Penetration Testing, express success as an observable decision over authorized attack hypothesis, realistic path, controlled objective, observable defense response, finding, remediation, independent retest, and regression; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“应用渗透测试”，以 授权攻击假设、真实路径、受控目标、可观察防御响应、发现、修复、独立复测和回归 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-16.13-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "16.13",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-16.13-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "16.13",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-16.13-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "16.13",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-16.13-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "16.13",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-16.13-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "16.13",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across generated code, forks, vendoring, transitive and mutable dependencies, build compromise, feature flags, tenant logic, business-logic flaws, secrets, emergency release, and provider components; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 生成代码、分叉、vendoring、传递与可变依赖、构建失陷、功能开关、租户逻辑、业务逻辑缺陷、秘密、紧急发布和提供商组件 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-16.13-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "16.13",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Include generated and copied code, forks, vendoring, transitive dependencies, mutable tags, build plugins, feature flags, tenant logic, secrets, emergency release, and provider components in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 生成与复制代码、分叉、vendoring、传递依赖、可变标签、构建插件、功能开关、租户逻辑、秘密、紧急发布和提供商组件 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-16.13-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "16.13",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Include scope drift, unsafe techniques, shared tenants, third-party systems, production impact, incomplete credentials, newly discovered critical paths, sensitive test data, and undetected activity in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 范围漂移、不安全技术、共享租户、第三方系统、生产影响、凭据不完整、新发现关键路径、敏感测试数据和未检测活动 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-16.13-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "16.13",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-16.13-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "16.13",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-16.13-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "16.13",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-16.13-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "16.13",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-16.13-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "16.13",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind product and engineering owners, developers, security champions, application security, platform engineering, vulnerability response, architecture, and operations to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 产品与工程责任人、开发者、安全负责人、应用安全、平台工程、漏洞响应、架构和运营 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-16.13-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "16.13",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Name who may transition designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-16.13-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "16.13",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Name who may transition authorized → scoped → rehearsed → executed with stop conditions → evidenced → triaged → remediated → independently retested → regression monitored, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 授权 → 定范围 → 预演 → 带停止条件执行 → 取证 → 分流 → 修复 → 独立复测 → 回归监测，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-16.13-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "16.13",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-16.13-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "16.13",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-16.13-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "16.13",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV5, M1, M2, M3, M4, M5, M6, M7) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV5, M1, M2, M3, M4, M5, M6, M7）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-16.13-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "16.13",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-16.13-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "16.13",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the secure-development, component, vulnerability, threat-model, build, release, and exception authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把安全开发、组件、漏洞、威胁模型、构建、发布与例外权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-16.13-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "16.13",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired.",
          "zh": "对生命周期“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-16.13-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "16.13",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle authorized → scoped → rehearsed → executed with stop conditions → evidenced → triaged → remediated → independently retested → regression monitored.",
          "zh": "对生命周期“授权 → 定范围 → 预演 → 带停止条件执行 → 取证 → 分流 → 修复 → 独立复测 → 回归监测”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-16.13-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "16.13",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 2.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 2.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-16.13-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "16.13",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-16.13-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "16.13",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-16.13-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "16.13",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-16.13-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "16.13",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile repositories, issue trackers, CI/CD, artifact registries, SBOMs, dependency sources, architecture models, scanners, tests, reports, deployments, and runtime telemetry and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 代码库、问题系统、CI/CD、制品库、SBOM、依赖来源、架构模型、扫描器、测试、报告、部署和运行遥测，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-16.13-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "16.13",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Require every connector carrying source-to-production software identity, design invariant, component trust, build provenance, test result, deployment state, runtime outcome, and vulnerability response to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 从源码到生产的软件身份、设计不变量、组件信任、构建来源、测试结果、部署状态、运行结果和漏洞响应 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-16.13-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "16.13",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Require every connector carrying authorized attack hypothesis, realistic path, controlled objective, observable defense response, finding, remediation, independent retest, and regression to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 授权攻击假设、真实路径、受控目标、可观察防御响应、发现、修复、独立复测和回归 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-16.13-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "16.13",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Define risk-based cadence/change triggers, rules of engagement, test identities/data, source/design access level and coordinated response.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“按风险定周期/变更触发、规则、测试身份/数据和源码/设计可见度，使用独立合格测试者，保护生产与证据，把发现接漏洞/RCA 流程。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-16.13-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "16.13",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-16.13-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "16.13",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-16.13-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "16.13",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-16.13-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "16.13",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the secure-development, component, vulnerability, threat-model, build, release, and exception authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在安全开发、组件、漏洞、威胁模型、构建、发布与例外权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-16.13-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "16.13",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Implement the explicit state machine designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-16.13-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "16.13",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Implement the explicit state machine authorized → scoped → rehearsed → executed with stop conditions → evidenced → triaged → remediated → independently retested → regression monitored; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“授权 → 定范围 → 预演 → 带停止条件执行 → 取证 → 分流 → 修复 → 独立复测 → 回归监测”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-16.13-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "16.13",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-16.13-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "16.13",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-16.13-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "16.13",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-16.13-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "16.13",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-16.13-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "16.13",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in applications, services, APIs, code, dependencies, build and deployment systems, design invariants, vulnerability reports, tests, and production behavior; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 应用、服务、API、代码、依赖、构建与部署系统、设计不变量、漏洞报告、测试和生产行为 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-16.13-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "16.13",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; alert before each deadline becomes overdue.",
          "zh": "为“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-16.13-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "16.13",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for authorized → scoped → rehearsed → executed with stop conditions → evidenced → triaged → remediated → independently retested → regression monitored; alert before each deadline becomes overdue.",
          "zh": "为“授权 → 定范围 → 预演 → 带停止条件执行 → 取证 → 分流 → 修复 → 独立复测 → 回归监测”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-16.13-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "16.13",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “A broad annual black-box test may miss new high-risk releases; targeted tests trigger on change.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“年度宽泛黑盒会漏新高风险发布，重大变化需目标测试。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-16.13-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "16.13",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-16.13-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "16.13",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-16.13-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "16.13",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-16.13-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "16.13",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat generated code, forks, vendoring, transitive and mutable dependencies, build compromise, feature flags, tenant logic, business-logic flaws, secrets, emergency release, and provider components as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 生成代码、分叉、vendoring、传递与可变依赖、构建失陷、功能开关、租户逻辑、业务逻辑缺陷、秘密、紧急发布和提供商组件 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-16.13-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "16.13",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Treat generated and copied code, forks, vendoring, transitive dependencies, mutable tags, build plugins, feature flags, tenant logic, secrets, emergency release, and provider components as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 生成与复制代码、分叉、vendoring、传递依赖、可变标签、构建插件、功能开关、租户逻辑、秘密、紧急发布和提供商组件 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-16.13-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "16.13",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Treat scope drift, unsafe techniques, shared tenants, third-party systems, production impact, incomplete credentials, newly discovered critical paths, sensitive test data, and undetected activity as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 范围漂移、不安全技术、共享租户、第三方系统、生产影响、凭据不完整、新发现关键路径、敏感测试数据和未检测活动 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-16.13-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "16.13",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Exercise anonymous, ordinary, privileged, cross-tenant and abuse workflows, validate chained impact safely and retest fixes with positive controls.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“从匿名、普通、高权、跨租户和滥用流程安全验证串链影响，并复测修复和正常正控；记录角色、端点、版本、限制与未测路径，以关键范围/发现关闭为指标。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-16.13-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "16.13",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-16.13-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "16.13",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 2 pinned CAS metric branch(es), 8 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 2 个指标分支、8 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-16.13-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "16.13",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-16.13-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "16.13",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the secure-development, component, vulnerability, threat-model, build, release, and exception authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以安全开发、组件、漏洞、威胁模型、构建、发布与例外权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-16.13-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "16.13",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Publish reviewed, unreviewed, reproducible, provenance-bound, vulnerable, test-failed, exception, deployed-unverified, drifted, rolled-back, and regression-protected releases with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已评审、未评审、可复现、来源绑定、存在漏洞、测试失败、例外、已部署未验证、漂移、已回滚和受回归保护发布物，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-16.13-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "16.13",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Publish planned, executed, stopped, out-of-scope, prevented, detected, contained, missed, found, fixed, retest-passed, recurrent, and untested attack paths with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 计划、执行、停止、越界、已阻断、已检测、已遏制、漏检、发现、修复、复测通过、复发和未测试攻击路径，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-16.13-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "16.13",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-16.13-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "16.13",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-16.13-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "16.13",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-16.13-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "16.13",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-16.13-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "16.13",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the secure-development, component, vulnerability, threat-model, build, release, and exception authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护安全开发、组件、漏洞、威胁模型、构建、发布与例外权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-16.13-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "16.13",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Restrict authority to change designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-16.13-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "16.13",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Restrict authority to change authorized → scoped → rehearsed → executed with stop conditions → evidenced → triaged → remediated → independently retested → regression monitored; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“授权 → 定范围 → 预演 → 带停止条件执行 → 取证 → 分流 → 修复 → 独立复测 → 回归监测”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-16.13-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "16.13",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-16.13-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "16.13",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-16.13-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "16.13",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-16.13-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "16.13",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-16.13-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "16.13",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise secure and insecure design paths, trusted and substituted components, accepted and rejected reports, code-level controls, authenticated abuse, build provenance, rollback, and regression through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 安全与不安全设计路径、可信与被替换组件、接受与拒绝报告、代码级控制、认证后滥用、构建来源、回滚和回归，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-16.13-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "16.13",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Run the positive control a trusted build that preserves the security invariant through deployment and runtime; exercise negative, stale, duplicate, bypass, and outage controls including a substituted dependency, unreviewed change, poisoned build input, failed security test, bypass path, vulnerable release, rollback, and regression.",
          "zh": "运行正向控制“一个把安全不变量贯穿部署与运行的可信构建”，并执行包含“依赖替换、未评审变更、构建输入污染、安全测试失败、绕过路径、漏洞发布、回滚和回归”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-16.13-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "16.13",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Run the positive control a controlled objective that exercises prevention, detection, response, and safe recovery; exercise negative, stale, duplicate, bypass, and outage controls including an unauthorized path, scope ambiguity, missed detection, unsafe impact, incomplete evidence, failed remediation, transferred discovery method, and regression.",
          "zh": "运行正向控制“一项同时检验预防、检测、响应和安全恢复的受控目标”，并执行包含“未授权路径、范围歧义、漏检、不安全影响、证据不完整、修复失败、旧发现方法迁移和回归”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-16.13-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "16.13",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-16.13-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "16.13",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-16.13-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "16.13",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-16.13-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "16.13",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-16.13-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "16.13",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever repositories, issue trackers, CI/CD, artifact registries, SBOMs, dependency sources, architecture models, scanners, tests, reports, deployments, and runtime telemetry change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 代码库、问题系统、CI/CD、制品库、SBOM、依赖来源、架构模型、扫描器、测试、报告、部署和运行遥测 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-16.13-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "16.13",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Use reviewed, unreviewed, reproducible, provenance-bound, vulnerable, test-failed, exception, deployed-unverified, drifted, rolled-back, and regression-protected releases to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已评审、未评审、可复现、来源绑定、存在漏洞、测试失败、例外、已部署未验证、漂移、已回滚和受回归保护发布物 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-16.13-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "16.13",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Use planned, executed, stopped, out-of-scope, prevented, detected, contained, missed, found, fixed, retest-passed, recurrent, and untested attack paths to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 计划、执行、停止、越界、已阻断、已检测、已遏制、漏检、发现、修复、复测通过、复发和未测试攻击路径 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "16.14",
      "control": 16,
      "title_en": "Conduct Threat Modeling",
      "title_zh": "威胁建模",
      "first_ig": 3,
      "implementation_groups": [
        3
      ],
      "asset_class": "Software",
      "security_function": "Protect",
      "patterns": [
        "software_dev",
        "adversarial"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "2.1"
        ],
        "variables": [
          "GV5",
          "M1",
          "M2",
          "M3",
          "M4"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "Threat modeling covers new and materially changed applications before code, mapping assets, actors, trust boundaries, data/state flows, entry points, abuse cases and dependencies across architecture and infrastructure.",
          "build": "Use trained multidisciplinary participants, choose a method proportionate to risk, state assumptions and rank threats, then create design requirements, tests, telemetry and accepted residual risks with owners.",
          "proof": "Select modeled threats and trace them to implemented controls and negative tests; add an architectural change or adversary scenario and verify the model catches the new path.",
          "boundary": "Counting applications with a workshop, as CAS does, cannot show coverage or quality."
        },
        "zh": {
          "scope": "在编码前对新建/重大变更应用梳理资产、参与者、信任边界、数据/状态流、入口、滥用和依赖，横跨架构与基础设施；这是决策实践，不是一张模板图。",
          "build": "由受训多学科人员用相称方法，声明假设、排序威胁并生成设计要求、测试、遥测和具名剩余风险；身份、数据、集成、AI 模型/工具或部署边界变化时重访。",
          "proof": "挑建模威胁追到实现控制和负测；加入架构变化/对手场景，验证模型能发现新路径；抽样未建模的生产事件/漏洞改方法，并查未完成行动。",
          "boundary": "CAS 只数开过 Workshop 的应用，证明不了质量/覆盖。"
        }
      },
      "category_counts": {
        "outcome": 7,
        "scope": 7,
        "ownership": 7,
        "data": 7,
        "integration": 7,
        "control": 7,
        "timing": 7,
        "exception": 7,
        "evidence": 7,
        "security": 7,
        "testing": 7,
        "operations": 7
      },
      "requirement_count": 84,
      "requirements": [
        {
          "code": "CIS-16.14-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "16.14",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Conduct Threat Modeling; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“威胁建模”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-16.14-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "16.14",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 16.14, official Asset Class Software, Security Function Protect, and IG3 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 16.14、官方资产类别“软件”、安全功能“保护”和首次出现的 IG3，并保存来源抓取日期。"
        },
        {
          "code": "CIS-16.14-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "16.14",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Threat modeling covers new and materially changed applications before code, mapping assets, actors, trust boundaries, data/state flows, entry points, abuse cases and dependencies across architecture and infrastructure.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“在编码前对新建/重大变更应用梳理资产、参与者、信任边界、数据/状态流、入口、滥用和依赖，横跨架构与基础设施；这是决策实践，不是一张模板图。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-16.14-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "16.14",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-16.14-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "16.14",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Conduct Threat Modeling to its operating object—applications, services, APIs, code, dependencies, build and deployment systems, design invariants, vulnerability reports, tests, and production behavior—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“威胁建模”连接到其运营对象——应用、服务、API、代码、依赖、构建与部署系统、设计不变量、漏洞报告、测试和生产行为——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-16.14-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "16.14",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "For Conduct Threat Modeling, express success as an observable decision over source-to-production software identity, design invariant, component trust, build provenance, test result, deployment state, runtime outcome, and vulnerability response; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“威胁建模”，以 从源码到生产的软件身份、设计不变量、组件信任、构建来源、测试结果、部署状态、运行结果和漏洞响应 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-16.14-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "16.14",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "For Conduct Threat Modeling, express success as an observable decision over authorized attack hypothesis, realistic path, controlled objective, observable defense response, finding, remediation, independent retest, and regression; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“威胁建模”，以 授权攻击假设、真实路径、受控目标、可观察防御响应、发现、修复、独立复测和回归 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-16.14-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "16.14",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-16.14-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "16.14",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-16.14-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "16.14",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-16.14-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "16.14",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-16.14-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "16.14",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across generated code, forks, vendoring, transitive and mutable dependencies, build compromise, feature flags, tenant logic, business-logic flaws, secrets, emergency release, and provider components; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 生成代码、分叉、vendoring、传递与可变依赖、构建失陷、功能开关、租户逻辑、业务逻辑缺陷、秘密、紧急发布和提供商组件 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-16.14-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "16.14",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Include generated and copied code, forks, vendoring, transitive dependencies, mutable tags, build plugins, feature flags, tenant logic, secrets, emergency release, and provider components in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 生成与复制代码、分叉、vendoring、传递依赖、可变标签、构建插件、功能开关、租户逻辑、秘密、紧急发布和提供商组件 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-16.14-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "16.14",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Include scope drift, unsafe techniques, shared tenants, third-party systems, production impact, incomplete credentials, newly discovered critical paths, sensitive test data, and undetected activity in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 范围漂移、不安全技术、共享租户、第三方系统、生产影响、凭据不完整、新发现关键路径、敏感测试数据和未检测活动 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-16.14-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "16.14",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-16.14-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "16.14",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-16.14-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "16.14",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-16.14-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "16.14",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-16.14-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "16.14",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind product and engineering owners, developers, security champions, application security, platform engineering, vulnerability response, architecture, and operations to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 产品与工程责任人、开发者、安全负责人、应用安全、平台工程、漏洞响应、架构和运营 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-16.14-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "16.14",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Name who may transition designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-16.14-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "16.14",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Name who may transition authorized → scoped → rehearsed → executed with stop conditions → evidenced → triaged → remediated → independently retested → regression monitored, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 授权 → 定范围 → 预演 → 带停止条件执行 → 取证 → 分流 → 修复 → 独立复测 → 回归监测，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-16.14-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "16.14",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-16.14-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "16.14",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-16.14-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "16.14",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV5, M1, M2, M3, M4) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV5, M1, M2, M3, M4）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-16.14-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "16.14",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-16.14-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "16.14",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the secure-development, component, vulnerability, threat-model, build, release, and exception authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把安全开发、组件、漏洞、威胁模型、构建、发布与例外权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-16.14-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "16.14",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired.",
          "zh": "对生命周期“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-16.14-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "16.14",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle authorized → scoped → rehearsed → executed with stop conditions → evidenced → triaged → remediated → independently retested → regression monitored.",
          "zh": "对生命周期“授权 → 定范围 → 预演 → 带停止条件执行 → 取证 → 分流 → 修复 → 独立复测 → 回归监测”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-16.14-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "16.14",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 2.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 2.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-16.14-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "16.14",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-16.14-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "16.14",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-16.14-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "16.14",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-16.14-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "16.14",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile repositories, issue trackers, CI/CD, artifact registries, SBOMs, dependency sources, architecture models, scanners, tests, reports, deployments, and runtime telemetry and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 代码库、问题系统、CI/CD、制品库、SBOM、依赖来源、架构模型、扫描器、测试、报告、部署和运行遥测，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-16.14-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "16.14",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Require every connector carrying source-to-production software identity, design invariant, component trust, build provenance, test result, deployment state, runtime outcome, and vulnerability response to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 从源码到生产的软件身份、设计不变量、组件信任、构建来源、测试结果、部署状态、运行结果和漏洞响应 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-16.14-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "16.14",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Require every connector carrying authorized attack hypothesis, realistic path, controlled objective, observable defense response, finding, remediation, independent retest, and regression to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 授权攻击假设、真实路径、受控目标、可观察防御响应、发现、修复、独立复测和回归 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-16.14-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "16.14",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Use trained multidisciplinary participants, choose a method proportionate to risk, state assumptions and rank threats, then create design requirements, tests, telemetry and accepted residual risks with owners.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“由受训多学科人员用相称方法，声明假设、排序威胁并生成设计要求、测试、遥测和具名剩余风险；身份、数据、集成、AI 模型/工具或部署边界变化时重访。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-16.14-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "16.14",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-16.14-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "16.14",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-16.14-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "16.14",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-16.14-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "16.14",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the secure-development, component, vulnerability, threat-model, build, release, and exception authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在安全开发、组件、漏洞、威胁模型、构建、发布与例外权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-16.14-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "16.14",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Implement the explicit state machine designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-16.14-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "16.14",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Implement the explicit state machine authorized → scoped → rehearsed → executed with stop conditions → evidenced → triaged → remediated → independently retested → regression monitored; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“授权 → 定范围 → 预演 → 带停止条件执行 → 取证 → 分流 → 修复 → 独立复测 → 回归监测”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-16.14-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "16.14",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-16.14-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "16.14",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-16.14-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "16.14",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-16.14-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "16.14",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-16.14-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "16.14",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in applications, services, APIs, code, dependencies, build and deployment systems, design invariants, vulnerability reports, tests, and production behavior; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 应用、服务、API、代码、依赖、构建与部署系统、设计不变量、漏洞报告、测试和生产行为 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-16.14-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "16.14",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; alert before each deadline becomes overdue.",
          "zh": "为“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-16.14-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "16.14",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for authorized → scoped → rehearsed → executed with stop conditions → evidenced → triaged → remediated → independently retested → regression monitored; alert before each deadline becomes overdue.",
          "zh": "为“授权 → 定范围 → 预演 → 带停止条件执行 → 取证 → 分流 → 修复 → 独立复测 → 回归监测”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-16.14-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "16.14",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “Counting applications with a workshop, as CAS does, cannot show coverage or quality.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“CAS 只数开过 Workshop 的应用，证明不了质量/覆盖。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-16.14-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "16.14",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-16.14-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "16.14",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-16.14-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "16.14",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-16.14-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "16.14",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat generated code, forks, vendoring, transitive and mutable dependencies, build compromise, feature flags, tenant logic, business-logic flaws, secrets, emergency release, and provider components as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 生成代码、分叉、vendoring、传递与可变依赖、构建失陷、功能开关、租户逻辑、业务逻辑缺陷、秘密、紧急发布和提供商组件 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-16.14-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "16.14",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Treat generated and copied code, forks, vendoring, transitive dependencies, mutable tags, build plugins, feature flags, tenant logic, secrets, emergency release, and provider components as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 生成与复制代码、分叉、vendoring、传递依赖、可变标签、构建插件、功能开关、租户逻辑、秘密、紧急发布和提供商组件 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-16.14-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "16.14",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Treat scope drift, unsafe techniques, shared tenants, third-party systems, production impact, incomplete credentials, newly discovered critical paths, sensitive test data, and undetected activity as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 范围漂移、不安全技术、共享租户、第三方系统、生产影响、凭据不完整、新发现关键路径、敏感测试数据和未检测活动 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-16.14-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "16.14",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Select modeled threats and trace them to implemented controls and negative tests; add an architectural change or adversary scenario and verify the model catches the new path.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“挑建模威胁追到实现控制和负测；加入架构变化/对手场景，验证模型能发现新路径；抽样未建模的生产事件/漏洞改方法，并查未完成行动。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-16.14-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "16.14",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-16.14-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "16.14",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 5 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、5 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-16.14-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "16.14",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-16.14-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "16.14",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the secure-development, component, vulnerability, threat-model, build, release, and exception authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以安全开发、组件、漏洞、威胁模型、构建、发布与例外权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-16.14-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "16.14",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Publish reviewed, unreviewed, reproducible, provenance-bound, vulnerable, test-failed, exception, deployed-unverified, drifted, rolled-back, and regression-protected releases with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已评审、未评审、可复现、来源绑定、存在漏洞、测试失败、例外、已部署未验证、漂移、已回滚和受回归保护发布物，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-16.14-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "16.14",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Publish planned, executed, stopped, out-of-scope, prevented, detected, contained, missed, found, fixed, retest-passed, recurrent, and untested attack paths with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 计划、执行、停止、越界、已阻断、已检测、已遏制、漏检、发现、修复、复测通过、复发和未测试攻击路径，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-16.14-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "16.14",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-16.14-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "16.14",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-16.14-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "16.14",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-16.14-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "16.14",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-16.14-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "16.14",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the secure-development, component, vulnerability, threat-model, build, release, and exception authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护安全开发、组件、漏洞、威胁模型、构建、发布与例外权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-16.14-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "16.14",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Restrict authority to change designed → reviewed → built from pinned inputs → tested → approved → deployed → observed → fixed/rolled back → retired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“设计 → 评审 → 使用固定输入构建 → 测试 → 批准 → 部署 → 观察 → 修复/回滚 → 退役”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-16.14-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "16.14",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Restrict authority to change authorized → scoped → rehearsed → executed with stop conditions → evidenced → triaged → remediated → independently retested → regression monitored; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“授权 → 定范围 → 预演 → 带停止条件执行 → 取证 → 分流 → 修复 → 独立复测 → 回归监测”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-16.14-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "16.14",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-16.14-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "16.14",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-16.14-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "16.14",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-16.14-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "16.14",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-16.14-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "16.14",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise secure and insecure design paths, trusted and substituted components, accepted and rejected reports, code-level controls, authenticated abuse, build provenance, rollback, and regression through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 安全与不安全设计路径、可信与被替换组件、接受与拒绝报告、代码级控制、认证后滥用、构建来源、回滚和回归，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-16.14-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "16.14",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Run the positive control a trusted build that preserves the security invariant through deployment and runtime; exercise negative, stale, duplicate, bypass, and outage controls including a substituted dependency, unreviewed change, poisoned build input, failed security test, bypass path, vulnerable release, rollback, and regression.",
          "zh": "运行正向控制“一个把安全不变量贯穿部署与运行的可信构建”，并执行包含“依赖替换、未评审变更、构建输入污染、安全测试失败、绕过路径、漏洞发布、回滚和回归”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-16.14-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "16.14",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Run the positive control a controlled objective that exercises prevention, detection, response, and safe recovery; exercise negative, stale, duplicate, bypass, and outage controls including an unauthorized path, scope ambiguity, missed detection, unsafe impact, incomplete evidence, failed remediation, transferred discovery method, and regression.",
          "zh": "运行正向控制“一项同时检验预防、检测、响应和安全恢复的受控目标”，并执行包含“未授权路径、范围歧义、漏检、不安全影响、证据不完整、修复失败、旧发现方法迁移和回归”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-16.14-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "16.14",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-16.14-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "16.14",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-16.14-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "16.14",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-16.14-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "16.14",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-16.14-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "16.14",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever repositories, issue trackers, CI/CD, artifact registries, SBOMs, dependency sources, architecture models, scanners, tests, reports, deployments, and runtime telemetry change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 代码库、问题系统、CI/CD、制品库、SBOM、依赖来源、架构模型、扫描器、测试、报告、部署和运行遥测 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-16.14-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "16.14",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original software_dev pattern analysis",
          "basis_zh": "SOSEC 原创 software_dev 模式分析",
          "en": "Use reviewed, unreviewed, reproducible, provenance-bound, vulnerable, test-failed, exception, deployed-unverified, drifted, rolled-back, and regression-protected releases to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已评审、未评审、可复现、来源绑定、存在漏洞、测试失败、例外、已部署未验证、漂移、已回滚和受回归保护发布物 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-16.14-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "16.14",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Use planned, executed, stopped, out-of-scope, prevented, detected, contained, missed, found, fixed, retest-passed, recurrent, and untested attack paths to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 计划、执行、停止、越界、已阻断、已检测、已遏制、漏检、发现、修复、复测通过、复发和未测试攻击路径 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "17.1",
      "control": 17,
      "title_en": "Designate Personnel to Manage Incident Handling",
      "title_zh": "事件处置负责人",
      "first_ig": 1,
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Users",
      "security_function": "Respond",
      "patterns": [
        "incident",
        "data_lifecycle",
        "governance"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [],
        "variables": [
          "GV51",
          "M1",
          "M2",
          "M3"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [
        "annually"
      ],
      "implementation_contract": {
        "en": {
          "scope": "Designate one primary and at least one backup with authority to coordinate and document response/recovery, available for the organization's risk hours.",
          "build": "Name people/roles, coverage/on-call, delegation, decision and spending authority, provider interface and succession; equip them with independent access to plans, contacts and communication.",
          "proof": "Page the primary and backup in an exercise, verify acknowledgement, access, handoff, decision log and continuity when one is unavailable.",
          "boundary": "A name in a plan can be on leave, lack privileges or lack authority."
        },
        "zh": {
          "scope": "指定一个主负责人和至少一个备份，有权协调和记录响应/恢复，覆盖组织风险时段；即使外部服务商主操作，仍要有内部负责人监督企业决定与责任。",
          "build": "写明人员/角色、值班覆盖、授权、决策/支出权、服务商接口和继任，并给独立访问计划、联系人、通信的能力；每年及人员、服务商、结构或风险变化时更新。",
          "proof": "演练 Page 主/备，验证确认、访问、交接、决定记录和一人缺席时连续性；确认 HR、值班、服务商记录一致，技术、法务和高层承认其权力。",
          "boundary": "计划里的名字可能休假、无权限或无权拍板。"
        }
      },
      "category_counts": {
        "outcome": 8,
        "scope": 8,
        "ownership": 8,
        "data": 8,
        "integration": 8,
        "control": 8,
        "timing": 8,
        "exception": 8,
        "evidence": 8,
        "security": 8,
        "testing": 8,
        "operations": 8
      },
      "requirement_count": 96,
      "requirements": [
        {
          "code": "CIS-17.1-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "17.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Designate Personnel to Manage Incident Handling; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“事件处置负责人”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-17.1-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "17.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 17.1, official Asset Class Users, Security Function Respond, and IG1 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 17.1、官方资产类别“用户与身份”、安全功能“响应”和首次出现的 IG1，并保存来源抓取日期。"
        },
        {
          "code": "CIS-17.1-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "17.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Designate one primary and at least one backup with authority to coordinate and document response/recovery, available for the organization's risk hours.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“指定一个主负责人和至少一个备份，有权协调和记录响应/恢复，覆盖组织风险时段；即使外部服务商主操作，仍要有内部负责人监督企业决定与责任。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-17.1-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "17.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-17.1-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "17.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Designate Personnel to Manage Incident Handling to its operating object—security events and incidents, thresholds, reports, roles, decisions, communications, evidence, containment, recovery, review, and follow-up actions—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“事件处置负责人”连接到其运营对象——安全事件与事故、阈值、报告、角色、决策、通信、证据、遏制、恢复、复盘和后续行动——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-17.1-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "17.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "For Designate Personnel to Manage Incident Handling, express success as an observable decision over event-to-incident threshold, report, command, decision, communication, containment, evidence, recovery, review, and corrective action; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“事件处置负责人”，以 事件到事故阈值、报告、指挥、决策、通信、遏制、证据、恢复、复盘和纠正行动 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-17.1-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "17.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "For Designate Personnel to Manage Incident Handling, express success as an observable decision over data identity, sensitivity, owner, purpose, location, flow, access, retention, copy, derivation, and disposal state; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“事件处置负责人”，以 数据身份、敏感度、责任人、目的、位置、流向、访问、保留、副本、派生与销毁状态 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-17.1-OUT-08",
          "local_code": "OUT-08",
          "display_code": "O08",
          "safeguard_id": "17.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "For Designate Personnel to Manage Incident Handling, express success as an observable decision over a documented decision system with policy, process, procedure, accountable owner, approval, and review; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“事件处置负责人”，以 包含策略、流程、程序、责任人、审批和复核的文档化决策系统 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-17.1-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "17.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-17.1-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "17.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-17.1-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "17.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-17.1-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "17.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-17.1-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "17.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across ambiguous thresholds, compromised primary channels, absent personnel, cross-jurisdiction notice, provider incidents, insider cases, safety events, evidence loss, prolonged recovery, and unresolved actions; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 阈值歧义、主通信通道失陷、人员缺席、跨辖区通知、提供商事件、内部人案件、安全生产事件、证据丢失、长期恢复和未关闭行动 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-17.1-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "17.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Include ambiguous classification, unavailable personnel, compromised primary channels, provider and cross-border incidents, insider and safety cases, evidence loss, prolonged recovery, and unresolved actions in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 分类歧义、人员不可用、主通道失陷、提供商与跨境事件、内部人与安全生产案件、证据丢失、长期恢复和未关闭行动 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-17.1-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "17.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Include unstructured and derived data, logs, caches, backups, exports, client-side copies, cross-region processing, AI corpora, holds, and provider residues in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 非结构化与派生数据、日志、缓存、备份、导出、客户端副本、跨地域处理、AI 语料、保全和提供商残留 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-17.1-SCP-08",
          "local_code": "SCP-08",
          "display_code": "P08",
          "safeguard_id": "17.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Include missing policy clauses, conflicting authorities, local deviations, obsolete documentation, and decisions made outside the governed workflow in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 策略条款缺失、权限冲突、本地偏离、文档过期及绕过治理流程的决策 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-17.1-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "17.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-17.1-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "17.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-17.1-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "17.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-17.1-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "17.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-17.1-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "17.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind incident command and responders, IT and security, legal/privacy, communications, HR, facilities, business owners, executives, providers, insurers, and authorities to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 事件指挥与响应人员、IT 与安全、法务/隐私、传播、HR、设施、业务责任人、管理层、提供商、保险和主管机关 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-17.1-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "17.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Name who may transition reported/detected → triaged → declared → commanded → contained → eradicated/recovered → reviewed → actions retested and closed, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 报告/检测 → 分流 → 宣告 → 指挥 → 遏制 → 根除/恢复 → 复盘 → 行动复测关闭，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-17.1-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "17.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Name who may transition created/collected → classified → approved use and flow → retained/held → disposed with verification, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-17.1-OWN-08",
          "local_code": "OWN-08",
          "display_code": "W08",
          "safeguard_id": "17.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Name who may transition draft → reviewed → approved → effective → exception/withdrawn → superseded, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-17.1-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "17.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-17.1-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "17.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-17.1-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "17.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV51, M1, M2, M3) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV51, M1, M2, M3）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-17.1-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "17.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-17.1-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "17.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the incident taxonomy, case, command, communication, evidence, and action authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把事件分类、案件、指挥、通信、证据与行动权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-17.1-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "17.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle reported/detected → triaged → declared → commanded → contained → eradicated/recovered → reviewed → actions retested and closed.",
          "zh": "对生命周期“报告/检测 → 分流 → 宣告 → 指挥 → 遏制 → 根除/恢复 → 复盘 → 行动复测关闭”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-17.1-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "17.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle created/collected → classified → approved use and flow → retained/held → disposed with verification.",
          "zh": "对生命周期“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-17.1-DAT-08",
          "local_code": "DAT-08",
          "display_code": "D08",
          "safeguard_id": "17.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle draft → reviewed → approved → effective → exception/withdrawn → superseded.",
          "zh": "对生命周期“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-17.1-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "17.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for no explicit predecessor in the pinned CAS page; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 固定 CAS 页面没有列出显式前置项 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-17.1-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "17.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-17.1-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "17.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-17.1-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "17.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-17.1-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "17.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile reporting channels, monitoring and provider alerts, case systems, contact rosters, communication plans, forensic stores, recovery systems, exercises, and post-incident records and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 报告通道、监测与提供商告警、案件系统、联系人名册、通信计划、取证存储、恢复系统、演练和事后记录，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-17.1-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "17.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Require every connector carrying event-to-incident threshold, report, command, decision, communication, containment, evidence, recovery, review, and corrective action to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 事件到事故阈值、报告、指挥、决策、通信、遏制、证据、恢复、复盘和纠正行动 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-17.1-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "17.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Require every connector carrying data identity, sensitivity, owner, purpose, location, flow, access, retention, copy, derivation, and disposal state to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 数据身份、敏感度、责任人、目的、位置、流向、访问、保留、副本、派生与销毁状态 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-17.1-INT-08",
          "local_code": "INT-08",
          "display_code": "I08",
          "safeguard_id": "17.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Require every connector carrying a documented decision system with policy, process, procedure, accountable owner, approval, and review to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 包含策略、流程、程序、责任人、审批和复核的文档化决策系统 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-17.1-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "17.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Name people/roles, coverage/on-call, delegation, decision and spending authority, provider interface and succession; equip them with independent access to plans, contacts and communication.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“写明人员/角色、值班覆盖、授权、决策/支出权、服务商接口和继任，并给独立访问计划、联系人、通信的能力；每年及人员、服务商、结构或风险变化时更新。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-17.1-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "17.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-17.1-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "17.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-17.1-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "17.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-17.1-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "17.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the incident taxonomy, case, command, communication, evidence, and action authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在事件分类、案件、指挥、通信、证据与行动权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-17.1-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "17.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Implement the explicit state machine reported/detected → triaged → declared → commanded → contained → eradicated/recovered → reviewed → actions retested and closed; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“报告/检测 → 分流 → 宣告 → 指挥 → 遏制 → 根除/恢复 → 复盘 → 行动复测关闭”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-17.1-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "17.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Implement the explicit state machine created/collected → classified → approved use and flow → retained/held → disposed with verification; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-17.1-CTL-08",
          "local_code": "CTL-08",
          "display_code": "C08",
          "safeguard_id": "17.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Implement the explicit state machine draft → reviewed → approved → effective → exception/withdrawn → superseded; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-17.1-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "17.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (annually); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（annually）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-17.1-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "17.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-17.1-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "17.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-17.1-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "17.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-17.1-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "17.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in security events and incidents, thresholds, reports, roles, decisions, communications, evidence, containment, recovery, review, and follow-up actions; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 安全事件与事故、阈值、报告、角色、决策、通信、证据、遏制、恢复、复盘和后续行动 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-17.1-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "17.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for reported/detected → triaged → declared → commanded → contained → eradicated/recovered → reviewed → actions retested and closed; alert before each deadline becomes overdue.",
          "zh": "为“报告/检测 → 分流 → 宣告 → 指挥 → 遏制 → 根除/恢复 → 复盘 → 行动复测关闭”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-17.1-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "17.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for created/collected → classified → approved use and flow → retained/held → disposed with verification; alert before each deadline becomes overdue.",
          "zh": "为“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-17.1-TIM-08",
          "local_code": "TIM-08",
          "display_code": "T08",
          "safeguard_id": "17.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for draft → reviewed → approved → effective → exception/withdrawn → superseded; alert before each deadline becomes overdue.",
          "zh": "为“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-17.1-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "17.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “A name in a plan can be on leave, lack privileges or lack authority.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“计划里的名字可能休假、无权限或无权拍板。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-17.1-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "17.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-17.1-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "17.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-17.1-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "17.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-17.1-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "17.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat ambiguous thresholds, compromised primary channels, absent personnel, cross-jurisdiction notice, provider incidents, insider cases, safety events, evidence loss, prolonged recovery, and unresolved actions as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 阈值歧义、主通信通道失陷、人员缺席、跨辖区通知、提供商事件、内部人案件、安全生产事件、证据丢失、长期恢复和未关闭行动 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-17.1-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "17.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Treat ambiguous classification, unavailable personnel, compromised primary channels, provider and cross-border incidents, insider and safety cases, evidence loss, prolonged recovery, and unresolved actions as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 分类歧义、人员不可用、主通道失陷、提供商与跨境事件、内部人与安全生产案件、证据丢失、长期恢复和未关闭行动 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-17.1-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "17.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Treat unstructured and derived data, logs, caches, backups, exports, client-side copies, cross-region processing, AI corpora, holds, and provider residues as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 非结构化与派生数据、日志、缓存、备份、导出、客户端副本、跨地域处理、AI 语料、保全和提供商残留 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-17.1-EXC-08",
          "local_code": "EXC-08",
          "display_code": "X08",
          "safeguard_id": "17.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Treat missing policy clauses, conflicting authorities, local deviations, obsolete documentation, and decisions made outside the governed workflow as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 策略条款缺失、权限冲突、本地偏离、文档过期及绕过治理流程的决策 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-17.1-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "17.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Page the primary and backup in an exercise, verify acknowledgement, access, handoff, decision log and continuity when one is unavailable.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“演练 Page 主/备，验证确认、访问、交接、决定记录和一人缺席时连续性；确认 HR、值班、服务商记录一致，技术、法务和高层承认其权力。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-17.1-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "17.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-17.1-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "17.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 4 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、4 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-17.1-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "17.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-17.1-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "17.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the incident taxonomy, case, command, communication, evidence, and action authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以事件分类、案件、指挥、通信、证据与行动权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-17.1-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "17.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Publish events, incidents, severity, ownership, acknowledgement, decision latency, communication success, containment, recovery, evidence gaps, and overdue corrective actions with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 事件、事故、严重度、责任、确认、决策延迟、通信成功、遏制、恢复、证据缺口和逾期纠正行动，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-17.1-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "17.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Publish known, unknown, classified, ownerless, over-retained, prematurely deleted, unapproved copy, blocked flow, held, and disposal-verified data sets with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已知、未知、已分类、无责任人、超期保留、过早删除、未批准副本、被阻断流、保全及销毁已验证数据集，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-17.1-EVD-08",
          "local_code": "EVD-08",
          "display_code": "E08",
          "safeguard_id": "17.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Publish clause coverage, owner and reviewer completeness, approval age, triggered reviews, deviations, overdue actions, and superseded versions still in use with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 条款覆盖、责任人与复核人完整性、批准年龄、触发式复核、偏离、逾期行动及仍在使用的旧版本，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-17.1-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "17.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-17.1-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "17.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-17.1-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "17.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-17.1-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "17.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-17.1-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "17.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the incident taxonomy, case, command, communication, evidence, and action authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护事件分类、案件、指挥、通信、证据与行动权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-17.1-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "17.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Restrict authority to change reported/detected → triaged → declared → commanded → contained → eradicated/recovered → reviewed → actions retested and closed; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“报告/检测 → 分流 → 宣告 → 指挥 → 遏制 → 根除/恢复 → 复盘 → 行动复测关闭”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-17.1-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "17.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Restrict authority to change created/collected → classified → approved use and flow → retained/held → disposed with verification; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“创建/收集 → 分类 → 获批使用与流转 → 保留/保全 → 带验证销毁”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-17.1-SEC-08",
          "local_code": "SEC-08",
          "display_code": "S08",
          "safeguard_id": "17.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Restrict authority to change draft → reviewed → approved → effective → exception/withdrawn → superseded; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-17.1-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "17.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-17.1-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "17.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-17.1-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "17.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-17.1-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "17.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-17.1-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "17.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise event-versus-incident triage, primary and backup reporting, out-of-band communication, containment and recovery decisions, exercise injects, provider coordination, and action retest through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 事件与事故分流、主备报告、带外通信、遏制与恢复决策、演练注入、提供商协同和行动复测，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-17.1-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "17.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Run the positive control a representative report that reaches command, coordinated response, recovery, review, and verified action closure; exercise negative, stale, duplicate, bypass, and outage controls including threshold ambiguity, primary-channel loss, absent role, provider delay, evidence gap, failed containment, recovery dependency, and action recurrence.",
          "zh": "运行正向控制“一项代表性报告进入指挥、协同响应、恢复、复盘并完成行动验证关闭”，并执行包含“阈值歧义、主通道丢失、角色缺席、提供商延迟、证据缺口、遏制失败、恢复依赖和行动复发”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-17.1-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "17.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Run the positive control an approved data set following its declared use, access, transfer, retention, and disposal path; exercise negative, stale, duplicate, bypass, and outage controls including an unknown or misclassified copy, forbidden reader or flow, early deletion, expired retention, failed disposal, and provider residue.",
          "zh": "运行正向控制“按声明用途、访问、传输、保留和销毁路径流转的获批数据集”，并执行包含“未知或误分类副本、禁止读取者或流向、过早删除、保留过期、销毁失败和提供商残留”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-17.1-TST-08",
          "local_code": "TST-08",
          "display_code": "V08",
          "safeguard_id": "17.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Run the positive control an approved current process used for a representative decision; exercise negative, stale, duplicate, bypass, and outage controls including an obsolete version, missing approver, undocumented deviation, overdue review, and bypassed workflow.",
          "zh": "运行正向控制“使用当前获批流程完成一项代表性决策”，并执行包含“旧版本、审批人缺失、未记录偏离、逾期复核和绕过流程”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-17.1-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "17.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-17.1-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "17.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-17.1-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "17.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-17.1-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "17.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-17.1-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "17.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever reporting channels, monitoring and provider alerts, case systems, contact rosters, communication plans, forensic stores, recovery systems, exercises, and post-incident records change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 报告通道、监测与提供商告警、案件系统、联系人名册、通信计划、取证存储、恢复系统、演练和事后记录 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-17.1-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "17.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Use events, incidents, severity, ownership, acknowledgement, decision latency, communication success, containment, recovery, evidence gaps, and overdue corrective actions to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 事件、事故、严重度、责任、确认、决策延迟、通信成功、遏制、恢复、证据缺口和逾期纠正行动 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-17.1-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "17.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original data_lifecycle pattern analysis",
          "basis_zh": "SOSEC 原创 data_lifecycle 模式分析",
          "en": "Use known, unknown, classified, ownerless, over-retained, prematurely deleted, unapproved copy, blocked flow, held, and disposal-verified data sets to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已知、未知、已分类、无责任人、超期保留、过早删除、未批准副本、被阻断流、保全及销毁已验证数据集 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-17.1-OPS-08",
          "local_code": "OPS-08",
          "display_code": "R08",
          "safeguard_id": "17.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Use clause coverage, owner and reviewer completeness, approval age, triggered reviews, deviations, overdue actions, and superseded versions still in use to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 条款覆盖、责任人与复核人完整性、批准年龄、触发式复核、偏离、逾期行动及仍在使用的旧版本 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "17.2",
      "control": 17,
      "title_en": "Establish and Maintain Contact Information for Reporting Security Incidents",
      "title_zh": "事件联络信息",
      "first_ig": 1,
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Documentation",
      "security_function": "Govern",
      "patterns": [
        "incident",
        "inventory"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [],
        "variables": [
          "GV51",
          "M1",
          "M2"
        ],
        "metric_branches": 0,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [
        "annually"
      ],
      "implementation_contract": {
        "en": {
          "scope": "Contacts include internal response/leadership, providers, legal/privacy, regulators, law enforcement, cyber insurer/broker, outside counsel/forensics, ISAC/sector bodies, facilities and other stakeholders selected by scenario and jurisdiction.",
          "build": "Maintain a protected, offline-accessible contact directory and call tree, verify at least annually and on role/contract/regulatory change, and map contacts to incident thresholds and deadlines.",
          "proof": "Conduct a call-tree exercise without using the primary corporate directory/email, confirm identity and route, and test one provider/insurer/regulator escalation as permitted.",
          "boundary": "Publishing sensitive direct contacts too broadly creates privacy/phishing risk, while locking them inside a compromised system makes them useless."
        },
        "zh": {
          "scope": "包括内部响应/领导、服务商、法务/隐私、监管、执法、网络保险/经纪、外部律师/取证、ISAC、设施和其他按场景/司法区需要的联系人，保存角色、主备、Secure/OOB 路径和通知条件。",
          "build": "维护受保护且离线可用的目录/Call tree，至少每年及角色、合同、法规变化时验证，并关联事件门槛/期限；少存个人信息但保证下班可达。",
          "proof": "不依赖主企业目录/邮件演练 Call tree，确认身份和通道，并按许可测试一个服务商/保险/监管升级；记录失败联系人和纠正时间，抽查合同/保单号和司法区。",
          "boundary": "太广发布直联会有隐私/钓鱼风险，锁在被攻陷系统又无用。"
        }
      },
      "category_counts": {
        "outcome": 7,
        "scope": 7,
        "ownership": 7,
        "data": 7,
        "integration": 7,
        "control": 7,
        "timing": 7,
        "exception": 7,
        "evidence": 7,
        "security": 7,
        "testing": 7,
        "operations": 7
      },
      "requirement_count": 84,
      "requirements": [
        {
          "code": "CIS-17.2-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "17.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Establish and Maintain Contact Information for Reporting Security Incidents; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“事件联络信息”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-17.2-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "17.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 17.2, official Asset Class Documentation, Security Function Govern, and IG1 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 17.2、官方资产类别“文档与治理”、安全功能“治理”和首次出现的 IG1，并保存来源抓取日期。"
        },
        {
          "code": "CIS-17.2-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "17.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Contacts include internal response/leadership, providers, legal/privacy, regulators, law enforcement, cyber insurer/broker, outside counsel/forensics, ISAC/sector bodies, facilities and other stakeholders selected by scenario and jurisdiction.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“包括内部响应/领导、服务商、法务/隐私、监管、执法、网络保险/经纪、外部律师/取证、ISAC、设施和其他按场景/司法区需要的联系人，保存角色、主备、Secure/OOB 路径和通知条件。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-17.2-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "17.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-17.2-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "17.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Establish and Maintain Contact Information for Reporting Security Incidents to its operating object—security events and incidents, thresholds, reports, roles, decisions, communications, evidence, containment, recovery, review, and follow-up actions—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“事件联络信息”连接到其运营对象——安全事件与事故、阈值、报告、角色、决策、通信、证据、遏制、恢复、复盘和后续行动——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-17.2-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "17.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "For Establish and Maintain Contact Information for Reporting Security Incidents, express success as an observable decision over event-to-incident threshold, report, command, decision, communication, containment, evidence, recovery, review, and corrective action; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“事件联络信息”，以 事件到事故阈值、报告、指挥、决策、通信、遏制、证据、恢复、复盘和纠正行动 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-17.2-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "17.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "For Establish and Maintain Contact Information for Reporting Security Incidents, express success as an observable decision over observed, approved, unapproved, ownerless, stale, duplicate, and retired object identity; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“事件联络信息”，以 已观测、已批准、未批准、无责任人、陈旧、重复和已退役对象身份 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-17.2-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "17.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-17.2-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "17.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-17.2-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "17.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-17.2-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "17.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-17.2-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "17.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across ambiguous thresholds, compromised primary channels, absent personnel, cross-jurisdiction notice, provider incidents, insider cases, safety events, evidence loss, prolonged recovery, and unresolved actions; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 阈值歧义、主通信通道失陷、人员缺席、跨辖区通知、提供商事件、内部人案件、安全生产事件、证据丢失、长期恢复和未关闭行动 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-17.2-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "17.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Include ambiguous classification, unavailable personnel, compromised primary channels, provider and cross-border incidents, insider and safety cases, evidence loss, prolonged recovery, and unresolved actions in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 分类歧义、人员不可用、主通道失陷、提供商与跨境事件、内部人与安全生产案件、证据丢失、长期恢复和未关闭行动 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-17.2-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "17.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Include dormant, ephemeral, disconnected, externally managed, provider-held, aliased, cloned, and cross-tenant objects in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 休眠、短生、离线、外部托管、提供商持有、别名、克隆和跨租户对象 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-17.2-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "17.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-17.2-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "17.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-17.2-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "17.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-17.2-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "17.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-17.2-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "17.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind incident command and responders, IT and security, legal/privacy, communications, HR, facilities, business owners, executives, providers, insurers, and authorities to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 事件指挥与响应人员、IT 与安全、法务/隐私、传播、HR、设施、业务责任人、管理层、提供商、保险和主管机关 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-17.2-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "17.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Name who may transition reported/detected → triaged → declared → commanded → contained → eradicated/recovered → reviewed → actions retested and closed, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 报告/检测 → 分流 → 宣告 → 指挥 → 遏制 → 根除/恢复 → 复盘 → 行动复测关闭，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-17.2-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "17.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Name who may transition discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-17.2-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "17.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-17.2-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "17.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-17.2-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "17.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV51, M1, M2) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV51, M1, M2）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-17.2-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "17.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-17.2-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "17.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the incident taxonomy, case, command, communication, evidence, and action authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把事件分类、案件、指挥、通信、证据与行动权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-17.2-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "17.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle reported/detected → triaged → declared → commanded → contained → eradicated/recovered → reviewed → actions retested and closed.",
          "zh": "对生命周期“报告/检测 → 分流 → 宣告 → 指挥 → 遏制 → 根除/恢复 → 复盘 → 行动复测关闭”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-17.2-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "17.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence.",
          "zh": "对生命周期“发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-17.2-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "17.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for no explicit predecessor in the pinned CAS page; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 固定 CAS 页面没有列出显式前置项 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-17.2-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "17.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-17.2-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "17.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-17.2-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "17.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-17.2-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "17.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile reporting channels, monitoring and provider alerts, case systems, contact rosters, communication plans, forensic stores, recovery systems, exercises, and post-incident records and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 报告通道、监测与提供商告警、案件系统、联系人名册、通信计划、取证存储、恢复系统、演练和事后记录，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-17.2-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "17.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Require every connector carrying event-to-incident threshold, report, command, decision, communication, containment, evidence, recovery, review, and corrective action to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 事件到事故阈值、报告、指挥、决策、通信、遏制、证据、恢复、复盘和纠正行动 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-17.2-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "17.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Require every connector carrying observed, approved, unapproved, ownerless, stale, duplicate, and retired object identity to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 已观测、已批准、未批准、无责任人、陈旧、重复和已退役对象身份 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-17.2-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "17.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Maintain a protected, offline-accessible contact directory and call tree, verify at least annually and on role/contract/regulatory change, and map contacts to incident thresholds and deadlines.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“维护受保护且离线可用的目录/Call tree，至少每年及角色、合同、法规变化时验证，并关联事件门槛/期限；少存个人信息但保证下班可达。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-17.2-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "17.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-17.2-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "17.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-17.2-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "17.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-17.2-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "17.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the incident taxonomy, case, command, communication, evidence, and action authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在事件分类、案件、指挥、通信、证据与行动权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-17.2-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "17.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Implement the explicit state machine reported/detected → triaged → declared → commanded → contained → eradicated/recovered → reviewed → actions retested and closed; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“报告/检测 → 分流 → 宣告 → 指挥 → 遏制 → 根除/恢复 → 复盘 → 行动复测关闭”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-17.2-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "17.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Implement the explicit state machine discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-17.2-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "17.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (annually); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（annually）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-17.2-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "17.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-17.2-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "17.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-17.2-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "17.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-17.2-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "17.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in security events and incidents, thresholds, reports, roles, decisions, communications, evidence, containment, recovery, review, and follow-up actions; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 安全事件与事故、阈值、报告、角色、决策、通信、证据、遏制、恢复、复盘和后续行动 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-17.2-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "17.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for reported/detected → triaged → declared → commanded → contained → eradicated/recovered → reviewed → actions retested and closed; alert before each deadline becomes overdue.",
          "zh": "为“报告/检测 → 分流 → 宣告 → 指挥 → 遏制 → 根除/恢复 → 复盘 → 行动复测关闭”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-17.2-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "17.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence; alert before each deadline becomes overdue.",
          "zh": "为“发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-17.2-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "17.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “Publishing sensitive direct contacts too broadly creates privacy/phishing risk, while locking them inside a compromised system makes them useless.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“太广发布直联会有隐私/钓鱼风险，锁在被攻陷系统又无用。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-17.2-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "17.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-17.2-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "17.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-17.2-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "17.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-17.2-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "17.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat ambiguous thresholds, compromised primary channels, absent personnel, cross-jurisdiction notice, provider incidents, insider cases, safety events, evidence loss, prolonged recovery, and unresolved actions as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 阈值歧义、主通信通道失陷、人员缺席、跨辖区通知、提供商事件、内部人案件、安全生产事件、证据丢失、长期恢复和未关闭行动 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-17.2-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "17.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Treat ambiguous classification, unavailable personnel, compromised primary channels, provider and cross-border incidents, insider and safety cases, evidence loss, prolonged recovery, and unresolved actions as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 分类歧义、人员不可用、主通道失陷、提供商与跨境事件、内部人与安全生产案件、证据丢失、长期恢复和未关闭行动 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-17.2-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "17.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Treat dormant, ephemeral, disconnected, externally managed, provider-held, aliased, cloned, and cross-tenant objects as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 休眠、短生、离线、外部托管、提供商持有、别名、克隆和跨租户对象 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-17.2-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "17.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Conduct a call-tree exercise without using the primary corporate directory/email, confirm identity and route, and test one provider/insurer/regulator escalation as permitted.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“不依赖主企业目录/邮件演练 Call tree，确认身份和通道，并按许可测试一个服务商/保险/监管升级；记录失败联系人和纠正时间，抽查合同/保单号和司法区。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-17.2-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "17.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-17.2-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "17.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 0 pinned CAS metric branch(es), 3 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 0 个指标分支、3 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-17.2-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "17.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-17.2-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "17.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the incident taxonomy, case, command, communication, evidence, and action authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以事件分类、案件、指挥、通信、证据与行动权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-17.2-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "17.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Publish events, incidents, severity, ownership, acknowledgement, decision latency, communication success, containment, recovery, evidence gaps, and overdue corrective actions with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 事件、事故、严重度、责任、确认、决策延迟、通信成功、遏制、恢复、证据缺口和逾期纠正行动，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-17.2-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "17.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Publish matched, missing, duplicate, stale, ownerless, unapproved, unevaluable, and retired-without-proof counts with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 匹配、缺失、重复、陈旧、无责任人、未批准、不可评估及无证明退役数量，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-17.2-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "17.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-17.2-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "17.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-17.2-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "17.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-17.2-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "17.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-17.2-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "17.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the incident taxonomy, case, command, communication, evidence, and action authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护事件分类、案件、指挥、通信、证据与行动权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-17.2-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "17.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Restrict authority to change reported/detected → triaged → declared → commanded → contained → eradicated/recovered → reviewed → actions retested and closed; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“报告/检测 → 分流 → 宣告 → 指挥 → 遏制 → 根除/恢复 → 复盘 → 行动复测关闭”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-17.2-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "17.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Restrict authority to change discovered → pending identity → approved/unapproved → contained/exception → retired with custody evidence; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“发现 → 待定身份 → 批准/未批准 → 遏制/例外 → 带保管证据退役”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-17.2-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "17.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-17.2-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "17.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-17.2-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "17.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-17.2-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "17.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-17.2-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "17.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise event-versus-incident triage, primary and backup reporting, out-of-band communication, containment and recovery decisions, exercise injects, provider coordination, and action retest through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 事件与事故分流、主备报告、带外通信、遏制与恢复决策、演练注入、提供商协同和行动复测，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-17.2-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "17.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Run the positive control a representative report that reaches command, coordinated response, recovery, review, and verified action closure; exercise negative, stale, duplicate, bypass, and outage controls including threshold ambiguity, primary-channel loss, absent role, provider delay, evidence gap, failed containment, recovery dependency, and action recurrence.",
          "zh": "运行正向控制“一项代表性报告进入指挥、协同响应、恢复、复盘并完成行动验证关闭”，并执行包含“阈值歧义、主通道丢失、角色缺席、提供商延迟、证据缺口、遏制失败、恢复依赖和行动复发”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-17.2-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "17.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Run the positive control a seeded approved object reconciled from two independent sources; exercise negative, stale, duplicate, bypass, and outage controls including an unknown object, duplicate identity, stale record, vanished object, failed source, and cross-tenant collision.",
          "zh": "运行正向控制“从两个独立来源对账的一项植入已批准对象”，并执行包含“未知对象、重复身份、陈旧记录、突然消失对象、失效来源和跨租户碰撞”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-17.2-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "17.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-17.2-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "17.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-17.2-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "17.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-17.2-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "17.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-17.2-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "17.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever reporting channels, monitoring and provider alerts, case systems, contact rosters, communication plans, forensic stores, recovery systems, exercises, and post-incident records change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 报告通道、监测与提供商告警、案件系统、联系人名册、通信计划、取证存储、恢复系统、演练和事后记录 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-17.2-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "17.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Use events, incidents, severity, ownership, acknowledgement, decision latency, communication success, containment, recovery, evidence gaps, and overdue corrective actions to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 事件、事故、严重度、责任、确认、决策延迟、通信成功、遏制、恢复、证据缺口和逾期纠正行动 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-17.2-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "17.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original inventory pattern analysis",
          "basis_zh": "SOSEC 原创 inventory 模式分析",
          "en": "Use matched, missing, duplicate, stale, ownerless, unapproved, unevaluable, and retired-without-proof counts to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 匹配、缺失、重复、陈旧、无责任人、未批准、不可评估及无证明退役数量 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "17.3",
      "control": 17,
      "title_en": "Establish and Maintain an Enterprise Process for Reporting Incidents",
      "title_zh": "全员事件报告流程",
      "first_ig": 1,
      "implementation_groups": [
        1,
        2,
        3
      ],
      "asset_class": "Documentation",
      "security_function": "Govern",
      "patterns": [
        "incident",
        "governance"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [],
        "variables": [
          "GV51",
          "M1",
          "M2",
          "M3",
          "M4"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [
        "annually"
      ],
      "implementation_contract": {
        "en": {
          "scope": "The reporting process is available to the whole workforce and states when, where, how and what minimum context to report, with urgent and anonymous/alternative paths as appropriate.",
          "build": "Provide memorable channels, after-hours coverage, accessible/localized instructions, acknowledgement, privacy/non-retaliation and evidence-preservation guidance.",
          "proof": "Have varied workforce members submit test reports from normal, locked-out, remote and after-hours contexts; verify receipt, useful metadata, triage and feedback.",
          "boundary": "An intranet-only form can fail during account compromise."
        },
        "zh": {
          "scope": "对全体人员公开报告流程，说明何时、向谁、怎样和最低上下文，按需有紧急、匿名/替代路径；接受不确定观察，不要求报告者先证明/定级。",
          "build": "提供易记、下班可用、无障碍/本地化入口，确认、隐私和非报复，并讲证据保全；接分诊、关联和升级，每年及组织、工具、威胁变化时更新。",
          "proof": "让不同人员从正常、锁号、远程和下班环境提交测试报告，验证接收、元数据、分诊与反馈；检查公开入口能否在身份/邮件故障时使用，重复报告能否关联。",
          "boundary": "只有内网表单在账户受损时会失败。"
        }
      },
      "category_counts": {
        "outcome": 7,
        "scope": 7,
        "ownership": 7,
        "data": 7,
        "integration": 7,
        "control": 7,
        "timing": 7,
        "exception": 7,
        "evidence": 7,
        "security": 7,
        "testing": 7,
        "operations": 7
      },
      "requirement_count": 84,
      "requirements": [
        {
          "code": "CIS-17.3-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "17.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Establish and Maintain an Enterprise Process for Reporting Incidents; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“全员事件报告流程”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-17.3-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "17.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 17.3, official Asset Class Documentation, Security Function Govern, and IG1 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 17.3、官方资产类别“文档与治理”、安全功能“治理”和首次出现的 IG1，并保存来源抓取日期。"
        },
        {
          "code": "CIS-17.3-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "17.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “The reporting process is available to the whole workforce and states when, where, how and what minimum context to report, with urgent and anonymous/alternative paths as appropriate.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“对全体人员公开报告流程，说明何时、向谁、怎样和最低上下文，按需有紧急、匿名/替代路径；接受不确定观察，不要求报告者先证明/定级。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-17.3-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "17.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-17.3-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "17.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Establish and Maintain an Enterprise Process for Reporting Incidents to its operating object—security events and incidents, thresholds, reports, roles, decisions, communications, evidence, containment, recovery, review, and follow-up actions—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“全员事件报告流程”连接到其运营对象——安全事件与事故、阈值、报告、角色、决策、通信、证据、遏制、恢复、复盘和后续行动——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-17.3-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "17.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "For Establish and Maintain an Enterprise Process for Reporting Incidents, express success as an observable decision over event-to-incident threshold, report, command, decision, communication, containment, evidence, recovery, review, and corrective action; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“全员事件报告流程”，以 事件到事故阈值、报告、指挥、决策、通信、遏制、证据、恢复、复盘和纠正行动 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-17.3-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "17.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "For Establish and Maintain an Enterprise Process for Reporting Incidents, express success as an observable decision over a documented decision system with policy, process, procedure, accountable owner, approval, and review; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“全员事件报告流程”，以 包含策略、流程、程序、责任人、审批和复核的文档化决策系统 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-17.3-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "17.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-17.3-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "17.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-17.3-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "17.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-17.3-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "17.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-17.3-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "17.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across ambiguous thresholds, compromised primary channels, absent personnel, cross-jurisdiction notice, provider incidents, insider cases, safety events, evidence loss, prolonged recovery, and unresolved actions; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 阈值歧义、主通信通道失陷、人员缺席、跨辖区通知、提供商事件、内部人案件、安全生产事件、证据丢失、长期恢复和未关闭行动 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-17.3-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "17.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Include ambiguous classification, unavailable personnel, compromised primary channels, provider and cross-border incidents, insider and safety cases, evidence loss, prolonged recovery, and unresolved actions in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 分类歧义、人员不可用、主通道失陷、提供商与跨境事件、内部人与安全生产案件、证据丢失、长期恢复和未关闭行动 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-17.3-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "17.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Include missing policy clauses, conflicting authorities, local deviations, obsolete documentation, and decisions made outside the governed workflow in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 策略条款缺失、权限冲突、本地偏离、文档过期及绕过治理流程的决策 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-17.3-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "17.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-17.3-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "17.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-17.3-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "17.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-17.3-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "17.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-17.3-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "17.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind incident command and responders, IT and security, legal/privacy, communications, HR, facilities, business owners, executives, providers, insurers, and authorities to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 事件指挥与响应人员、IT 与安全、法务/隐私、传播、HR、设施、业务责任人、管理层、提供商、保险和主管机关 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-17.3-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "17.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Name who may transition reported/detected → triaged → declared → commanded → contained → eradicated/recovered → reviewed → actions retested and closed, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 报告/检测 → 分流 → 宣告 → 指挥 → 遏制 → 根除/恢复 → 复盘 → 行动复测关闭，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-17.3-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "17.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Name who may transition draft → reviewed → approved → effective → exception/withdrawn → superseded, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-17.3-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "17.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-17.3-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "17.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-17.3-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "17.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV51, M1, M2, M3, M4) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV51, M1, M2, M3, M4）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-17.3-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "17.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-17.3-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "17.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the incident taxonomy, case, command, communication, evidence, and action authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把事件分类、案件、指挥、通信、证据与行动权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-17.3-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "17.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle reported/detected → triaged → declared → commanded → contained → eradicated/recovered → reviewed → actions retested and closed.",
          "zh": "对生命周期“报告/检测 → 分流 → 宣告 → 指挥 → 遏制 → 根除/恢复 → 复盘 → 行动复测关闭”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-17.3-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "17.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle draft → reviewed → approved → effective → exception/withdrawn → superseded.",
          "zh": "对生命周期“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-17.3-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "17.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for no explicit predecessor in the pinned CAS page; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 固定 CAS 页面没有列出显式前置项 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-17.3-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "17.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-17.3-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "17.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-17.3-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "17.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-17.3-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "17.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile reporting channels, monitoring and provider alerts, case systems, contact rosters, communication plans, forensic stores, recovery systems, exercises, and post-incident records and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 报告通道、监测与提供商告警、案件系统、联系人名册、通信计划、取证存储、恢复系统、演练和事后记录，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-17.3-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "17.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Require every connector carrying event-to-incident threshold, report, command, decision, communication, containment, evidence, recovery, review, and corrective action to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 事件到事故阈值、报告、指挥、决策、通信、遏制、证据、恢复、复盘和纠正行动 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-17.3-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "17.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Require every connector carrying a documented decision system with policy, process, procedure, accountable owner, approval, and review to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 包含策略、流程、程序、责任人、审批和复核的文档化决策系统 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-17.3-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "17.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Provide memorable channels, after-hours coverage, accessible/localized instructions, acknowledgement, privacy/non-retaliation and evidence-preservation guidance.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“提供易记、下班可用、无障碍/本地化入口，确认、隐私和非报复，并讲证据保全；接分诊、关联和升级，每年及组织、工具、威胁变化时更新。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-17.3-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "17.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-17.3-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "17.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-17.3-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "17.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-17.3-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "17.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the incident taxonomy, case, command, communication, evidence, and action authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在事件分类、案件、指挥、通信、证据与行动权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-17.3-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "17.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Implement the explicit state machine reported/detected → triaged → declared → commanded → contained → eradicated/recovered → reviewed → actions retested and closed; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“报告/检测 → 分流 → 宣告 → 指挥 → 遏制 → 根除/恢复 → 复盘 → 行动复测关闭”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-17.3-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "17.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Implement the explicit state machine draft → reviewed → approved → effective → exception/withdrawn → superseded; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-17.3-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "17.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (annually); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（annually）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-17.3-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "17.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-17.3-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "17.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-17.3-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "17.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-17.3-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "17.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in security events and incidents, thresholds, reports, roles, decisions, communications, evidence, containment, recovery, review, and follow-up actions; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 安全事件与事故、阈值、报告、角色、决策、通信、证据、遏制、恢复、复盘和后续行动 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-17.3-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "17.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for reported/detected → triaged → declared → commanded → contained → eradicated/recovered → reviewed → actions retested and closed; alert before each deadline becomes overdue.",
          "zh": "为“报告/检测 → 分流 → 宣告 → 指挥 → 遏制 → 根除/恢复 → 复盘 → 行动复测关闭”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-17.3-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "17.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for draft → reviewed → approved → effective → exception/withdrawn → superseded; alert before each deadline becomes overdue.",
          "zh": "为“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-17.3-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "17.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “An intranet-only form can fail during account compromise.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“只有内网表单在账户受损时会失败。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-17.3-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "17.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-17.3-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "17.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-17.3-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "17.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-17.3-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "17.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat ambiguous thresholds, compromised primary channels, absent personnel, cross-jurisdiction notice, provider incidents, insider cases, safety events, evidence loss, prolonged recovery, and unresolved actions as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 阈值歧义、主通信通道失陷、人员缺席、跨辖区通知、提供商事件、内部人案件、安全生产事件、证据丢失、长期恢复和未关闭行动 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-17.3-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "17.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Treat ambiguous classification, unavailable personnel, compromised primary channels, provider and cross-border incidents, insider and safety cases, evidence loss, prolonged recovery, and unresolved actions as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 分类歧义、人员不可用、主通道失陷、提供商与跨境事件、内部人与安全生产案件、证据丢失、长期恢复和未关闭行动 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-17.3-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "17.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Treat missing policy clauses, conflicting authorities, local deviations, obsolete documentation, and decisions made outside the governed workflow as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 策略条款缺失、权限冲突、本地偏离、文档过期及绕过治理流程的决策 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-17.3-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "17.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Have varied workforce members submit test reports from normal, locked-out, remote and after-hours contexts; verify receipt, useful metadata, triage and feedback.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“让不同人员从正常、锁号、远程和下班环境提交测试报告，验证接收、元数据、分诊与反馈；检查公开入口能否在身份/邮件故障时使用，重复报告能否关联。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-17.3-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "17.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-17.3-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "17.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 5 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、5 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-17.3-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "17.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-17.3-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "17.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the incident taxonomy, case, command, communication, evidence, and action authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以事件分类、案件、指挥、通信、证据与行动权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-17.3-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "17.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Publish events, incidents, severity, ownership, acknowledgement, decision latency, communication success, containment, recovery, evidence gaps, and overdue corrective actions with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 事件、事故、严重度、责任、确认、决策延迟、通信成功、遏制、恢复、证据缺口和逾期纠正行动，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-17.3-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "17.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Publish clause coverage, owner and reviewer completeness, approval age, triggered reviews, deviations, overdue actions, and superseded versions still in use with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 条款覆盖、责任人与复核人完整性、批准年龄、触发式复核、偏离、逾期行动及仍在使用的旧版本，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-17.3-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "17.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-17.3-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "17.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-17.3-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "17.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-17.3-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "17.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-17.3-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "17.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the incident taxonomy, case, command, communication, evidence, and action authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护事件分类、案件、指挥、通信、证据与行动权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-17.3-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "17.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Restrict authority to change reported/detected → triaged → declared → commanded → contained → eradicated/recovered → reviewed → actions retested and closed; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“报告/检测 → 分流 → 宣告 → 指挥 → 遏制 → 根除/恢复 → 复盘 → 行动复测关闭”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-17.3-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "17.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Restrict authority to change draft → reviewed → approved → effective → exception/withdrawn → superseded; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-17.3-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "17.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-17.3-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "17.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-17.3-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "17.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-17.3-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "17.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-17.3-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "17.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise event-versus-incident triage, primary and backup reporting, out-of-band communication, containment and recovery decisions, exercise injects, provider coordination, and action retest through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 事件与事故分流、主备报告、带外通信、遏制与恢复决策、演练注入、提供商协同和行动复测，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-17.3-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "17.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Run the positive control a representative report that reaches command, coordinated response, recovery, review, and verified action closure; exercise negative, stale, duplicate, bypass, and outage controls including threshold ambiguity, primary-channel loss, absent role, provider delay, evidence gap, failed containment, recovery dependency, and action recurrence.",
          "zh": "运行正向控制“一项代表性报告进入指挥、协同响应、恢复、复盘并完成行动验证关闭”，并执行包含“阈值歧义、主通道丢失、角色缺席、提供商延迟、证据缺口、遏制失败、恢复依赖和行动复发”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-17.3-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "17.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Run the positive control an approved current process used for a representative decision; exercise negative, stale, duplicate, bypass, and outage controls including an obsolete version, missing approver, undocumented deviation, overdue review, and bypassed workflow.",
          "zh": "运行正向控制“使用当前获批流程完成一项代表性决策”，并执行包含“旧版本、审批人缺失、未记录偏离、逾期复核和绕过流程”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-17.3-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "17.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-17.3-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "17.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-17.3-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "17.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-17.3-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "17.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-17.3-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "17.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever reporting channels, monitoring and provider alerts, case systems, contact rosters, communication plans, forensic stores, recovery systems, exercises, and post-incident records change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 报告通道、监测与提供商告警、案件系统、联系人名册、通信计划、取证存储、恢复系统、演练和事后记录 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-17.3-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "17.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Use events, incidents, severity, ownership, acknowledgement, decision latency, communication success, containment, recovery, evidence gaps, and overdue corrective actions to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 事件、事故、严重度、责任、确认、决策延迟、通信成功、遏制、恢复、证据缺口和逾期纠正行动 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-17.3-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "17.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Use clause coverage, owner and reviewer completeness, approval age, triggered reviews, deviations, overdue actions, and superseded versions still in use to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 条款覆盖、责任人与复核人完整性、批准年龄、触发式复核、偏离、逾期行动及仍在使用的旧版本 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "17.4",
      "control": 17,
      "title_en": "Establish and Maintain an Incident Response Process",
      "title_zh": "事件响应流程",
      "first_ig": 2,
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Documentation",
      "security_function": "Govern",
      "patterns": [
        "incident",
        "governance"
      ],
      "expanded_complexity": true,
      "cas_context": {
        "dependencies": [],
        "variables": [
          "GV51",
          "GV52",
          "M1",
          "M2",
          "M3"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [
        "annually"
      ],
      "implementation_contract": {
        "en": {
          "scope": "The process covers preparation, detection/validation, classification, containment, evidence, eradication, recovery, communications, compliance and closure for cyber, privacy, availability and provider incidents.",
          "build": "Document and equip workflows, evidence/case systems, legal/privacy requirements, communication, third-party coordination, recovery criteria and escalation; integrate business continuity and vulnerability lessons.",
          "proof": "Run a scenario through alert/report, declaration, containment, evidence, business decision, recovery and notification, including ambiguous facts and failed tools.",
          "boundary": "CAS checks three document topics only."
        },
        "zh": {
          "scope": "覆盖准备、检测/验证、分级、遏制、证据、清除、恢复、通信、合规和结案，适用于网络、隐私、可用与供应商事件；关联角色、决策权和场景 Playbook，但不假装所有事件线性。",
          "build": "写清并配齐工作流、证据/案件系统、法务/隐私要求、沟通、第三方协同、恢复标准和升级；对接连续性与漏洞学习，每年及演练、事件、架构/要求重大变化后更新。",
          "proof": "从告警/报告跑到宣告、遏制、证据、业务决定、恢复和通知，加入事实模糊和工具失败；测决定/动作时间、交接、缺失权限/数据和偏离，并复测重大修正。",
          "boundary": "CAS 只检查三类文档主题。"
        }
      },
      "category_counts": {
        "outcome": 8,
        "scope": 8,
        "ownership": 8,
        "data": 8,
        "integration": 8,
        "control": 8,
        "timing": 8,
        "exception": 8,
        "evidence": 8,
        "security": 8,
        "testing": 8,
        "operations": 8
      },
      "requirement_count": 96,
      "requirements": [
        {
          "code": "CIS-17.4-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "17.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Establish and Maintain an Incident Response Process; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“事件响应流程”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-17.4-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "17.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 17.4, official Asset Class Documentation, Security Function Govern, and IG2 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 17.4、官方资产类别“文档与治理”、安全功能“治理”和首次出现的 IG2，并保存来源抓取日期。"
        },
        {
          "code": "CIS-17.4-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "17.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “The process covers preparation, detection/validation, classification, containment, evidence, eradication, recovery, communications, compliance and closure for cyber, privacy, availability and provider incidents.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“覆盖准备、检测/验证、分级、遏制、证据、清除、恢复、通信、合规和结案，适用于网络、隐私、可用与供应商事件；关联角色、决策权和场景 Playbook，但不假装所有事件线性。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-17.4-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "17.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-17.4-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "17.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Establish and Maintain an Incident Response Process to its operating object—security events and incidents, thresholds, reports, roles, decisions, communications, evidence, containment, recovery, review, and follow-up actions—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“事件响应流程”连接到其运营对象——安全事件与事故、阈值、报告、角色、决策、通信、证据、遏制、恢复、复盘和后续行动——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-17.4-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "17.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "For Establish and Maintain an Incident Response Process, express success as an observable decision over event-to-incident threshold, report, command, decision, communication, containment, evidence, recovery, review, and corrective action; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“事件响应流程”，以 事件到事故阈值、报告、指挥、决策、通信、遏制、证据、恢复、复盘和纠正行动 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-17.4-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "17.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "For Establish and Maintain an Incident Response Process, express success as an observable decision over a documented decision system with policy, process, procedure, accountable owner, approval, and review; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“事件响应流程”，以 包含策略、流程、程序、责任人、审批和复核的文档化决策系统 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-17.4-OUT-08",
          "local_code": "OUT-08",
          "display_code": "O08",
          "safeguard_id": "17.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "For the expanded Establish and Maintain an Incident Response Process scope, resolve conflicts among security, safety, privacy, legal, availability, customer, and operational objectives through an explicit risk decision.",
          "zh": "对“事件响应流程”的扩展范围，通过显式风险决策解决安全、安全生产、隐私、法律、可用性、客户和运营目标冲突。"
        },
        {
          "code": "CIS-17.4-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "17.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-17.4-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "17.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-17.4-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "17.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-17.4-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "17.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-17.4-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "17.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across ambiguous thresholds, compromised primary channels, absent personnel, cross-jurisdiction notice, provider incidents, insider cases, safety events, evidence loss, prolonged recovery, and unresolved actions; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 阈值歧义、主通信通道失陷、人员缺席、跨辖区通知、提供商事件、内部人案件、安全生产事件、证据丢失、长期恢复和未关闭行动 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-17.4-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "17.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Include ambiguous classification, unavailable personnel, compromised primary channels, provider and cross-border incidents, insider and safety cases, evidence loss, prolonged recovery, and unresolved actions in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 分类歧义、人员不可用、主通道失陷、提供商与跨境事件、内部人与安全生产案件、证据丢失、长期恢复和未关闭行动 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-17.4-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "17.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Include missing policy clauses, conflicting authorities, local deviations, obsolete documentation, and decisions made outside the governed workflow in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 策略条款缺失、权限冲突、本地偏离、文档过期及绕过治理流程的决策 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-17.4-SCP-08",
          "local_code": "SCP-08",
          "display_code": "P08",
          "safeguard_id": "17.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Define nested scope at enterprise, business service, tenant, environment, platform, object, identity, data set, and transaction levels; prohibit a parent result from hiding a failing child.",
          "zh": "按企业、业务服务、租户、环境、平台、对象、身份、数据集和交易定义嵌套范围，禁止父级结果遮蔽失败子级。"
        },
        {
          "code": "CIS-17.4-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "17.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-17.4-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "17.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-17.4-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "17.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-17.4-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "17.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-17.4-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "17.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind incident command and responders, IT and security, legal/privacy, communications, HR, facilities, business owners, executives, providers, insurers, and authorities to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 事件指挥与响应人员、IT 与安全、法务/隐私、传播、HR、设施、业务责任人、管理层、提供商、保险和主管机关 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-17.4-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "17.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Name who may transition reported/detected → triaged → declared → commanded → contained → eradicated/recovered → reviewed → actions retested and closed, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 报告/检测 → 分流 → 宣告 → 指挥 → 遏制 → 根除/恢复 → 复盘 → 行动复测关闭，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-17.4-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "17.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Name who may transition draft → reviewed → approved → effective → exception/withdrawn → superseded, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-17.4-OWN-08",
          "local_code": "OWN-08",
          "display_code": "W08",
          "safeguard_id": "17.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Model delegated authority, quorum or dual approval where warranted, escalation deadlines, provider handoffs, conflict resolution, and executive risk acceptance.",
          "zh": "建模委派权限、必要时的双人或法定人数审批、升级期限、提供商交接、冲突解决和管理层风险接受。"
        },
        {
          "code": "CIS-17.4-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "17.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-17.4-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "17.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-17.4-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "17.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV51, GV52, M1, M2, M3) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV51, GV52, M1, M2, M3）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-17.4-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "17.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-17.4-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "17.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the incident taxonomy, case, command, communication, evidence, and action authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把事件分类、案件、指挥、通信、证据与行动权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-17.4-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "17.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle reported/detected → triaged → declared → commanded → contained → eradicated/recovered → reviewed → actions retested and closed.",
          "zh": "对生命周期“报告/检测 → 分流 → 宣告 → 指挥 → 遏制 → 根除/恢复 → 复盘 → 行动复测关闭”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-17.4-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "17.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle draft → reviewed → approved → effective → exception/withdrawn → superseded.",
          "zh": "对生命周期“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-17.4-DAT-08",
          "local_code": "DAT-08",
          "display_code": "D08",
          "safeguard_id": "17.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Version schemas and state transitions with migration, backfill, deduplication, lineage, historical denominator, deletion, and rollback semantics.",
          "zh": "对模式和状态转换做版本管理，定义迁移、回填、去重、血缘、历史分母、删除和回滚语义。"
        },
        {
          "code": "CIS-17.4-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "17.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for no explicit predecessor in the pinned CAS page; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 固定 CAS 页面没有列出显式前置项 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-17.4-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "17.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-17.4-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "17.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-17.4-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "17.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-17.4-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "17.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile reporting channels, monitoring and provider alerts, case systems, contact rosters, communication plans, forensic stores, recovery systems, exercises, and post-incident records and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 报告通道、监测与提供商告警、案件系统、联系人名册、通信计划、取证存储、恢复系统、演练和事后记录，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-17.4-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "17.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Require every connector carrying event-to-incident threshold, report, command, decision, communication, containment, evidence, recovery, review, and corrective action to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 事件到事故阈值、报告、指挥、决策、通信、遏制、证据、恢复、复盘和纠正行动 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-17.4-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "17.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Require every connector carrying a documented decision system with policy, process, procedure, accountable owner, approval, and review to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 包含策略、流程、程序、责任人、审批和复核的文档化决策系统 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-17.4-INT-08",
          "local_code": "INT-08",
          "display_code": "I08",
          "safeguard_id": "17.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Define consistency rules across disagreeing sources, source precedence, confidence, reconciliation queues, dead-letter handling, reprocessing, and end-to-end trace identity.",
          "zh": "定义冲突来源的一致性、优先级、置信度、对账队列、死信、重处理和端到端追踪身份。"
        },
        {
          "code": "CIS-17.4-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "17.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Document and equip workflows, evidence/case systems, legal/privacy requirements, communication, third-party coordination, recovery criteria and escalation; integrate business continuity and vulnerability lessons.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“写清并配齐工作流、证据/案件系统、法务/隐私要求、沟通、第三方协同、恢复标准和升级；对接连续性与漏洞学习，每年及演练、事件、架构/要求重大变化后更新。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-17.4-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "17.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-17.4-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "17.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-17.4-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "17.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-17.4-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "17.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the incident taxonomy, case, command, communication, evidence, and action authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在事件分类、案件、指挥、通信、证据与行动权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-17.4-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "17.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Implement the explicit state machine reported/detected → triaged → declared → commanded → contained → eradicated/recovered → reviewed → actions retested and closed; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“报告/检测 → 分流 → 宣告 → 指挥 → 遏制 → 根除/恢复 → 复盘 → 行动复测关闭”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-17.4-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "17.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Implement the explicit state machine draft → reviewed → approved → effective → exception/withdrawn → superseded; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-17.4-CTL-08",
          "local_code": "CTL-08",
          "display_code": "C08",
          "safeguard_id": "17.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Specify concurrent decisions, partial success, compensating transactions, repeated requests, stale policy, dependency outage, and recovery from an interrupted state transition.",
          "zh": "定义并发决策、部分成功、补偿事务、重复请求、陈旧策略、依赖中断和中途状态转换恢复。"
        },
        {
          "code": "CIS-17.4-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "17.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (annually); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（annually）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-17.4-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "17.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-17.4-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "17.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-17.4-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "17.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-17.4-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "17.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in security events and incidents, thresholds, reports, roles, decisions, communications, evidence, containment, recovery, review, and follow-up actions; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 安全事件与事故、阈值、报告、角色、决策、通信、证据、遏制、恢复、复盘和后续行动 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-17.4-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "17.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for reported/detected → triaged → declared → commanded → contained → eradicated/recovered → reviewed → actions retested and closed; alert before each deadline becomes overdue.",
          "zh": "为“报告/检测 → 分流 → 宣告 → 指挥 → 遏制 → 根除/恢复 → 复盘 → 行动复测关闭”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-17.4-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "17.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for draft → reviewed → approved → effective → exception/withdrawn → superseded; alert before each deadline becomes overdue.",
          "zh": "为“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-17.4-TIM-08",
          "local_code": "TIM-08",
          "display_code": "T08",
          "safeguard_id": "17.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Allocate an end-to-end SLO budget across discovery, collection, processing, approval, enforcement, verification, and closure; prioritize overdue work by consequence and exposure.",
          "zh": "把端到端 SLO 预算分配到发现、采集、处理、审批、执行、验证和关闭，并按后果与暴露排列逾期工作。"
        },
        {
          "code": "CIS-17.4-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "17.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “CAS checks three document topics only.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“CAS 只检查三类文档主题。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-17.4-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "17.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-17.4-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "17.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-17.4-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "17.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-17.4-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "17.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat ambiguous thresholds, compromised primary channels, absent personnel, cross-jurisdiction notice, provider incidents, insider cases, safety events, evidence loss, prolonged recovery, and unresolved actions as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 阈值歧义、主通信通道失陷、人员缺席、跨辖区通知、提供商事件、内部人案件、安全生产事件、证据丢失、长期恢复和未关闭行动 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-17.4-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "17.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Treat ambiguous classification, unavailable personnel, compromised primary channels, provider and cross-border incidents, insider and safety cases, evidence loss, prolonged recovery, and unresolved actions as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 分类歧义、人员不可用、主通道失陷、提供商与跨境事件、内部人与安全生产案件、证据丢失、长期恢复和未关闭行动 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-17.4-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "17.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Treat missing policy clauses, conflicting authorities, local deviations, obsolete documentation, and decisions made outside the governed workflow as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 策略条款缺失、权限冲突、本地偏离、文档过期及绕过治理流程的决策 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-17.4-EXC-08",
          "local_code": "EXC-08",
          "display_code": "X08",
          "safeguard_id": "17.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Exercise compound failures where an exception, stale source, provider outage, unavailable owner, and degraded control overlap; define one safe command and one accountable decision.",
          "zh": "演练例外、陈旧来源、提供商中断、责任人不可用和控制降级同时出现的复合故障，明确一条安全指令和一个责任决策。"
        },
        {
          "code": "CIS-17.4-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "17.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Run a scenario through alert/report, declaration, containment, evidence, business decision, recovery and notification, including ambiguous facts and failed tools.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“从告警/报告跑到宣告、遏制、证据、业务决定、恢复和通知，加入事实模糊和工具失败；测决定/动作时间、交接、缺失权限/数据和偏离，并复测重大修正。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-17.4-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "17.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-17.4-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "17.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 5 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、5 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-17.4-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "17.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-17.4-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "17.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the incident taxonomy, case, command, communication, evidence, and action authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以事件分类、案件、指挥、通信、证据与行动权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-17.4-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "17.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Publish events, incidents, severity, ownership, acknowledgement, decision latency, communication success, containment, recovery, evidence gaps, and overdue corrective actions with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 事件、事故、严重度、责任、确认、决策延迟、通信成功、遏制、恢复、证据缺口和逾期纠正行动，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-17.4-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "17.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Publish clause coverage, owner and reviewer completeness, approval age, triggered reviews, deviations, overdue actions, and superseded versions still in use with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 条款覆盖、责任人与复核人完整性、批准年龄、触发式复核、偏离、逾期行动及仍在使用的旧版本，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-17.4-EVD-08",
          "local_code": "EVD-08",
          "display_code": "E08",
          "safeguard_id": "17.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Require an independent party to reconstruct the decision from source receipts and reproduce the population, state transition, calculation, test result, exception, and final closure.",
          "zh": "要求独立人员使用来源回执重建决策，并复现总体、状态转换、计算、测试结果、例外和最终关闭。"
        },
        {
          "code": "CIS-17.4-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "17.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-17.4-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "17.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-17.4-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "17.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-17.4-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "17.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-17.4-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "17.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the incident taxonomy, case, command, communication, evidence, and action authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护事件分类、案件、指挥、通信、证据与行动权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-17.4-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "17.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Restrict authority to change reported/detected → triaged → declared → commanded → contained → eradicated/recovered → reviewed → actions retested and closed; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“报告/检测 → 分流 → 宣告 → 指挥 → 遏制 → 根除/恢复 → 复盘 → 行动复测关闭”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-17.4-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "17.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Restrict authority to change draft → reviewed → approved → effective → exception/withdrawn → superseded; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-17.4-SEC-08",
          "local_code": "SEC-08",
          "display_code": "S08",
          "safeguard_id": "17.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Threat-model the implementation system itself: forged evidence, poisoned inventory, privilege abuse, cross-tenant confusion, policy rollback, audit deletion, denial of service, and recovery compromise.",
          "zh": "威胁建模实施系统自身：伪造证据、污染清单、权限滥用、跨租户混淆、策略回滚、审计删除、拒绝服务和恢复失陷。"
        },
        {
          "code": "CIS-17.4-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "17.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-17.4-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "17.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-17.4-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "17.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-17.4-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "17.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-17.4-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "17.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise event-versus-incident triage, primary and backup reporting, out-of-band communication, containment and recovery decisions, exercise injects, provider coordination, and action retest through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 事件与事故分流、主备报告、带外通信、遏制与恢复决策、演练注入、提供商协同和行动复测，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-17.4-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "17.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Run the positive control a representative report that reaches command, coordinated response, recovery, review, and verified action closure; exercise negative, stale, duplicate, bypass, and outage controls including threshold ambiguity, primary-channel loss, absent role, provider delay, evidence gap, failed containment, recovery dependency, and action recurrence.",
          "zh": "运行正向控制“一项代表性报告进入指挥、协同响应、恢复、复盘并完成行动验证关闭”，并执行包含“阈值歧义、主通道丢失、角色缺席、提供商延迟、证据缺口、遏制失败、恢复依赖和行动复发”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-17.4-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "17.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Run the positive control an approved current process used for a representative decision; exercise negative, stale, duplicate, bypass, and outage controls including an obsolete version, missing approver, undocumented deviation, overdue review, and bypassed workflow.",
          "zh": "运行正向控制“使用当前获批流程完成一项代表性决策”，并执行包含“旧版本、审批人缺失、未记录偏离、逾期复核和绕过流程”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-17.4-TST-08",
          "local_code": "TST-08",
          "display_code": "V08",
          "safeguard_id": "17.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Build a pairwise platform-and-failure matrix, then add high-consequence multi-factor cases, historical regression, source substitution, red-team challenge, and assessor replay.",
          "zh": "建立平台—故障两两组合矩阵，再加入高后果多因素案例、历史回归、来源替换、红队挑战和评估方重放。"
        },
        {
          "code": "CIS-17.4-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "17.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-17.4-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "17.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-17.4-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "17.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-17.4-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "17.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-17.4-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "17.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever reporting channels, monitoring and provider alerts, case systems, contact rosters, communication plans, forensic stores, recovery systems, exercises, and post-incident records change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 报告通道、监测与提供商告警、案件系统、联系人名册、通信计划、取证存储、恢复系统、演练和事后记录 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-17.4-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "17.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Use events, incidents, severity, ownership, acknowledgement, decision latency, communication success, containment, recovery, evidence gaps, and overdue corrective actions to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 事件、事故、严重度、责任、确认、决策延迟、通信成功、遏制、恢复、证据缺口和逾期纠正行动 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-17.4-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "17.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Use clause coverage, owner and reviewer completeness, approval age, triggered reviews, deviations, overdue actions, and superseded versions still in use to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 条款覆盖、责任人与复核人完整性、批准年龄、触发式复核、偏离、逾期行动及仍在使用的旧版本 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-17.4-OPS-08",
          "local_code": "OPS-08",
          "display_code": "R08",
          "safeguard_id": "17.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Use canary deployment, kill criteria, rollback, backlog burn-down, exception reduction, source-quality targets, quarterly design review, and a measurable retirement plan.",
          "zh": "采用金丝雀、停止标准、回滚、积压燃尽、例外缩减、来源质量目标、季度设计复核和可量化退役计划。"
        }
      ]
    },
    {
      "id": "17.5",
      "control": 17,
      "title_en": "Assign Key Roles and Responsibilities",
      "title_zh": "关键角色与职责",
      "first_ig": 2,
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Users",
      "security_function": "Respond",
      "patterns": [
        "incident",
        "governance"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "17.4"
        ],
        "variables": [
          "GV52",
          "M1",
          "M2",
          "M3",
          "M4",
          "M5"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [
        "annually"
      ],
      "implementation_contract": {
        "en": {
          "scope": "Map legal, IT, security, facilities, communications, HR, responders, analysts, business/data owners, privacy, executives and relevant third parties to scenario-specific responsibilities, authority, backup and conflicts.",
          "build": "Assign named role holders and backups, train them, provision least required emergency access, define decision/escalation and external interfaces, and review annually plus on personnel/provider/structure change.",
          "proof": "Tabletop ransomware, data breach, insider and physical/provider scenarios and require each role to make its decision and handoff.",
          "boundary": "One person may hold several roles in a small organization, but conflicting duties and overload need backup."
        },
        "zh": {
          "scope": "把法务、IT、安全、设施、公关、HR、响应/分析、业务/数据所有者、隐私、高层和相关第三方映射到场景责任、权限、备份和冲突；空 RACI 不可运营。",
          "build": "指定具名主备，培训并给最小应急访问，定义决策/升级和外部接口，每年及人员/服务商/结构变化时更新；用能在普通身份故障时存活的角色账户/联系路径。",
          "proof": "桌演勒索、数据泄露、内部人、物理/服务商场景，让各角色做真实决定/交接；验证下班访问与覆盖，对比 HR、值班、厂商、计划并补空责任。",
          "boundary": "小组织一人可兼多角，但冲突/过载需备份。"
        }
      },
      "category_counts": {
        "outcome": 7,
        "scope": 7,
        "ownership": 7,
        "data": 7,
        "integration": 7,
        "control": 7,
        "timing": 7,
        "exception": 7,
        "evidence": 7,
        "security": 7,
        "testing": 7,
        "operations": 7
      },
      "requirement_count": 84,
      "requirements": [
        {
          "code": "CIS-17.5-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "17.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Assign Key Roles and Responsibilities; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“关键角色与职责”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-17.5-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "17.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 17.5, official Asset Class Users, Security Function Respond, and IG2 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 17.5、官方资产类别“用户与身份”、安全功能“响应”和首次出现的 IG2，并保存来源抓取日期。"
        },
        {
          "code": "CIS-17.5-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "17.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Map legal, IT, security, facilities, communications, HR, responders, analysts, business/data owners, privacy, executives and relevant third parties to scenario-specific responsibilities, authority, backup and conflicts.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“把法务、IT、安全、设施、公关、HR、响应/分析、业务/数据所有者、隐私、高层和相关第三方映射到场景责任、权限、备份和冲突；空 RACI 不可运营。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-17.5-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "17.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-17.5-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "17.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Assign Key Roles and Responsibilities to its operating object—security events and incidents, thresholds, reports, roles, decisions, communications, evidence, containment, recovery, review, and follow-up actions—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“关键角色与职责”连接到其运营对象——安全事件与事故、阈值、报告、角色、决策、通信、证据、遏制、恢复、复盘和后续行动——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-17.5-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "17.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "For Assign Key Roles and Responsibilities, express success as an observable decision over event-to-incident threshold, report, command, decision, communication, containment, evidence, recovery, review, and corrective action; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“关键角色与职责”，以 事件到事故阈值、报告、指挥、决策、通信、遏制、证据、恢复、复盘和纠正行动 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-17.5-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "17.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "For Assign Key Roles and Responsibilities, express success as an observable decision over a documented decision system with policy, process, procedure, accountable owner, approval, and review; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“关键角色与职责”，以 包含策略、流程、程序、责任人、审批和复核的文档化决策系统 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-17.5-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "17.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-17.5-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "17.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-17.5-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "17.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-17.5-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "17.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-17.5-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "17.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across ambiguous thresholds, compromised primary channels, absent personnel, cross-jurisdiction notice, provider incidents, insider cases, safety events, evidence loss, prolonged recovery, and unresolved actions; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 阈值歧义、主通信通道失陷、人员缺席、跨辖区通知、提供商事件、内部人案件、安全生产事件、证据丢失、长期恢复和未关闭行动 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-17.5-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "17.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Include ambiguous classification, unavailable personnel, compromised primary channels, provider and cross-border incidents, insider and safety cases, evidence loss, prolonged recovery, and unresolved actions in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 分类歧义、人员不可用、主通道失陷、提供商与跨境事件、内部人与安全生产案件、证据丢失、长期恢复和未关闭行动 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-17.5-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "17.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Include missing policy clauses, conflicting authorities, local deviations, obsolete documentation, and decisions made outside the governed workflow in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 策略条款缺失、权限冲突、本地偏离、文档过期及绕过治理流程的决策 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-17.5-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "17.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-17.5-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "17.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-17.5-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "17.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-17.5-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "17.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-17.5-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "17.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind incident command and responders, IT and security, legal/privacy, communications, HR, facilities, business owners, executives, providers, insurers, and authorities to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 事件指挥与响应人员、IT 与安全、法务/隐私、传播、HR、设施、业务责任人、管理层、提供商、保险和主管机关 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-17.5-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "17.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Name who may transition reported/detected → triaged → declared → commanded → contained → eradicated/recovered → reviewed → actions retested and closed, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 报告/检测 → 分流 → 宣告 → 指挥 → 遏制 → 根除/恢复 → 复盘 → 行动复测关闭，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-17.5-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "17.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Name who may transition draft → reviewed → approved → effective → exception/withdrawn → superseded, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-17.5-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "17.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-17.5-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "17.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-17.5-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "17.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV52, M1, M2, M3, M4, M5) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV52, M1, M2, M3, M4, M5）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-17.5-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "17.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-17.5-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "17.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the incident taxonomy, case, command, communication, evidence, and action authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把事件分类、案件、指挥、通信、证据与行动权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-17.5-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "17.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle reported/detected → triaged → declared → commanded → contained → eradicated/recovered → reviewed → actions retested and closed.",
          "zh": "对生命周期“报告/检测 → 分流 → 宣告 → 指挥 → 遏制 → 根除/恢复 → 复盘 → 行动复测关闭”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-17.5-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "17.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle draft → reviewed → approved → effective → exception/withdrawn → superseded.",
          "zh": "对生命周期“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-17.5-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "17.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 17.4; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 17.4 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-17.5-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "17.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-17.5-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "17.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-17.5-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "17.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-17.5-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "17.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile reporting channels, monitoring and provider alerts, case systems, contact rosters, communication plans, forensic stores, recovery systems, exercises, and post-incident records and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 报告通道、监测与提供商告警、案件系统、联系人名册、通信计划、取证存储、恢复系统、演练和事后记录，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-17.5-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "17.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Require every connector carrying event-to-incident threshold, report, command, decision, communication, containment, evidence, recovery, review, and corrective action to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 事件到事故阈值、报告、指挥、决策、通信、遏制、证据、恢复、复盘和纠正行动 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-17.5-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "17.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Require every connector carrying a documented decision system with policy, process, procedure, accountable owner, approval, and review to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 包含策略、流程、程序、责任人、审批和复核的文档化决策系统 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-17.5-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "17.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Assign named role holders and backups, train them, provision least required emergency access, define decision/escalation and external interfaces, and review annually plus on personnel/provider/structure change.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“指定具名主备，培训并给最小应急访问，定义决策/升级和外部接口，每年及人员/服务商/结构变化时更新；用能在普通身份故障时存活的角色账户/联系路径。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-17.5-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "17.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-17.5-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "17.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-17.5-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "17.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-17.5-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "17.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the incident taxonomy, case, command, communication, evidence, and action authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在事件分类、案件、指挥、通信、证据与行动权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-17.5-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "17.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Implement the explicit state machine reported/detected → triaged → declared → commanded → contained → eradicated/recovered → reviewed → actions retested and closed; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“报告/检测 → 分流 → 宣告 → 指挥 → 遏制 → 根除/恢复 → 复盘 → 行动复测关闭”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-17.5-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "17.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Implement the explicit state machine draft → reviewed → approved → effective → exception/withdrawn → superseded; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-17.5-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "17.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (annually); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（annually）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-17.5-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "17.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-17.5-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "17.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-17.5-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "17.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-17.5-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "17.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in security events and incidents, thresholds, reports, roles, decisions, communications, evidence, containment, recovery, review, and follow-up actions; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 安全事件与事故、阈值、报告、角色、决策、通信、证据、遏制、恢复、复盘和后续行动 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-17.5-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "17.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for reported/detected → triaged → declared → commanded → contained → eradicated/recovered → reviewed → actions retested and closed; alert before each deadline becomes overdue.",
          "zh": "为“报告/检测 → 分流 → 宣告 → 指挥 → 遏制 → 根除/恢复 → 复盘 → 行动复测关闭”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-17.5-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "17.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for draft → reviewed → approved → effective → exception/withdrawn → superseded; alert before each deadline becomes overdue.",
          "zh": "为“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-17.5-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "17.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “One person may hold several roles in a small organization, but conflicting duties and overload need backup.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“小组织一人可兼多角，但冲突/过载需备份。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-17.5-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "17.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-17.5-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "17.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-17.5-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "17.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-17.5-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "17.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat ambiguous thresholds, compromised primary channels, absent personnel, cross-jurisdiction notice, provider incidents, insider cases, safety events, evidence loss, prolonged recovery, and unresolved actions as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 阈值歧义、主通信通道失陷、人员缺席、跨辖区通知、提供商事件、内部人案件、安全生产事件、证据丢失、长期恢复和未关闭行动 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-17.5-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "17.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Treat ambiguous classification, unavailable personnel, compromised primary channels, provider and cross-border incidents, insider and safety cases, evidence loss, prolonged recovery, and unresolved actions as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 分类歧义、人员不可用、主通道失陷、提供商与跨境事件、内部人与安全生产案件、证据丢失、长期恢复和未关闭行动 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-17.5-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "17.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Treat missing policy clauses, conflicting authorities, local deviations, obsolete documentation, and decisions made outside the governed workflow as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 策略条款缺失、权限冲突、本地偏离、文档过期及绕过治理流程的决策 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-17.5-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "17.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Tabletop ransomware, data breach, insider and physical/provider scenarios and require each role to make its decision and handoff.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“桌演勒索、数据泄露、内部人、物理/服务商场景，让各角色做真实决定/交接；验证下班访问与覆盖，对比 HR、值班、厂商、计划并补空责任。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-17.5-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "17.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-17.5-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "17.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 6 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、6 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-17.5-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "17.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-17.5-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "17.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the incident taxonomy, case, command, communication, evidence, and action authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以事件分类、案件、指挥、通信、证据与行动权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-17.5-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "17.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Publish events, incidents, severity, ownership, acknowledgement, decision latency, communication success, containment, recovery, evidence gaps, and overdue corrective actions with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 事件、事故、严重度、责任、确认、决策延迟、通信成功、遏制、恢复、证据缺口和逾期纠正行动，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-17.5-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "17.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Publish clause coverage, owner and reviewer completeness, approval age, triggered reviews, deviations, overdue actions, and superseded versions still in use with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 条款覆盖、责任人与复核人完整性、批准年龄、触发式复核、偏离、逾期行动及仍在使用的旧版本，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-17.5-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "17.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-17.5-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "17.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-17.5-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "17.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-17.5-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "17.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-17.5-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "17.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the incident taxonomy, case, command, communication, evidence, and action authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护事件分类、案件、指挥、通信、证据与行动权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-17.5-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "17.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Restrict authority to change reported/detected → triaged → declared → commanded → contained → eradicated/recovered → reviewed → actions retested and closed; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“报告/检测 → 分流 → 宣告 → 指挥 → 遏制 → 根除/恢复 → 复盘 → 行动复测关闭”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-17.5-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "17.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Restrict authority to change draft → reviewed → approved → effective → exception/withdrawn → superseded; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-17.5-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "17.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-17.5-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "17.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-17.5-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "17.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-17.5-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "17.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-17.5-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "17.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise event-versus-incident triage, primary and backup reporting, out-of-band communication, containment and recovery decisions, exercise injects, provider coordination, and action retest through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 事件与事故分流、主备报告、带外通信、遏制与恢复决策、演练注入、提供商协同和行动复测，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-17.5-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "17.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Run the positive control a representative report that reaches command, coordinated response, recovery, review, and verified action closure; exercise negative, stale, duplicate, bypass, and outage controls including threshold ambiguity, primary-channel loss, absent role, provider delay, evidence gap, failed containment, recovery dependency, and action recurrence.",
          "zh": "运行正向控制“一项代表性报告进入指挥、协同响应、恢复、复盘并完成行动验证关闭”，并执行包含“阈值歧义、主通道丢失、角色缺席、提供商延迟、证据缺口、遏制失败、恢复依赖和行动复发”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-17.5-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "17.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Run the positive control an approved current process used for a representative decision; exercise negative, stale, duplicate, bypass, and outage controls including an obsolete version, missing approver, undocumented deviation, overdue review, and bypassed workflow.",
          "zh": "运行正向控制“使用当前获批流程完成一项代表性决策”，并执行包含“旧版本、审批人缺失、未记录偏离、逾期复核和绕过流程”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-17.5-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "17.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-17.5-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "17.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-17.5-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "17.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-17.5-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "17.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-17.5-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "17.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever reporting channels, monitoring and provider alerts, case systems, contact rosters, communication plans, forensic stores, recovery systems, exercises, and post-incident records change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 报告通道、监测与提供商告警、案件系统、联系人名册、通信计划、取证存储、恢复系统、演练和事后记录 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-17.5-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "17.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Use events, incidents, severity, ownership, acknowledgement, decision latency, communication success, containment, recovery, evidence gaps, and overdue corrective actions to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 事件、事故、严重度、责任、确认、决策延迟、通信成功、遏制、恢复、证据缺口和逾期纠正行动 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-17.5-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "17.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Use clause coverage, owner and reviewer completeness, approval age, triggered reviews, deviations, overdue actions, and superseded versions still in use to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 条款覆盖、责任人与复核人完整性、批准年龄、触发式复核、偏离、逾期行动及仍在使用的旧版本 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "17.6",
      "control": 17,
      "title_en": "Define Mechanisms for Communicating During Incident Response",
      "title_zh": "事件期间通信机制",
      "first_ig": 2,
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Users",
      "security_function": "Respond",
      "patterns": [
        "incident",
        "governance"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "17.4"
        ],
        "variables": [
          "GV52",
          "M1",
          "M2",
          "M3"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [
        "annually"
      ],
      "implementation_contract": {
        "en": {
          "scope": "Primary and secondary mechanisms must serve responders, leadership, workforce, customers, providers and regulators as relevant, assuming corporate email/chat/identity or networks may be compromised.",
          "build": "Preconfigure out-of-band phone/chat/bridge or alternate tenant, authenticate participants, protect distribution lists/templates, define approval and record custody, and review annually/change.",
          "proof": "Disable the primary channel in an exercise, activate the secondary, verify identity, access, participant capacity, confidentiality, decision logging and message approval.",
          "boundary": "Consumer apps may violate retention/privacy and phone trees can be slow or spoofed."
        },
        "zh": {
          "scope": "主、备通信要服务相关响应者、领导、员工、客户、服务商和监管，并假设企业邮件/聊天/身份/网络会失陷；分开机密协同、广泛通知和证据记录。",
          "build": "预配 OOB 电话/聊天/Bridge 或备用租户，认证参与人，保护通讯录/模板，定义批准和记录保管，每年/变化时更新；离线留最低访问并提前测容量/隐私。",
          "proof": "演练关闭主通道，启动备通道，验证身份、访问、容量、机密、决定记录和消息批准；测试外部通知草拟与切回且不丢记录。",
          "boundary": "消费 App 可能不符保留/隐私，电话树又慢且可伪造。"
        }
      },
      "category_counts": {
        "outcome": 7,
        "scope": 7,
        "ownership": 7,
        "data": 7,
        "integration": 7,
        "control": 7,
        "timing": 7,
        "exception": 7,
        "evidence": 7,
        "security": 7,
        "testing": 7,
        "operations": 7
      },
      "requirement_count": 84,
      "requirements": [
        {
          "code": "CIS-17.6-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "17.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Define Mechanisms for Communicating During Incident Response; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“事件期间通信机制”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-17.6-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "17.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 17.6, official Asset Class Users, Security Function Respond, and IG2 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 17.6、官方资产类别“用户与身份”、安全功能“响应”和首次出现的 IG2，并保存来源抓取日期。"
        },
        {
          "code": "CIS-17.6-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "17.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Primary and secondary mechanisms must serve responders, leadership, workforce, customers, providers and regulators as relevant, assuming corporate email/chat/identity or networks may be compromised.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“主、备通信要服务相关响应者、领导、员工、客户、服务商和监管，并假设企业邮件/聊天/身份/网络会失陷；分开机密协同、广泛通知和证据记录。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-17.6-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "17.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-17.6-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "17.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Define Mechanisms for Communicating During Incident Response to its operating object—security events and incidents, thresholds, reports, roles, decisions, communications, evidence, containment, recovery, review, and follow-up actions—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“事件期间通信机制”连接到其运营对象——安全事件与事故、阈值、报告、角色、决策、通信、证据、遏制、恢复、复盘和后续行动——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-17.6-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "17.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "For Define Mechanisms for Communicating During Incident Response, express success as an observable decision over event-to-incident threshold, report, command, decision, communication, containment, evidence, recovery, review, and corrective action; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“事件期间通信机制”，以 事件到事故阈值、报告、指挥、决策、通信、遏制、证据、恢复、复盘和纠正行动 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-17.6-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "17.6",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "For Define Mechanisms for Communicating During Incident Response, express success as an observable decision over a documented decision system with policy, process, procedure, accountable owner, approval, and review; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“事件期间通信机制”，以 包含策略、流程、程序、责任人、审批和复核的文档化决策系统 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-17.6-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "17.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-17.6-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "17.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-17.6-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "17.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-17.6-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "17.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-17.6-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "17.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across ambiguous thresholds, compromised primary channels, absent personnel, cross-jurisdiction notice, provider incidents, insider cases, safety events, evidence loss, prolonged recovery, and unresolved actions; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 阈值歧义、主通信通道失陷、人员缺席、跨辖区通知、提供商事件、内部人案件、安全生产事件、证据丢失、长期恢复和未关闭行动 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-17.6-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "17.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Include ambiguous classification, unavailable personnel, compromised primary channels, provider and cross-border incidents, insider and safety cases, evidence loss, prolonged recovery, and unresolved actions in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 分类歧义、人员不可用、主通道失陷、提供商与跨境事件、内部人与安全生产案件、证据丢失、长期恢复和未关闭行动 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-17.6-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "17.6",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Include missing policy clauses, conflicting authorities, local deviations, obsolete documentation, and decisions made outside the governed workflow in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 策略条款缺失、权限冲突、本地偏离、文档过期及绕过治理流程的决策 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-17.6-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "17.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-17.6-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "17.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-17.6-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "17.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-17.6-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "17.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-17.6-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "17.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind incident command and responders, IT and security, legal/privacy, communications, HR, facilities, business owners, executives, providers, insurers, and authorities to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 事件指挥与响应人员、IT 与安全、法务/隐私、传播、HR、设施、业务责任人、管理层、提供商、保险和主管机关 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-17.6-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "17.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Name who may transition reported/detected → triaged → declared → commanded → contained → eradicated/recovered → reviewed → actions retested and closed, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 报告/检测 → 分流 → 宣告 → 指挥 → 遏制 → 根除/恢复 → 复盘 → 行动复测关闭，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-17.6-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "17.6",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Name who may transition draft → reviewed → approved → effective → exception/withdrawn → superseded, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-17.6-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "17.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-17.6-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "17.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-17.6-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "17.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV52, M1, M2, M3) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV52, M1, M2, M3）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-17.6-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "17.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-17.6-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "17.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the incident taxonomy, case, command, communication, evidence, and action authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把事件分类、案件、指挥、通信、证据与行动权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-17.6-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "17.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle reported/detected → triaged → declared → commanded → contained → eradicated/recovered → reviewed → actions retested and closed.",
          "zh": "对生命周期“报告/检测 → 分流 → 宣告 → 指挥 → 遏制 → 根除/恢复 → 复盘 → 行动复测关闭”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-17.6-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "17.6",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle draft → reviewed → approved → effective → exception/withdrawn → superseded.",
          "zh": "对生命周期“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-17.6-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "17.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 17.4; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 17.4 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-17.6-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "17.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-17.6-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "17.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-17.6-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "17.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-17.6-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "17.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile reporting channels, monitoring and provider alerts, case systems, contact rosters, communication plans, forensic stores, recovery systems, exercises, and post-incident records and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 报告通道、监测与提供商告警、案件系统、联系人名册、通信计划、取证存储、恢复系统、演练和事后记录，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-17.6-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "17.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Require every connector carrying event-to-incident threshold, report, command, decision, communication, containment, evidence, recovery, review, and corrective action to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 事件到事故阈值、报告、指挥、决策、通信、遏制、证据、恢复、复盘和纠正行动 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-17.6-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "17.6",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Require every connector carrying a documented decision system with policy, process, procedure, accountable owner, approval, and review to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 包含策略、流程、程序、责任人、审批和复核的文档化决策系统 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-17.6-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "17.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Preconfigure out-of-band phone/chat/bridge or alternate tenant, authenticate participants, protect distribution lists/templates, define approval and record custody, and review annually/change.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“预配 OOB 电话/聊天/Bridge 或备用租户，认证参与人，保护通讯录/模板，定义批准和记录保管，每年/变化时更新；离线留最低访问并提前测容量/隐私。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-17.6-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "17.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-17.6-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "17.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-17.6-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "17.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-17.6-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "17.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the incident taxonomy, case, command, communication, evidence, and action authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在事件分类、案件、指挥、通信、证据与行动权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-17.6-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "17.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Implement the explicit state machine reported/detected → triaged → declared → commanded → contained → eradicated/recovered → reviewed → actions retested and closed; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“报告/检测 → 分流 → 宣告 → 指挥 → 遏制 → 根除/恢复 → 复盘 → 行动复测关闭”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-17.6-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "17.6",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Implement the explicit state machine draft → reviewed → approved → effective → exception/withdrawn → superseded; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-17.6-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "17.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (annually); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（annually）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-17.6-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "17.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-17.6-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "17.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-17.6-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "17.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-17.6-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "17.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in security events and incidents, thresholds, reports, roles, decisions, communications, evidence, containment, recovery, review, and follow-up actions; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 安全事件与事故、阈值、报告、角色、决策、通信、证据、遏制、恢复、复盘和后续行动 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-17.6-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "17.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for reported/detected → triaged → declared → commanded → contained → eradicated/recovered → reviewed → actions retested and closed; alert before each deadline becomes overdue.",
          "zh": "为“报告/检测 → 分流 → 宣告 → 指挥 → 遏制 → 根除/恢复 → 复盘 → 行动复测关闭”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-17.6-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "17.6",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for draft → reviewed → approved → effective → exception/withdrawn → superseded; alert before each deadline becomes overdue.",
          "zh": "为“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-17.6-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "17.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “Consumer apps may violate retention/privacy and phone trees can be slow or spoofed.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“消费 App 可能不符保留/隐私，电话树又慢且可伪造。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-17.6-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "17.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-17.6-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "17.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-17.6-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "17.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-17.6-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "17.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat ambiguous thresholds, compromised primary channels, absent personnel, cross-jurisdiction notice, provider incidents, insider cases, safety events, evidence loss, prolonged recovery, and unresolved actions as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 阈值歧义、主通信通道失陷、人员缺席、跨辖区通知、提供商事件、内部人案件、安全生产事件、证据丢失、长期恢复和未关闭行动 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-17.6-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "17.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Treat ambiguous classification, unavailable personnel, compromised primary channels, provider and cross-border incidents, insider and safety cases, evidence loss, prolonged recovery, and unresolved actions as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 分类歧义、人员不可用、主通道失陷、提供商与跨境事件、内部人与安全生产案件、证据丢失、长期恢复和未关闭行动 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-17.6-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "17.6",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Treat missing policy clauses, conflicting authorities, local deviations, obsolete documentation, and decisions made outside the governed workflow as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 策略条款缺失、权限冲突、本地偏离、文档过期及绕过治理流程的决策 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-17.6-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "17.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Disable the primary channel in an exercise, activate the secondary, verify identity, access, participant capacity, confidentiality, decision logging and message approval.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“演练关闭主通道，启动备通道，验证身份、访问、容量、机密、决定记录和消息批准；测试外部通知草拟与切回且不丢记录。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-17.6-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "17.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-17.6-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "17.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 4 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、4 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-17.6-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "17.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-17.6-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "17.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the incident taxonomy, case, command, communication, evidence, and action authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以事件分类、案件、指挥、通信、证据与行动权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-17.6-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "17.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Publish events, incidents, severity, ownership, acknowledgement, decision latency, communication success, containment, recovery, evidence gaps, and overdue corrective actions with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 事件、事故、严重度、责任、确认、决策延迟、通信成功、遏制、恢复、证据缺口和逾期纠正行动，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-17.6-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "17.6",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Publish clause coverage, owner and reviewer completeness, approval age, triggered reviews, deviations, overdue actions, and superseded versions still in use with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 条款覆盖、责任人与复核人完整性、批准年龄、触发式复核、偏离、逾期行动及仍在使用的旧版本，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-17.6-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "17.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-17.6-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "17.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-17.6-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "17.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-17.6-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "17.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-17.6-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "17.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the incident taxonomy, case, command, communication, evidence, and action authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护事件分类、案件、指挥、通信、证据与行动权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-17.6-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "17.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Restrict authority to change reported/detected → triaged → declared → commanded → contained → eradicated/recovered → reviewed → actions retested and closed; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“报告/检测 → 分流 → 宣告 → 指挥 → 遏制 → 根除/恢复 → 复盘 → 行动复测关闭”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-17.6-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "17.6",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Restrict authority to change draft → reviewed → approved → effective → exception/withdrawn → superseded; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-17.6-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "17.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-17.6-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "17.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-17.6-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "17.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-17.6-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "17.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-17.6-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "17.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise event-versus-incident triage, primary and backup reporting, out-of-band communication, containment and recovery decisions, exercise injects, provider coordination, and action retest through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 事件与事故分流、主备报告、带外通信、遏制与恢复决策、演练注入、提供商协同和行动复测，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-17.6-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "17.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Run the positive control a representative report that reaches command, coordinated response, recovery, review, and verified action closure; exercise negative, stale, duplicate, bypass, and outage controls including threshold ambiguity, primary-channel loss, absent role, provider delay, evidence gap, failed containment, recovery dependency, and action recurrence.",
          "zh": "运行正向控制“一项代表性报告进入指挥、协同响应、恢复、复盘并完成行动验证关闭”，并执行包含“阈值歧义、主通道丢失、角色缺席、提供商延迟、证据缺口、遏制失败、恢复依赖和行动复发”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-17.6-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "17.6",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Run the positive control an approved current process used for a representative decision; exercise negative, stale, duplicate, bypass, and outage controls including an obsolete version, missing approver, undocumented deviation, overdue review, and bypassed workflow.",
          "zh": "运行正向控制“使用当前获批流程完成一项代表性决策”，并执行包含“旧版本、审批人缺失、未记录偏离、逾期复核和绕过流程”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-17.6-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "17.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-17.6-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "17.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-17.6-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "17.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-17.6-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "17.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-17.6-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "17.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever reporting channels, monitoring and provider alerts, case systems, contact rosters, communication plans, forensic stores, recovery systems, exercises, and post-incident records change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 报告通道、监测与提供商告警、案件系统、联系人名册、通信计划、取证存储、恢复系统、演练和事后记录 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-17.6-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "17.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Use events, incidents, severity, ownership, acknowledgement, decision latency, communication success, containment, recovery, evidence gaps, and overdue corrective actions to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 事件、事故、严重度、责任、确认、决策延迟、通信成功、遏制、恢复、证据缺口和逾期纠正行动 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-17.6-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "17.6",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Use clause coverage, owner and reviewer completeness, approval age, triggered reviews, deviations, overdue actions, and superseded versions still in use to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 条款覆盖、责任人与复核人完整性、批准年龄、触发式复核、偏离、逾期行动及仍在使用的旧版本 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "17.7",
      "control": 17,
      "title_en": "Conduct Routine Incident Response Exercises",
      "title_zh": "常态化响应演练",
      "first_ig": 2,
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Users",
      "security_function": "Recover",
      "patterns": [
        "incident",
        "training"
      ],
      "expanded_complexity": true,
      "cas_context": {
        "dependencies": [
          "17.4"
        ],
        "variables": [
          "GV52",
          "M1",
          "M2",
          "M3"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "Exercises at least annually should test communications, decisions and workflows with key personnel, and rotate realistic scenarios across technical, business, legal, provider and recovery boundaries.",
          "build": "Define objectives and no-fault rules, create injects and evidence, involve backups/providers, observe actions without scripting answers, and produce owned improvements with deadlines.",
          "proof": "Measure page/declare/contain/decide/communicate/recover times, evidence quality, handoffs, unavailable dependencies and deviations.",
          "boundary": "A yearly calendar event can pass CAS while never testing actual channels or authority."
        },
        "zh": {
          "scope": "至少年度演练应让关键人员测试通信、决定和工作流，并在技术、业务、法务、服务商、恢复场景间轮换；Tabletop 与技术模拟测试不同能力。",
          "build": "定目标和无责规则，设计 Inject/证据，纳入备份人员/服务商，观察真实动作而不提前给答案，形成有责任/日期的改进；从桌演安全进阶到功能/技术，并协调生产。",
          "proof": "测 Page、宣告、遏制、决策、通信、恢复时间，证据质量、交接、不可用依赖和偏离；加入主通信失败和模糊/误报，重大改进要复测，不以会议纪要关闭。",
          "boundary": "年度日历事件可过 CAS，但可能没测通道/权力。"
        }
      },
      "category_counts": {
        "outcome": 8,
        "scope": 8,
        "ownership": 8,
        "data": 8,
        "integration": 8,
        "control": 8,
        "timing": 8,
        "exception": 8,
        "evidence": 8,
        "security": 8,
        "testing": 8,
        "operations": 8
      },
      "requirement_count": 96,
      "requirements": [
        {
          "code": "CIS-17.7-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "17.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Conduct Routine Incident Response Exercises; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“常态化响应演练”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-17.7-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "17.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 17.7, official Asset Class Users, Security Function Recover, and IG2 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 17.7、官方资产类别“用户与身份”、安全功能“恢复”和首次出现的 IG2，并保存来源抓取日期。"
        },
        {
          "code": "CIS-17.7-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "17.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Exercises at least annually should test communications, decisions and workflows with key personnel, and rotate realistic scenarios across technical, business, legal, provider and recovery boundaries.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“至少年度演练应让关键人员测试通信、决定和工作流，并在技术、业务、法务、服务商、恢复场景间轮换；Tabletop 与技术模拟测试不同能力。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-17.7-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "17.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-17.7-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "17.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Conduct Routine Incident Response Exercises to its operating object—security events and incidents, thresholds, reports, roles, decisions, communications, evidence, containment, recovery, review, and follow-up actions—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“常态化响应演练”连接到其运营对象——安全事件与事故、阈值、报告、角色、决策、通信、证据、遏制、恢复、复盘和后续行动——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-17.7-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "17.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "For Conduct Routine Incident Response Exercises, express success as an observable decision over event-to-incident threshold, report, command, decision, communication, containment, evidence, recovery, review, and corrective action; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“常态化响应演练”，以 事件到事故阈值、报告、指挥、决策、通信、遏制、证据、恢复、复盘和纠正行动 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-17.7-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "17.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "For Conduct Routine Incident Response Exercises, express success as an observable decision over role-specific knowledge, practiced decision, reporting behavior, measurable comprehension, and retraining outcome; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“常态化响应演练”，以 岗位相关知识、练习过的决策、报告行为、可测理解和再培训结果 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-17.7-OUT-08",
          "local_code": "OUT-08",
          "display_code": "O08",
          "safeguard_id": "17.7",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "For the expanded Conduct Routine Incident Response Exercises scope, resolve conflicts among security, safety, privacy, legal, availability, customer, and operational objectives through an explicit risk decision.",
          "zh": "对“常态化响应演练”的扩展范围，通过显式风险决策解决安全、安全生产、隐私、法律、可用性、客户和运营目标冲突。"
        },
        {
          "code": "CIS-17.7-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "17.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-17.7-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "17.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-17.7-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "17.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-17.7-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "17.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-17.7-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "17.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across ambiguous thresholds, compromised primary channels, absent personnel, cross-jurisdiction notice, provider incidents, insider cases, safety events, evidence loss, prolonged recovery, and unresolved actions; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 阈值歧义、主通信通道失陷、人员缺席、跨辖区通知、提供商事件、内部人案件、安全生产事件、证据丢失、长期恢复和未关闭行动 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-17.7-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "17.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Include ambiguous classification, unavailable personnel, compromised primary channels, provider and cross-border incidents, insider and safety cases, evidence loss, prolonged recovery, and unresolved actions in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 分类歧义、人员不可用、主通道失陷、提供商与跨境事件、内部人与安全生产案件、证据丢失、长期恢复和未关闭行动 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-17.7-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "17.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Include new hires, contractors, temporary and privileged roles, role changes, accessibility and language needs, absence, remote work, simulation harm, and completion without comprehension in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 新员工、承包商、临时与特权角色、角色变化、无障碍和语言需求、缺席、远程工作、模拟伤害及完成却未理解 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-17.7-SCP-08",
          "local_code": "SCP-08",
          "display_code": "P08",
          "safeguard_id": "17.7",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Define nested scope at enterprise, business service, tenant, environment, platform, object, identity, data set, and transaction levels; prohibit a parent result from hiding a failing child.",
          "zh": "按企业、业务服务、租户、环境、平台、对象、身份、数据集和交易定义嵌套范围，禁止父级结果遮蔽失败子级。"
        },
        {
          "code": "CIS-17.7-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "17.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-17.7-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "17.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-17.7-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "17.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-17.7-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "17.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-17.7-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "17.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind incident command and responders, IT and security, legal/privacy, communications, HR, facilities, business owners, executives, providers, insurers, and authorities to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 事件指挥与响应人员、IT 与安全、法务/隐私、传播、HR、设施、业务责任人、管理层、提供商、保险和主管机关 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-17.7-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "17.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Name who may transition reported/detected → triaged → declared → commanded → contained → eradicated/recovered → reviewed → actions retested and closed, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 报告/检测 → 分流 → 宣告 → 指挥 → 遏制 → 根除/恢复 → 复盘 → 行动复测关闭，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-17.7-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "17.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Name who may transition need identified → objective and scenario designed → assigned → practiced/assessed → remediated → behavior reviewed → content renewed, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 识别需要 → 设计目标与情境 → 分配 → 练习/评估 → 补救 → 复核行为 → 更新内容，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-17.7-OWN-08",
          "local_code": "OWN-08",
          "display_code": "W08",
          "safeguard_id": "17.7",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Model delegated authority, quorum or dual approval where warranted, escalation deadlines, provider handoffs, conflict resolution, and executive risk acceptance.",
          "zh": "建模委派权限、必要时的双人或法定人数审批、升级期限、提供商交接、冲突解决和管理层风险接受。"
        },
        {
          "code": "CIS-17.7-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "17.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-17.7-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "17.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-17.7-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "17.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV52, M1, M2, M3) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV52, M1, M2, M3）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-17.7-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "17.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-17.7-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "17.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the incident taxonomy, case, command, communication, evidence, and action authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把事件分类、案件、指挥、通信、证据与行动权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-17.7-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "17.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle reported/detected → triaged → declared → commanded → contained → eradicated/recovered → reviewed → actions retested and closed.",
          "zh": "对生命周期“报告/检测 → 分流 → 宣告 → 指挥 → 遏制 → 根除/恢复 → 复盘 → 行动复测关闭”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-17.7-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "17.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle need identified → objective and scenario designed → assigned → practiced/assessed → remediated → behavior reviewed → content renewed.",
          "zh": "对生命周期“识别需要 → 设计目标与情境 → 分配 → 练习/评估 → 补救 → 复核行为 → 更新内容”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-17.7-DAT-08",
          "local_code": "DAT-08",
          "display_code": "D08",
          "safeguard_id": "17.7",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Version schemas and state transitions with migration, backfill, deduplication, lineage, historical denominator, deletion, and rollback semantics.",
          "zh": "对模式和状态转换做版本管理，定义迁移、回填、去重、血缘、历史分母、删除和回滚语义。"
        },
        {
          "code": "CIS-17.7-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "17.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 17.4; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 17.4 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-17.7-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "17.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-17.7-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "17.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-17.7-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "17.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-17.7-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "17.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile reporting channels, monitoring and provider alerts, case systems, contact rosters, communication plans, forensic stores, recovery systems, exercises, and post-incident records and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 报告通道、监测与提供商告警、案件系统、联系人名册、通信计划、取证存储、恢复系统、演练和事后记录，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-17.7-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "17.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Require every connector carrying event-to-incident threshold, report, command, decision, communication, containment, evidence, recovery, review, and corrective action to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 事件到事故阈值、报告、指挥、决策、通信、遏制、证据、恢复、复盘和纠正行动 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-17.7-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "17.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Require every connector carrying role-specific knowledge, practiced decision, reporting behavior, measurable comprehension, and retraining outcome to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 岗位相关知识、练习过的决策、报告行为、可测理解和再培训结果 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-17.7-INT-08",
          "local_code": "INT-08",
          "display_code": "I08",
          "safeguard_id": "17.7",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Define consistency rules across disagreeing sources, source precedence, confidence, reconciliation queues, dead-letter handling, reprocessing, and end-to-end trace identity.",
          "zh": "定义冲突来源的一致性、优先级、置信度、对账队列、死信、重处理和端到端追踪身份。"
        },
        {
          "code": "CIS-17.7-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "17.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Define objectives and no-fault rules, create injects and evidence, involve backups/providers, observe actions without scripting answers, and produce owned improvements with deadlines.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“定目标和无责规则，设计 Inject/证据，纳入备份人员/服务商，观察真实动作而不提前给答案，形成有责任/日期的改进；从桌演安全进阶到功能/技术，并协调生产。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-17.7-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "17.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-17.7-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "17.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-17.7-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "17.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-17.7-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "17.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the incident taxonomy, case, command, communication, evidence, and action authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在事件分类、案件、指挥、通信、证据与行动权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-17.7-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "17.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Implement the explicit state machine reported/detected → triaged → declared → commanded → contained → eradicated/recovered → reviewed → actions retested and closed; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“报告/检测 → 分流 → 宣告 → 指挥 → 遏制 → 根除/恢复 → 复盘 → 行动复测关闭”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-17.7-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "17.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Implement the explicit state machine need identified → objective and scenario designed → assigned → practiced/assessed → remediated → behavior reviewed → content renewed; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“识别需要 → 设计目标与情境 → 分配 → 练习/评估 → 补救 → 复核行为 → 更新内容”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-17.7-CTL-08",
          "local_code": "CTL-08",
          "display_code": "C08",
          "safeguard_id": "17.7",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Specify concurrent decisions, partial success, compensating transactions, repeated requests, stale policy, dependency outage, and recovery from an interrupted state transition.",
          "zh": "定义并发决策、部分成功、补偿事务、重复请求、陈旧策略、依赖中断和中途状态转换恢复。"
        },
        {
          "code": "CIS-17.7-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "17.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-17.7-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "17.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-17.7-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "17.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-17.7-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "17.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-17.7-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "17.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in security events and incidents, thresholds, reports, roles, decisions, communications, evidence, containment, recovery, review, and follow-up actions; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 安全事件与事故、阈值、报告、角色、决策、通信、证据、遏制、恢复、复盘和后续行动 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-17.7-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "17.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for reported/detected → triaged → declared → commanded → contained → eradicated/recovered → reviewed → actions retested and closed; alert before each deadline becomes overdue.",
          "zh": "为“报告/检测 → 分流 → 宣告 → 指挥 → 遏制 → 根除/恢复 → 复盘 → 行动复测关闭”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-17.7-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "17.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for need identified → objective and scenario designed → assigned → practiced/assessed → remediated → behavior reviewed → content renewed; alert before each deadline becomes overdue.",
          "zh": "为“识别需要 → 设计目标与情境 → 分配 → 练习/评估 → 补救 → 复核行为 → 更新内容”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-17.7-TIM-08",
          "local_code": "TIM-08",
          "display_code": "T08",
          "safeguard_id": "17.7",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Allocate an end-to-end SLO budget across discovery, collection, processing, approval, enforcement, verification, and closure; prioritize overdue work by consequence and exposure.",
          "zh": "把端到端 SLO 预算分配到发现、采集、处理、审批、执行、验证和关闭，并按后果与暴露排列逾期工作。"
        },
        {
          "code": "CIS-17.7-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "17.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “A yearly calendar event can pass CAS while never testing actual channels or authority.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“年度日历事件可过 CAS，但可能没测通道/权力。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-17.7-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "17.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-17.7-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "17.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-17.7-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "17.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-17.7-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "17.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat ambiguous thresholds, compromised primary channels, absent personnel, cross-jurisdiction notice, provider incidents, insider cases, safety events, evidence loss, prolonged recovery, and unresolved actions as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 阈值歧义、主通信通道失陷、人员缺席、跨辖区通知、提供商事件、内部人案件、安全生产事件、证据丢失、长期恢复和未关闭行动 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-17.7-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "17.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Treat ambiguous classification, unavailable personnel, compromised primary channels, provider and cross-border incidents, insider and safety cases, evidence loss, prolonged recovery, and unresolved actions as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 分类歧义、人员不可用、主通道失陷、提供商与跨境事件、内部人与安全生产案件、证据丢失、长期恢复和未关闭行动 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-17.7-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "17.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Treat new hires, contractors, temporary and privileged roles, role changes, accessibility and language needs, absence, remote work, simulation harm, and completion without comprehension as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 新员工、承包商、临时与特权角色、角色变化、无障碍和语言需求、缺席、远程工作、模拟伤害及完成却未理解 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-17.7-EXC-08",
          "local_code": "EXC-08",
          "display_code": "X08",
          "safeguard_id": "17.7",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Exercise compound failures where an exception, stale source, provider outage, unavailable owner, and degraded control overlap; define one safe command and one accountable decision.",
          "zh": "演练例外、陈旧来源、提供商中断、责任人不可用和控制降级同时出现的复合故障，明确一条安全指令和一个责任决策。"
        },
        {
          "code": "CIS-17.7-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "17.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Measure page/declare/contain/decide/communicate/recover times, evidence quality, handoffs, unavailable dependencies and deviations.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“测 Page、宣告、遏制、决策、通信、恢复时间，证据质量、交接、不可用依赖和偏离；加入主通信失败和模糊/误报，重大改进要复测，不以会议纪要关闭。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-17.7-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "17.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-17.7-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "17.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 4 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、4 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-17.7-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "17.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-17.7-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "17.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the incident taxonomy, case, command, communication, evidence, and action authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以事件分类、案件、指挥、通信、证据与行动权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-17.7-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "17.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Publish events, incidents, severity, ownership, acknowledgement, decision latency, communication success, containment, recovery, evidence gaps, and overdue corrective actions with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 事件、事故、严重度、责任、确认、决策延迟、通信成功、遏制、恢复、证据缺口和逾期纠正行动，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-17.7-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "17.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Publish assigned, started, completed, passed, failed, overdue, exempted, role-mismatched, retrained, reported, and behavior-improved learners with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 已分配、已开始、已完成、通过、失败、逾期、豁免、岗位不匹配、再培训、已报告和行为改善人员，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-17.7-EVD-08",
          "local_code": "EVD-08",
          "display_code": "E08",
          "safeguard_id": "17.7",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Require an independent party to reconstruct the decision from source receipts and reproduce the population, state transition, calculation, test result, exception, and final closure.",
          "zh": "要求独立人员使用来源回执重建决策，并复现总体、状态转换、计算、测试结果、例外和最终关闭。"
        },
        {
          "code": "CIS-17.7-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "17.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-17.7-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "17.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-17.7-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "17.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-17.7-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "17.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-17.7-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "17.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the incident taxonomy, case, command, communication, evidence, and action authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护事件分类、案件、指挥、通信、证据与行动权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-17.7-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "17.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Restrict authority to change reported/detected → triaged → declared → commanded → contained → eradicated/recovered → reviewed → actions retested and closed; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“报告/检测 → 分流 → 宣告 → 指挥 → 遏制 → 根除/恢复 → 复盘 → 行动复测关闭”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-17.7-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "17.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Restrict authority to change need identified → objective and scenario designed → assigned → practiced/assessed → remediated → behavior reviewed → content renewed; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“识别需要 → 设计目标与情境 → 分配 → 练习/评估 → 补救 → 复核行为 → 更新内容”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-17.7-SEC-08",
          "local_code": "SEC-08",
          "display_code": "S08",
          "safeguard_id": "17.7",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Threat-model the implementation system itself: forged evidence, poisoned inventory, privilege abuse, cross-tenant confusion, policy rollback, audit deletion, denial of service, and recovery compromise.",
          "zh": "威胁建模实施系统自身：伪造证据、污染清单、权限滥用、跨租户混淆、策略回滚、审计删除、拒绝服务和恢复失陷。"
        },
        {
          "code": "CIS-17.7-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "17.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-17.7-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "17.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-17.7-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "17.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-17.7-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "17.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-17.7-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "17.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise event-versus-incident triage, primary and backup reporting, out-of-band communication, containment and recovery decisions, exercise injects, provider coordination, and action retest through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 事件与事故分流、主备报告、带外通信、遏制与恢复决策、演练注入、提供商协同和行动复测，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-17.7-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "17.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Run the positive control a representative report that reaches command, coordinated response, recovery, review, and verified action closure; exercise negative, stale, duplicate, bypass, and outage controls including threshold ambiguity, primary-channel loss, absent role, provider delay, evidence gap, failed containment, recovery dependency, and action recurrence.",
          "zh": "运行正向控制“一项代表性报告进入指挥、协同响应、恢复、复盘并完成行动验证关闭”，并执行包含“阈值歧义、主通道丢失、角色缺席、提供商延迟、证据缺口、遏制失败、恢复依赖和行动复发”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-17.7-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "17.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Run the positive control a representative learner making and reporting the secure decision in a realistic scenario; exercise negative, stale, duplicate, bypass, and outage controls including a missed assignment, incorrect decision, inaccessible content, stale scenario, role mismatch, failed report channel, and ineffective retraining.",
          "zh": "运行正向控制“代表性人员在真实情境中作出并报告安全决策”，并执行包含“漏分配、错误决策、内容不可访问、情境陈旧、岗位不匹配、报告通道失败和再培训无效”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-17.7-TST-08",
          "local_code": "TST-08",
          "display_code": "V08",
          "safeguard_id": "17.7",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Build a pairwise platform-and-failure matrix, then add high-consequence multi-factor cases, historical regression, source substitution, red-team challenge, and assessor replay.",
          "zh": "建立平台—故障两两组合矩阵，再加入高后果多因素案例、历史回归、来源替换、红队挑战和评估方重放。"
        },
        {
          "code": "CIS-17.7-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "17.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-17.7-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "17.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-17.7-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "17.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-17.7-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "17.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-17.7-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "17.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever reporting channels, monitoring and provider alerts, case systems, contact rosters, communication plans, forensic stores, recovery systems, exercises, and post-incident records change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 报告通道、监测与提供商告警、案件系统、联系人名册、通信计划、取证存储、恢复系统、演练和事后记录 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-17.7-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "17.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Use events, incidents, severity, ownership, acknowledgement, decision latency, communication success, containment, recovery, evidence gaps, and overdue corrective actions to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 事件、事故、严重度、责任、确认、决策延迟、通信成功、遏制、恢复、证据缺口和逾期纠正行动 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-17.7-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "17.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original training pattern analysis",
          "basis_zh": "SOSEC 原创 training 模式分析",
          "en": "Use assigned, started, completed, passed, failed, overdue, exempted, role-mismatched, retrained, reported, and behavior-improved learners to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 已分配、已开始、已完成、通过、失败、逾期、豁免、岗位不匹配、再培训、已报告和行为改善人员 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-17.7-OPS-08",
          "local_code": "OPS-08",
          "display_code": "R08",
          "safeguard_id": "17.7",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Use canary deployment, kill criteria, rollback, backlog burn-down, exception reduction, source-quality targets, quarterly design review, and a measurable retirement plan.",
          "zh": "采用金丝雀、停止标准、回滚、积压燃尽、例外缩减、来源质量目标、季度设计复核和可量化退役计划。"
        }
      ]
    },
    {
      "id": "17.8",
      "control": 17,
      "title_en": "Conduct Post-Incident Reviews",
      "title_zh": "事后复盘",
      "first_ig": 2,
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Users",
      "security_function": "Recover",
      "patterns": [
        "incident",
        "telemetry"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "17.4"
        ],
        "variables": [
          "GV52",
          "M1",
          "M2"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "Every material incident and selected near miss gets a timely, blameless review of timeline, detection, decisions, controls, impact, communications, recovery and systemic causes.",
          "build": "Set review threshold/timing, preserve facts and uncertainty, include affected teams/providers, identify contributing conditions and assign prioritized actions with owners/dates.",
          "proof": "Sample incidents from declaration to review and trace actions to implemented control and a retest or outcome.",
          "boundary": "CAS checks only whether a last review mentions lessons/actions, with no population or closure."
        },
        "zh": {
          "scope": "每个重大事件和选定 Near miss 要及时无责复盘时间线、检测、决定、控制、影响、沟通、恢复与系统根因，目标是验证改进和防复发，不是找人背锅或美化时间线。",
          "build": "设复盘门槛/时间，保留事实与不确定，纳入相关团队/服务商，找促成条件并分配有优先、责任、日期的行动；反馈架构、检测、恢复、培训和风险，高层解逾期阻塞。",
          "proof": "抽样从宣告追到复盘，把行动追到已实现控制和复测/结果；比较复发、检测/恢复变化，确认假设/争议已标识，敏感/法律材料访问合适。",
          "boundary": "CAS 只看上次复盘是否有经验/行动，无总体和关闭。"
        }
      },
      "category_counts": {
        "outcome": 7,
        "scope": 7,
        "ownership": 7,
        "data": 7,
        "integration": 7,
        "control": 7,
        "timing": 7,
        "exception": 7,
        "evidence": 7,
        "security": 7,
        "testing": 7,
        "operations": 7
      },
      "requirement_count": 84,
      "requirements": [
        {
          "code": "CIS-17.8-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "17.8",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Conduct Post-Incident Reviews; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“事后复盘”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-17.8-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "17.8",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 17.8, official Asset Class Users, Security Function Recover, and IG2 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 17.8、官方资产类别“用户与身份”、安全功能“恢复”和首次出现的 IG2，并保存来源抓取日期。"
        },
        {
          "code": "CIS-17.8-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "17.8",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Every material incident and selected near miss gets a timely, blameless review of timeline, detection, decisions, controls, impact, communications, recovery and systemic causes.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“每个重大事件和选定 Near miss 要及时无责复盘时间线、检测、决定、控制、影响、沟通、恢复与系统根因，目标是验证改进和防复发，不是找人背锅或美化时间线。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-17.8-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "17.8",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-17.8-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "17.8",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Conduct Post-Incident Reviews to its operating object—security events and incidents, thresholds, reports, roles, decisions, communications, evidence, containment, recovery, review, and follow-up actions—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“事后复盘”连接到其运营对象——安全事件与事故、阈值、报告、角色、决策、通信、证据、遏制、恢复、复盘和后续行动——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-17.8-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "17.8",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "For Conduct Post-Incident Reviews, express success as an observable decision over event-to-incident threshold, report, command, decision, communication, containment, evidence, recovery, review, and corrective action; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“事后复盘”，以 事件到事故阈值、报告、指挥、决策、通信、遏制、证据、恢复、复盘和纠正行动 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-17.8-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "17.8",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "For Conduct Post-Incident Reviews, express success as an observable decision over complete, attributable, timely, protected, searchable, and actionable security telemetry plus source health; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“事后复盘”，以 完整、可归因、及时、受保护、可检索、可行动的安全遥测及来源健康 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-17.8-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "17.8",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-17.8-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "17.8",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-17.8-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "17.8",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-17.8-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "17.8",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-17.8-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "17.8",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across ambiguous thresholds, compromised primary channels, absent personnel, cross-jurisdiction notice, provider incidents, insider cases, safety events, evidence loss, prolonged recovery, and unresolved actions; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 阈值歧义、主通信通道失陷、人员缺席、跨辖区通知、提供商事件、内部人案件、安全生产事件、证据丢失、长期恢复和未关闭行动 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-17.8-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "17.8",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Include ambiguous classification, unavailable personnel, compromised primary channels, provider and cross-border incidents, insider and safety cases, evidence loss, prolonged recovery, and unresolved actions in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 分类歧义、人员不可用、主通道失陷、提供商与跨境事件、内部人与安全生产案件、证据丢失、长期恢复和未关闭行动 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-17.8-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "17.8",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Include clock skew, actor loss, field truncation, parser drift, dropped or duplicate events, privacy redaction, provider gaps, encrypted paths, quota, and archive failure in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 时钟偏移、行为者丢失、字段截断、解析漂移、事件丢失或重复、隐私脱敏、提供商缺口、加密路径、配额和归档故障 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-17.8-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "17.8",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-17.8-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "17.8",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-17.8-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "17.8",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-17.8-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "17.8",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-17.8-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "17.8",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind incident command and responders, IT and security, legal/privacy, communications, HR, facilities, business owners, executives, providers, insurers, and authorities to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 事件指挥与响应人员、IT 与安全、法务/隐私、传播、HR、设施、业务责任人、管理层、提供商、保险和主管机关 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-17.8-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "17.8",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Name who may transition reported/detected → triaged → declared → commanded → contained → eradicated/recovered → reviewed → actions retested and closed, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 报告/检测 → 分流 → 宣告 → 指挥 → 遏制 → 根除/恢复 → 复盘 → 行动复测关闭，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-17.8-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "17.8",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Name who may transition event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-17.8-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "17.8",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-17.8-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "17.8",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-17.8-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "17.8",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV52, M1, M2) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV52, M1, M2）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-17.8-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "17.8",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-17.8-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "17.8",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the incident taxonomy, case, command, communication, evidence, and action authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把事件分类、案件、指挥、通信、证据与行动权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-17.8-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "17.8",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle reported/detected → triaged → declared → commanded → contained → eradicated/recovered → reviewed → actions retested and closed.",
          "zh": "对生命周期“报告/检测 → 分流 → 宣告 → 指挥 → 遏制 → 根除/恢复 → 复盘 → 行动复测关闭”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-17.8-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "17.8",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired.",
          "zh": "对生命周期“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-17.8-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "17.8",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 17.4; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 17.4 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-17.8-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "17.8",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-17.8-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "17.8",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-17.8-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "17.8",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-17.8-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "17.8",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile reporting channels, monitoring and provider alerts, case systems, contact rosters, communication plans, forensic stores, recovery systems, exercises, and post-incident records and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 报告通道、监测与提供商告警、案件系统、联系人名册、通信计划、取证存储、恢复系统、演练和事后记录，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-17.8-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "17.8",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Require every connector carrying event-to-incident threshold, report, command, decision, communication, containment, evidence, recovery, review, and corrective action to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 事件到事故阈值、报告、指挥、决策、通信、遏制、证据、恢复、复盘和纠正行动 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-17.8-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "17.8",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Require every connector carrying complete, attributable, timely, protected, searchable, and actionable security telemetry plus source health to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 完整、可归因、及时、受保护、可检索、可行动的安全遥测及来源健康 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-17.8-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "17.8",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Set review threshold/timing, preserve facts and uncertainty, include affected teams/providers, identify contributing conditions and assign prioritized actions with owners/dates.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“设复盘门槛/时间，保留事实与不确定，纳入相关团队/服务商，找促成条件并分配有优先、责任、日期的行动；反馈架构、检测、恢复、培训和风险，高层解逾期阻塞。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-17.8-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "17.8",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-17.8-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "17.8",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-17.8-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "17.8",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-17.8-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "17.8",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the incident taxonomy, case, command, communication, evidence, and action authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在事件分类、案件、指挥、通信、证据与行动权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-17.8-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "17.8",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Implement the explicit state machine reported/detected → triaged → declared → commanded → contained → eradicated/recovered → reviewed → actions retested and closed; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“报告/检测 → 分流 → 宣告 → 指挥 → 遏制 → 根除/恢复 → 复盘 → 行动复测关闭”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-17.8-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "17.8",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Implement the explicit state machine event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-17.8-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "17.8",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-17.8-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "17.8",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-17.8-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "17.8",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-17.8-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "17.8",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-17.8-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "17.8",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in security events and incidents, thresholds, reports, roles, decisions, communications, evidence, containment, recovery, review, and follow-up actions; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 安全事件与事故、阈值、报告、角色、决策、通信、证据、遏制、恢复、复盘和后续行动 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-17.8-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "17.8",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for reported/detected → triaged → declared → commanded → contained → eradicated/recovered → reviewed → actions retested and closed; alert before each deadline becomes overdue.",
          "zh": "为“报告/检测 → 分流 → 宣告 → 指挥 → 遏制 → 根除/恢复 → 复盘 → 行动复测关闭”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-17.8-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "17.8",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired; alert before each deadline becomes overdue.",
          "zh": "为“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-17.8-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "17.8",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “CAS checks only whether a last review mentions lessons/actions, with no population or closure.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“CAS 只看上次复盘是否有经验/行动，无总体和关闭。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-17.8-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "17.8",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-17.8-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "17.8",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-17.8-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "17.8",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-17.8-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "17.8",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat ambiguous thresholds, compromised primary channels, absent personnel, cross-jurisdiction notice, provider incidents, insider cases, safety events, evidence loss, prolonged recovery, and unresolved actions as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 阈值歧义、主通信通道失陷、人员缺席、跨辖区通知、提供商事件、内部人案件、安全生产事件、证据丢失、长期恢复和未关闭行动 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-17.8-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "17.8",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Treat ambiguous classification, unavailable personnel, compromised primary channels, provider and cross-border incidents, insider and safety cases, evidence loss, prolonged recovery, and unresolved actions as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 分类歧义、人员不可用、主通道失陷、提供商与跨境事件、内部人与安全生产案件、证据丢失、长期恢复和未关闭行动 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-17.8-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "17.8",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Treat clock skew, actor loss, field truncation, parser drift, dropped or duplicate events, privacy redaction, provider gaps, encrypted paths, quota, and archive failure as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 时钟偏移、行为者丢失、字段截断、解析漂移、事件丢失或重复、隐私脱敏、提供商缺口、加密路径、配额和归档故障 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-17.8-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "17.8",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Sample incidents from declaration to review and trace actions to implemented control and a retest or outcome.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“抽样从宣告追到复盘，把行动追到已实现控制和复测/结果；比较复发、检测/恢复变化，确认假设/争议已标识，敏感/法律材料访问合适。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-17.8-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "17.8",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-17.8-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "17.8",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 3 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、3 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-17.8-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "17.8",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-17.8-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "17.8",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the incident taxonomy, case, command, communication, evidence, and action authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以事件分类、案件、指挥、通信、证据与行动权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-17.8-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "17.8",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Publish events, incidents, severity, ownership, acknowledgement, decision latency, communication success, containment, recovery, evidence gaps, and overdue corrective actions with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 事件、事故、严重度、责任、确认、决策延迟、通信成功、遏制、恢复、证据缺口和逾期纠正行动，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-17.8-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "17.8",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Publish healthy, silent, partial, late, malformed, duplicate, unowned, unreviewed, alerted, investigated, and archived sources or events with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 健康、静默、部分、迟到、畸形、重复、无责任人、未审阅、已告警、已调查和已归档来源或事件，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-17.8-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "17.8",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-17.8-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "17.8",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-17.8-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "17.8",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-17.8-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "17.8",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-17.8-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "17.8",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the incident taxonomy, case, command, communication, evidence, and action authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护事件分类、案件、指挥、通信、证据与行动权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-17.8-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "17.8",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Restrict authority to change reported/detected → triaged → declared → commanded → contained → eradicated/recovered → reviewed → actions retested and closed; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“报告/检测 → 分流 → 宣告 → 指挥 → 遏制 → 根除/恢复 → 复盘 → 行动复测关闭”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-17.8-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "17.8",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Restrict authority to change event produced → collected → parsed → enriched → stored → detected/reviewed → preserved/expired; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“事件产生 → 采集 → 解析 → 丰富 → 存储 → 检测/审阅 → 保全/到期”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-17.8-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "17.8",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-17.8-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "17.8",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-17.8-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "17.8",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-17.8-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "17.8",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-17.8-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "17.8",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise event-versus-incident triage, primary and backup reporting, out-of-band communication, containment and recovery decisions, exercise injects, provider coordination, and action retest through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 事件与事故分流、主备报告、带外通信、遏制与恢复决策、演练注入、提供商协同和行动复测，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-17.8-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "17.8",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Run the positive control a representative report that reaches command, coordinated response, recovery, review, and verified action closure; exercise negative, stale, duplicate, bypass, and outage controls including threshold ambiguity, primary-channel loss, absent role, provider delay, evidence gap, failed containment, recovery dependency, and action recurrence.",
          "zh": "运行正向控制“一项代表性报告进入指挥、协同响应、恢复、复盘并完成行动验证关闭”，并执行包含“阈值歧义、主通道丢失、角色缺席、提供商延迟、证据缺口、遏制失败、恢复依赖和行动复发”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-17.8-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "17.8",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Run the positive control an allowed and denied canary event traced from source through review; exercise negative, stale, duplicate, bypass, and outage controls including source loss, parser/schema change, time skew, queue overflow, duplicate delivery, provider export outage, missed alert, and unreadable archive.",
          "zh": "运行正向控制“一项允许与拒绝金丝雀事件从来源贯穿到审阅”，并执行包含“来源丢失、解析器/模式变化、时钟偏移、队列溢出、重复投递、提供商导出中断、漏报和归档不可读”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-17.8-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "17.8",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-17.8-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "17.8",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-17.8-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "17.8",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-17.8-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "17.8",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-17.8-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "17.8",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever reporting channels, monitoring and provider alerts, case systems, contact rosters, communication plans, forensic stores, recovery systems, exercises, and post-incident records change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 报告通道、监测与提供商告警、案件系统、联系人名册、通信计划、取证存储、恢复系统、演练和事后记录 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-17.8-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "17.8",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Use events, incidents, severity, ownership, acknowledgement, decision latency, communication success, containment, recovery, evidence gaps, and overdue corrective actions to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 事件、事故、严重度、责任、确认、决策延迟、通信成功、遏制、恢复、证据缺口和逾期纠正行动 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-17.8-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "17.8",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original telemetry pattern analysis",
          "basis_zh": "SOSEC 原创 telemetry 模式分析",
          "en": "Use healthy, silent, partial, late, malformed, duplicate, unowned, unreviewed, alerted, investigated, and archived sources or events to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 健康、静默、部分、迟到、畸形、重复、无责任人、未审阅、已告警、已调查和已归档来源或事件 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "17.9",
      "control": 17,
      "title_en": "Establish and Maintain Security Incident Thresholds",
      "title_zh": "事件阈值与分级",
      "first_ig": 3,
      "implementation_groups": [
        3
      ],
      "asset_class": "Documentation",
      "security_function": "Recover",
      "patterns": [
        "incident"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "17.4"
        ],
        "variables": [
          "GV52",
          "M1",
          "M2",
          "M3"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [
        "annually"
      ],
      "implementation_contract": {
        "en": {
          "scope": "Thresholds distinguish observable events, alerts, cases, incidents, privacy breaches and crises; prioritize known/potential impact and drive declaration, status frequency, escalation, containment authority and notification assessment.",
          "build": "Define qualitative/quantitative triggers with decision owners and override, map them to playbooks/SLAs and review annually plus on incidents, regulations, threats or business change.",
          "proof": "Give independent responders ambiguous scenarios and compare classification, actions and communications; inject growing impact and verify escalation/status changes.",
          "boundary": "Rigid record counts can underreact to high-impact single cases and overreact to harmless volume."
        },
        "zh": {
          "scope": "阈值区分 Event、Alert、Case、Incident、隐私 Breach 和 Crisis，按已知/潜在影响排序，并驱动宣告、状态频率、升级、遏制权和通知评估，覆盖机密、完整、可用、安全、欺诈和服务商。",
          "build": "定义定性/定量 Trigger、决策责任与 Override，映射 Playbook/SLA，每年及事件、法规、威胁、业务变化时更新；允许在影响未精确前升级并保留不确定。",
          "proof": "给独立响应者模糊场景，比较分类/动作/通信；逐步扩大影响验证升级和状态频率，复查临界真实案件的延迟、过度宣告和不一致。",
          "boundary": "死板记录数会漏一例高后果或放大无害量。"
        }
      },
      "category_counts": {
        "outcome": 6,
        "scope": 6,
        "ownership": 6,
        "data": 6,
        "integration": 6,
        "control": 6,
        "timing": 6,
        "exception": 6,
        "evidence": 6,
        "security": 6,
        "testing": 6,
        "operations": 6
      },
      "requirement_count": 72,
      "requirements": [
        {
          "code": "CIS-17.9-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "17.9",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Establish and Maintain Security Incident Thresholds; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“事件阈值与分级”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-17.9-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "17.9",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 17.9, official Asset Class Documentation, Security Function Recover, and IG3 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 17.9、官方资产类别“文档与治理”、安全功能“恢复”和首次出现的 IG3，并保存来源抓取日期。"
        },
        {
          "code": "CIS-17.9-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "17.9",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Thresholds distinguish observable events, alerts, cases, incidents, privacy breaches and crises; prioritize known/potential impact and drive declaration, status frequency, escalation, containment authority and notification assessment.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“阈值区分 Event、Alert、Case、Incident、隐私 Breach 和 Crisis，按已知/潜在影响排序，并驱动宣告、状态频率、升级、遏制权和通知评估，覆盖机密、完整、可用、安全、欺诈和服务商。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-17.9-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "17.9",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-17.9-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "17.9",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Establish and Maintain Security Incident Thresholds to its operating object—security events and incidents, thresholds, reports, roles, decisions, communications, evidence, containment, recovery, review, and follow-up actions—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“事件阈值与分级”连接到其运营对象——安全事件与事故、阈值、报告、角色、决策、通信、证据、遏制、恢复、复盘和后续行动——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-17.9-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "17.9",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "For Establish and Maintain Security Incident Thresholds, express success as an observable decision over event-to-incident threshold, report, command, decision, communication, containment, evidence, recovery, review, and corrective action; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“事件阈值与分级”，以 事件到事故阈值、报告、指挥、决策、通信、遏制、证据、恢复、复盘和纠正行动 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-17.9-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "17.9",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-17.9-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "17.9",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-17.9-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "17.9",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-17.9-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "17.9",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-17.9-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "17.9",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across ambiguous thresholds, compromised primary channels, absent personnel, cross-jurisdiction notice, provider incidents, insider cases, safety events, evidence loss, prolonged recovery, and unresolved actions; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 阈值歧义、主通信通道失陷、人员缺席、跨辖区通知、提供商事件、内部人案件、安全生产事件、证据丢失、长期恢复和未关闭行动 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-17.9-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "17.9",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Include ambiguous classification, unavailable personnel, compromised primary channels, provider and cross-border incidents, insider and safety cases, evidence loss, prolonged recovery, and unresolved actions in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 分类歧义、人员不可用、主通道失陷、提供商与跨境事件、内部人与安全生产案件、证据丢失、长期恢复和未关闭行动 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-17.9-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "17.9",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-17.9-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "17.9",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-17.9-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "17.9",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-17.9-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "17.9",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-17.9-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "17.9",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind incident command and responders, IT and security, legal/privacy, communications, HR, facilities, business owners, executives, providers, insurers, and authorities to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 事件指挥与响应人员、IT 与安全、法务/隐私、传播、HR、设施、业务责任人、管理层、提供商、保险和主管机关 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-17.9-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "17.9",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Name who may transition reported/detected → triaged → declared → commanded → contained → eradicated/recovered → reviewed → actions retested and closed, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 报告/检测 → 分流 → 宣告 → 指挥 → 遏制 → 根除/恢复 → 复盘 → 行动复测关闭，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-17.9-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "17.9",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-17.9-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "17.9",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-17.9-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "17.9",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV52, M1, M2, M3) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV52, M1, M2, M3）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-17.9-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "17.9",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-17.9-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "17.9",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the incident taxonomy, case, command, communication, evidence, and action authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把事件分类、案件、指挥、通信、证据与行动权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-17.9-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "17.9",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle reported/detected → triaged → declared → commanded → contained → eradicated/recovered → reviewed → actions retested and closed.",
          "zh": "对生命周期“报告/检测 → 分流 → 宣告 → 指挥 → 遏制 → 根除/恢复 → 复盘 → 行动复测关闭”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-17.9-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "17.9",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 17.4; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 17.4 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-17.9-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "17.9",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-17.9-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "17.9",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-17.9-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "17.9",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-17.9-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "17.9",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile reporting channels, monitoring and provider alerts, case systems, contact rosters, communication plans, forensic stores, recovery systems, exercises, and post-incident records and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 报告通道、监测与提供商告警、案件系统、联系人名册、通信计划、取证存储、恢复系统、演练和事后记录，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-17.9-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "17.9",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Require every connector carrying event-to-incident threshold, report, command, decision, communication, containment, evidence, recovery, review, and corrective action to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 事件到事故阈值、报告、指挥、决策、通信、遏制、证据、恢复、复盘和纠正行动 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-17.9-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "17.9",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Define qualitative/quantitative triggers with decision owners and override, map them to playbooks/SLAs and review annually plus on incidents, regulations, threats or business change.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“定义定性/定量 Trigger、决策责任与 Override，映射 Playbook/SLA，每年及事件、法规、威胁、业务变化时更新；允许在影响未精确前升级并保留不确定。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-17.9-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "17.9",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-17.9-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "17.9",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-17.9-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "17.9",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-17.9-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "17.9",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the incident taxonomy, case, command, communication, evidence, and action authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在事件分类、案件、指挥、通信、证据与行动权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-17.9-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "17.9",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Implement the explicit state machine reported/detected → triaged → declared → commanded → contained → eradicated/recovered → reviewed → actions retested and closed; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“报告/检测 → 分流 → 宣告 → 指挥 → 遏制 → 根除/恢复 → 复盘 → 行动复测关闭”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-17.9-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "17.9",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (annually); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（annually）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-17.9-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "17.9",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-17.9-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "17.9",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-17.9-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "17.9",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-17.9-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "17.9",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in security events and incidents, thresholds, reports, roles, decisions, communications, evidence, containment, recovery, review, and follow-up actions; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 安全事件与事故、阈值、报告、角色、决策、通信、证据、遏制、恢复、复盘和后续行动 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-17.9-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "17.9",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for reported/detected → triaged → declared → commanded → contained → eradicated/recovered → reviewed → actions retested and closed; alert before each deadline becomes overdue.",
          "zh": "为“报告/检测 → 分流 → 宣告 → 指挥 → 遏制 → 根除/恢复 → 复盘 → 行动复测关闭”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-17.9-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "17.9",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “Rigid record counts can underreact to high-impact single cases and overreact to harmless volume.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“死板记录数会漏一例高后果或放大无害量。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-17.9-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "17.9",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-17.9-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "17.9",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-17.9-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "17.9",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-17.9-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "17.9",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat ambiguous thresholds, compromised primary channels, absent personnel, cross-jurisdiction notice, provider incidents, insider cases, safety events, evidence loss, prolonged recovery, and unresolved actions as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 阈值歧义、主通信通道失陷、人员缺席、跨辖区通知、提供商事件、内部人案件、安全生产事件、证据丢失、长期恢复和未关闭行动 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-17.9-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "17.9",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Treat ambiguous classification, unavailable personnel, compromised primary channels, provider and cross-border incidents, insider and safety cases, evidence loss, prolonged recovery, and unresolved actions as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 分类歧义、人员不可用、主通道失陷、提供商与跨境事件、内部人与安全生产案件、证据丢失、长期恢复和未关闭行动 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-17.9-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "17.9",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Give independent responders ambiguous scenarios and compare classification, actions and communications; inject growing impact and verify escalation/status changes.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“给独立响应者模糊场景，比较分类/动作/通信；逐步扩大影响验证升级和状态频率，复查临界真实案件的延迟、过度宣告和不一致。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-17.9-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "17.9",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-17.9-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "17.9",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 4 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、4 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-17.9-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "17.9",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-17.9-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "17.9",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the incident taxonomy, case, command, communication, evidence, and action authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以事件分类、案件、指挥、通信、证据与行动权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-17.9-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "17.9",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Publish events, incidents, severity, ownership, acknowledgement, decision latency, communication success, containment, recovery, evidence gaps, and overdue corrective actions with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 事件、事故、严重度、责任、确认、决策延迟、通信成功、遏制、恢复、证据缺口和逾期纠正行动，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-17.9-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "17.9",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-17.9-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "17.9",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-17.9-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "17.9",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-17.9-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "17.9",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-17.9-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "17.9",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the incident taxonomy, case, command, communication, evidence, and action authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护事件分类、案件、指挥、通信、证据与行动权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-17.9-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "17.9",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Restrict authority to change reported/detected → triaged → declared → commanded → contained → eradicated/recovered → reviewed → actions retested and closed; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“报告/检测 → 分流 → 宣告 → 指挥 → 遏制 → 根除/恢复 → 复盘 → 行动复测关闭”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-17.9-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "17.9",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-17.9-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "17.9",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-17.9-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "17.9",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-17.9-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "17.9",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-17.9-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "17.9",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise event-versus-incident triage, primary and backup reporting, out-of-band communication, containment and recovery decisions, exercise injects, provider coordination, and action retest through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 事件与事故分流、主备报告、带外通信、遏制与恢复决策、演练注入、提供商协同和行动复测，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-17.9-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "17.9",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Run the positive control a representative report that reaches command, coordinated response, recovery, review, and verified action closure; exercise negative, stale, duplicate, bypass, and outage controls including threshold ambiguity, primary-channel loss, absent role, provider delay, evidence gap, failed containment, recovery dependency, and action recurrence.",
          "zh": "运行正向控制“一项代表性报告进入指挥、协同响应、恢复、复盘并完成行动验证关闭”，并执行包含“阈值歧义、主通道丢失、角色缺席、提供商延迟、证据缺口、遏制失败、恢复依赖和行动复发”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-17.9-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "17.9",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-17.9-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "17.9",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-17.9-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "17.9",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-17.9-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "17.9",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-17.9-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "17.9",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever reporting channels, monitoring and provider alerts, case systems, contact rosters, communication plans, forensic stores, recovery systems, exercises, and post-incident records change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 报告通道、监测与提供商告警、案件系统、联系人名册、通信计划、取证存储、恢复系统、演练和事后记录 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-17.9-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "17.9",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original incident pattern analysis",
          "basis_zh": "SOSEC 原创 incident 模式分析",
          "en": "Use events, incidents, severity, ownership, acknowledgement, decision latency, communication success, containment, recovery, evidence gaps, and overdue corrective actions to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 事件、事故、严重度、责任、确认、决策延迟、通信成功、遏制、恢复、证据缺口和逾期纠正行动 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "18.1",
      "control": 18,
      "title_en": "Establish and Maintain a Penetration Testing Program",
      "title_zh": "渗透测试计划",
      "first_ig": 2,
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Documentation",
      "security_function": "Govern",
      "patterns": [
        "adversarial",
        "governance"
      ],
      "expanded_complexity": true,
      "cas_context": {
        "dependencies": [],
        "variables": [
          "GV53",
          "M1",
          "M2",
          "M3"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "The program covers network, web/mobile applications, APIs, cloud/hosted services, identity, wireless, physical and social or provider surfaces according to risk, size and maturity.",
          "build": "Assign an independent program owner, qualified testers, written authorization and safe rules, production coordination, data handling and emergency stop.",
          "proof": "Select tests over a multi-year cycle and trace critical attack surfaces and changes to coverage; run a rules-of-engagement tabletop including outage, discovered active compromise and out-of-scope pivot.",
          "boundary": "A report bought for compliance can repeat the same narrow scope."
        },
        "zh": {
          "scope": "计划按规模、复杂度、行业和成熟度覆盖网络、Web/移动、API、云/托管、身份、无线、物理、社工或服务商面，定义周期/变更触发、范围台账、透明度、攻击限制、联系人、证据、修复、验证和复盘。",
          "build": "指定独立计划负责人和合格测试者，书面授权与安全规则、生产协调、数据处理和急停；轮换对手目标/路径，把发现接修复/RCA，每年及重大变化/测试后更新。",
          "proof": "从多年测试周期把关键攻击面/变化追到覆盖，桌演 Rules of Engagement 中停机、发现真实入侵和越界 Pivot；检查资质、证据保管、限制和发现关闭。",
          "boundary": "为合规买的报告可能年年窄范围。"
        }
      },
      "category_counts": {
        "outcome": 8,
        "scope": 8,
        "ownership": 8,
        "data": 8,
        "integration": 8,
        "control": 8,
        "timing": 8,
        "exception": 8,
        "evidence": 8,
        "security": 8,
        "testing": 8,
        "operations": 8
      },
      "requirement_count": 96,
      "requirements": [
        {
          "code": "CIS-18.1-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "18.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Establish and Maintain a Penetration Testing Program; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“渗透测试计划”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-18.1-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "18.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 18.1, official Asset Class Documentation, Security Function Govern, and IG2 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 18.1、官方资产类别“文档与治理”、安全功能“治理”和首次出现的 IG2，并保存来源抓取日期。"
        },
        {
          "code": "CIS-18.1-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "18.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “The program covers network, web/mobile applications, APIs, cloud/hosted services, identity, wireless, physical and social or provider surfaces according to risk, size and maturity.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“计划按规模、复杂度、行业和成熟度覆盖网络、Web/移动、API、云/托管、身份、无线、物理、社工或服务商面，定义周期/变更触发、范围台账、透明度、攻击限制、联系人、证据、修复、验证和复盘。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-18.1-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "18.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-18.1-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "18.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Establish and Maintain a Penetration Testing Program to its operating object—authorized external and internal attack paths across networks, applications, APIs, cloud, identity, physical controls, people, and chained business impact—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“渗透测试计划”连接到其运营对象——网络、应用、API、云、身份、物理控制、人员及业务影响链上的授权内外部攻击路径——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-18.1-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "18.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "For Establish and Maintain a Penetration Testing Program, express success as an observable decision over authorized attack hypothesis, realistic path, controlled objective, observable defense response, finding, remediation, independent retest, and regression; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“渗透测试计划”，以 授权攻击假设、真实路径、受控目标、可观察防御响应、发现、修复、独立复测和回归 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-18.1-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "18.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "For Establish and Maintain a Penetration Testing Program, express success as an observable decision over a documented decision system with policy, process, procedure, accountable owner, approval, and review; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“渗透测试计划”，以 包含策略、流程、程序、责任人、审批和复核的文档化决策系统 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-18.1-OUT-08",
          "local_code": "OUT-08",
          "display_code": "O08",
          "safeguard_id": "18.1",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "For the expanded Establish and Maintain a Penetration Testing Program scope, resolve conflicts among security, safety, privacy, legal, availability, customer, and operational objectives through an explicit risk decision.",
          "zh": "对“渗透测试计划”的扩展范围，通过显式风险决策解决安全、安全生产、隐私、法律、可用性、客户和运营目标冲突。"
        },
        {
          "code": "CIS-18.1-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "18.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-18.1-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "18.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-18.1-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "18.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-18.1-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "18.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-18.1-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "18.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across scope drift, unsafe techniques, shared tenants, third-party infrastructure, production impact, incomplete credentials, discovered critical paths, data handling, test detectability, and finding recurrence; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 范围漂移、不安全技术、共享租户、第三方基础设施、生产影响、凭据不完整、新发现关键路径、数据处理、测试可检测性和问题复发 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-18.1-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "18.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Include scope drift, unsafe techniques, shared tenants, third-party systems, production impact, incomplete credentials, newly discovered critical paths, sensitive test data, and undetected activity in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 范围漂移、不安全技术、共享租户、第三方系统、生产影响、凭据不完整、新发现关键路径、敏感测试数据和未检测活动 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-18.1-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "18.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Include missing policy clauses, conflicting authorities, local deviations, obsolete documentation, and decisions made outside the governed workflow in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 策略条款缺失、权限冲突、本地偏离、文档过期及绕过治理流程的决策 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-18.1-SCP-08",
          "local_code": "SCP-08",
          "display_code": "P08",
          "safeguard_id": "18.1",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Define nested scope at enterprise, business service, tenant, environment, platform, object, identity, data set, and transaction levels; prohibit a parent result from hiding a failing child.",
          "zh": "按企业、业务服务、租户、环境、平台、对象、身份、数据集和交易定义嵌套范围，禁止父级结果遮蔽失败子级。"
        },
        {
          "code": "CIS-18.1-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "18.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-18.1-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "18.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-18.1-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "18.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-18.1-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "18.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-18.1-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "18.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind test sponsors, qualified testers, system and business owners, security operations, incident response, legal/privacy, safety, providers, and remediation teams to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 测试发起人、合格测试方、系统与业务责任人、安全运营、事件响应、法务/隐私、安全生产、提供商和修复团队 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-18.1-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "18.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Name who may transition authorized → scoped → rehearsed → executed with stop conditions → evidenced → triaged → remediated → independently retested → regression monitored, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 授权 → 定范围 → 预演 → 带停止条件执行 → 取证 → 分流 → 修复 → 独立复测 → 回归监测，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-18.1-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "18.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Name who may transition draft → reviewed → approved → effective → exception/withdrawn → superseded, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-18.1-OWN-08",
          "local_code": "OWN-08",
          "display_code": "W08",
          "safeguard_id": "18.1",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Model delegated authority, quorum or dual approval where warranted, escalation deadlines, provider handoffs, conflict resolution, and executive risk acceptance.",
          "zh": "建模委派权限、必要时的双人或法定人数审批、升级期限、提供商交接、冲突解决和管理层风险接受。"
        },
        {
          "code": "CIS-18.1-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "18.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-18.1-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "18.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-18.1-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "18.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV53, M1, M2, M3) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV53, M1, M2, M3）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-18.1-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "18.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-18.1-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "18.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the penetration-testing scope, authorization, finding, remediation, validation, and regression authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把渗透测试范围、授权、发现、修复、验证与回归权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-18.1-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "18.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle authorized → scoped → rehearsed → executed with stop conditions → evidenced → triaged → remediated → independently retested → regression monitored.",
          "zh": "对生命周期“授权 → 定范围 → 预演 → 带停止条件执行 → 取证 → 分流 → 修复 → 独立复测 → 回归监测”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-18.1-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "18.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle draft → reviewed → approved → effective → exception/withdrawn → superseded.",
          "zh": "对生命周期“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-18.1-DAT-08",
          "local_code": "DAT-08",
          "display_code": "D08",
          "safeguard_id": "18.1",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Version schemas and state transitions with migration, backfill, deduplication, lineage, historical denominator, deletion, and rollback semantics.",
          "zh": "对模式和状态转换做版本管理，定义迁移、回填、去重、血缘、历史分母、删除和回滚语义。"
        },
        {
          "code": "CIS-18.1-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "18.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for no explicit predecessor in the pinned CAS page; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 固定 CAS 页面没有列出显式前置项 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-18.1-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "18.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-18.1-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "18.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-18.1-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "18.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-18.1-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "18.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile asset and exposure inventories, architecture and threat models, rules of engagement, credentials, tester records, evidence, findings, remediation tickets, detections, and retest results and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 资产与暴露清单、架构与威胁模型、交战规则、凭据、测试人员记录、证据、发现、修复工单、检测和复测结果，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-18.1-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "18.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Require every connector carrying authorized attack hypothesis, realistic path, controlled objective, observable defense response, finding, remediation, independent retest, and regression to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 授权攻击假设、真实路径、受控目标、可观察防御响应、发现、修复、独立复测和回归 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-18.1-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "18.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Require every connector carrying a documented decision system with policy, process, procedure, accountable owner, approval, and review to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 包含策略、流程、程序、责任人、审批和复核的文档化决策系统 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-18.1-INT-08",
          "local_code": "INT-08",
          "display_code": "I08",
          "safeguard_id": "18.1",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Define consistency rules across disagreeing sources, source precedence, confidence, reconciliation queues, dead-letter handling, reprocessing, and end-to-end trace identity.",
          "zh": "定义冲突来源的一致性、优先级、置信度、对账队列、死信、重处理和端到端追踪身份。"
        },
        {
          "code": "CIS-18.1-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "18.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Assign an independent program owner, qualified testers, written authorization and safe rules, production coordination, data handling and emergency stop.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“指定独立计划负责人和合格测试者，书面授权与安全规则、生产协调、数据处理和急停；轮换对手目标/路径，把发现接修复/RCA，每年及重大变化/测试后更新。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-18.1-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "18.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-18.1-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "18.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-18.1-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "18.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-18.1-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "18.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the penetration-testing scope, authorization, finding, remediation, validation, and regression authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在渗透测试范围、授权、发现、修复、验证与回归权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-18.1-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "18.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Implement the explicit state machine authorized → scoped → rehearsed → executed with stop conditions → evidenced → triaged → remediated → independently retested → regression monitored; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“授权 → 定范围 → 预演 → 带停止条件执行 → 取证 → 分流 → 修复 → 独立复测 → 回归监测”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-18.1-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "18.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Implement the explicit state machine draft → reviewed → approved → effective → exception/withdrawn → superseded; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-18.1-CTL-08",
          "local_code": "CTL-08",
          "display_code": "C08",
          "safeguard_id": "18.1",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Specify concurrent decisions, partial success, compensating transactions, repeated requests, stale policy, dependency outage, and recovery from an interrupted state transition.",
          "zh": "定义并发决策、部分成功、补偿事务、重复请求、陈旧策略、依赖中断和中途状态转换恢复。"
        },
        {
          "code": "CIS-18.1-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "18.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-18.1-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "18.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-18.1-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "18.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-18.1-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "18.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-18.1-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "18.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in authorized external and internal attack paths across networks, applications, APIs, cloud, identity, physical controls, people, and chained business impact; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 网络、应用、API、云、身份、物理控制、人员及业务影响链上的授权内外部攻击路径 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-18.1-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "18.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for authorized → scoped → rehearsed → executed with stop conditions → evidenced → triaged → remediated → independently retested → regression monitored; alert before each deadline becomes overdue.",
          "zh": "为“授权 → 定范围 → 预演 → 带停止条件执行 → 取证 → 分流 → 修复 → 独立复测 → 回归监测”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-18.1-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "18.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for draft → reviewed → approved → effective → exception/withdrawn → superseded; alert before each deadline becomes overdue.",
          "zh": "为“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-18.1-TIM-08",
          "local_code": "TIM-08",
          "display_code": "T08",
          "safeguard_id": "18.1",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Allocate an end-to-end SLO budget across discovery, collection, processing, approval, enforcement, verification, and closure; prioritize overdue work by consequence and exposure.",
          "zh": "把端到端 SLO 预算分配到发现、采集、处理、审批、执行、验证和关闭，并按后果与暴露排列逾期工作。"
        },
        {
          "code": "CIS-18.1-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "18.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “A report bought for compliance can repeat the same narrow scope.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“为合规买的报告可能年年窄范围。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-18.1-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "18.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-18.1-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "18.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-18.1-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "18.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-18.1-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "18.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat scope drift, unsafe techniques, shared tenants, third-party infrastructure, production impact, incomplete credentials, discovered critical paths, data handling, test detectability, and finding recurrence as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 范围漂移、不安全技术、共享租户、第三方基础设施、生产影响、凭据不完整、新发现关键路径、数据处理、测试可检测性和问题复发 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-18.1-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "18.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Treat scope drift, unsafe techniques, shared tenants, third-party systems, production impact, incomplete credentials, newly discovered critical paths, sensitive test data, and undetected activity as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 范围漂移、不安全技术、共享租户、第三方系统、生产影响、凭据不完整、新发现关键路径、敏感测试数据和未检测活动 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-18.1-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "18.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Treat missing policy clauses, conflicting authorities, local deviations, obsolete documentation, and decisions made outside the governed workflow as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 策略条款缺失、权限冲突、本地偏离、文档过期及绕过治理流程的决策 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-18.1-EXC-08",
          "local_code": "EXC-08",
          "display_code": "X08",
          "safeguard_id": "18.1",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Exercise compound failures where an exception, stale source, provider outage, unavailable owner, and degraded control overlap; define one safe command and one accountable decision.",
          "zh": "演练例外、陈旧来源、提供商中断、责任人不可用和控制降级同时出现的复合故障，明确一条安全指令和一个责任决策。"
        },
        {
          "code": "CIS-18.1-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "18.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Select tests over a multi-year cycle and trace critical attack surfaces and changes to coverage; run a rules-of-engagement tabletop including outage, discovered active compromise and out-of-scope pivot.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“从多年测试周期把关键攻击面/变化追到覆盖，桌演 Rules of Engagement 中停机、发现真实入侵和越界 Pivot；检查资质、证据保管、限制和发现关闭。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-18.1-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "18.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-18.1-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "18.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 4 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、4 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-18.1-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "18.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-18.1-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "18.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the penetration-testing scope, authorization, finding, remediation, validation, and regression authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以渗透测试范围、授权、发现、修复、验证与回归权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-18.1-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "18.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Publish planned, executed, stopped, out-of-scope, prevented, detected, contained, missed, found, fixed, retest-passed, recurrent, and untested attack paths with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 计划、执行、停止、越界、已阻断、已检测、已遏制、漏检、发现、修复、复测通过、复发和未测试攻击路径，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-18.1-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "18.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Publish clause coverage, owner and reviewer completeness, approval age, triggered reviews, deviations, overdue actions, and superseded versions still in use with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 条款覆盖、责任人与复核人完整性、批准年龄、触发式复核、偏离、逾期行动及仍在使用的旧版本，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-18.1-EVD-08",
          "local_code": "EVD-08",
          "display_code": "E08",
          "safeguard_id": "18.1",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Require an independent party to reconstruct the decision from source receipts and reproduce the population, state transition, calculation, test result, exception, and final closure.",
          "zh": "要求独立人员使用来源回执重建决策，并复现总体、状态转换、计算、测试结果、例外和最终关闭。"
        },
        {
          "code": "CIS-18.1-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "18.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-18.1-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "18.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-18.1-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "18.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-18.1-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "18.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-18.1-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "18.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the penetration-testing scope, authorization, finding, remediation, validation, and regression authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护渗透测试范围、授权、发现、修复、验证与回归权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-18.1-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "18.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Restrict authority to change authorized → scoped → rehearsed → executed with stop conditions → evidenced → triaged → remediated → independently retested → regression monitored; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“授权 → 定范围 → 预演 → 带停止条件执行 → 取证 → 分流 → 修复 → 独立复测 → 回归监测”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-18.1-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "18.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Restrict authority to change draft → reviewed → approved → effective → exception/withdrawn → superseded; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“草拟 → 评审 → 批准 → 生效 → 例外/撤回 → 被取代”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-18.1-SEC-08",
          "local_code": "SEC-08",
          "display_code": "S08",
          "safeguard_id": "18.1",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Threat-model the implementation system itself: forged evidence, poisoned inventory, privilege abuse, cross-tenant confusion, policy rollback, audit deletion, denial of service, and recovery compromise.",
          "zh": "威胁建模实施系统自身：伪造证据、污染清单、权限滥用、跨租户混淆、策略回滚、审计删除、拒绝服务和恢复失陷。"
        },
        {
          "code": "CIS-18.1-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "18.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-18.1-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "18.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-18.1-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "18.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-18.1-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "18.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-18.1-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "18.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise external and internal reconnaissance, unauthenticated and authenticated paths, segmentation and privilege chains, controlled objectives, stop conditions, detection response, remediation, and independent retest through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 外部与内部侦察、未认证与已认证路径、分段与权限链、受控目标、停止条件、检测响应、修复和独立复测，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-18.1-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "18.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Run the positive control a controlled objective that exercises prevention, detection, response, and safe recovery; exercise negative, stale, duplicate, bypass, and outage controls including an unauthorized path, scope ambiguity, missed detection, unsafe impact, incomplete evidence, failed remediation, transferred discovery method, and regression.",
          "zh": "运行正向控制“一项同时检验预防、检测、响应和安全恢复的受控目标”，并执行包含“未授权路径、范围歧义、漏检、不安全影响、证据不完整、修复失败、旧发现方法迁移和回归”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-18.1-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "18.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Run the positive control an approved current process used for a representative decision; exercise negative, stale, duplicate, bypass, and outage controls including an obsolete version, missing approver, undocumented deviation, overdue review, and bypassed workflow.",
          "zh": "运行正向控制“使用当前获批流程完成一项代表性决策”，并执行包含“旧版本、审批人缺失、未记录偏离、逾期复核和绕过流程”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-18.1-TST-08",
          "local_code": "TST-08",
          "display_code": "V08",
          "safeguard_id": "18.1",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Build a pairwise platform-and-failure matrix, then add high-consequence multi-factor cases, historical regression, source substitution, red-team challenge, and assessor replay.",
          "zh": "建立平台—故障两两组合矩阵，再加入高后果多因素案例、历史回归、来源替换、红队挑战和评估方重放。"
        },
        {
          "code": "CIS-18.1-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "18.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-18.1-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "18.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-18.1-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "18.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-18.1-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "18.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-18.1-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "18.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever asset and exposure inventories, architecture and threat models, rules of engagement, credentials, tester records, evidence, findings, remediation tickets, detections, and retest results change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 资产与暴露清单、架构与威胁模型、交战规则、凭据、测试人员记录、证据、发现、修复工单、检测和复测结果 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-18.1-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "18.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Use planned, executed, stopped, out-of-scope, prevented, detected, contained, missed, found, fixed, retest-passed, recurrent, and untested attack paths to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 计划、执行、停止、越界、已阻断、已检测、已遏制、漏检、发现、修复、复测通过、复发和未测试攻击路径 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-18.1-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "18.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original governance pattern analysis",
          "basis_zh": "SOSEC 原创 governance 模式分析",
          "en": "Use clause coverage, owner and reviewer completeness, approval age, triggered reviews, deviations, overdue actions, and superseded versions still in use to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 条款覆盖、责任人与复核人完整性、批准年龄、触发式复核、偏离、逾期行动及仍在使用的旧版本 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-18.1-OPS-08",
          "local_code": "OPS-08",
          "display_code": "R08",
          "safeguard_id": "18.1",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC expanded-complexity PRD analysis",
          "basis_zh": "SOSEC 扩展复杂度原创 PRD 分析",
          "en": "Use canary deployment, kill criteria, rollback, backlog burn-down, exception reduction, source-quality targets, quarterly design review, and a measurable retirement plan.",
          "zh": "采用金丝雀、停止标准、回滚、积压燃尽、例外缩减、来源质量目标、季度设计复核和可量化退役计划。"
        }
      ]
    },
    {
      "id": "18.2",
      "control": 18,
      "title_en": "Perform Periodic External Penetration Tests",
      "title_zh": "周期性外部渗透测试",
      "first_ig": 2,
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Network",
      "security_function": "Detect",
      "patterns": [
        "adversarial"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "18.1"
        ],
        "variables": [
          "GV54",
          "M1"
        ],
        "metric_branches": 0,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [
        "annually",
        "no less than annually"
      ],
      "implementation_contract": {
        "en": {
          "scope": "At least annually, test the enterprise from outside using reconnaissance that includes public infrastructure, domains, cloud, applications/APIs, credentials/leaks and environmental information within authorization.",
          "build": "Use a qualified independent party, freeze and verify targets/contacts, define safe proof and stop rules, test discovery through exploit chains and business impact, and coordinate without over-whitelisting defenses.",
          "proof": "Compare tester reconnaissance with asset inventories, validate exploitable findings safely, test direct origin/IPv6/alternate domains and record detection/response observed.",
          "boundary": "CAS checks only the report date, so a one-host scan can pass."
        },
        "zh": {
          "scope": "至少年度从外部测试，侦察公开基础设施、域名、云、应用/API、凭据泄露和环境信息，范围跟真实暴露而非去年 IP 表；可 Clear-box 或 Opaque-box。",
          "build": "用合格独立方，冻结并核对目标/联系人，定义安全证明/急停，测试从发现到利用链和业务影响，不要过度 Whitelist 防守；重大暴露/架构变化后追加。",
          "proof": "把测试者侦察与资产台账比较，安全验证可利用发现，测试直连 Origin、IPv6、替代域并记录检测/响应；保存版本、日期、限制和负控，发现路由并复测。",
          "boundary": "CAS 只看报告日期，一台主机扫描也可过。"
        }
      },
      "category_counts": {
        "outcome": 6,
        "scope": 6,
        "ownership": 6,
        "data": 6,
        "integration": 6,
        "control": 6,
        "timing": 6,
        "exception": 6,
        "evidence": 6,
        "security": 6,
        "testing": 6,
        "operations": 6
      },
      "requirement_count": 72,
      "requirements": [
        {
          "code": "CIS-18.2-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "18.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Perform Periodic External Penetration Tests; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“周期性外部渗透测试”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-18.2-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "18.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 18.2, official Asset Class Network, Security Function Detect, and IG2 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 18.2、官方资产类别“网络”、安全功能“检测”和首次出现的 IG2，并保存来源抓取日期。"
        },
        {
          "code": "CIS-18.2-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "18.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “At least annually, test the enterprise from outside using reconnaissance that includes public infrastructure, domains, cloud, applications/APIs, credentials/leaks and environmental information within authorization.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“至少年度从外部测试，侦察公开基础设施、域名、云、应用/API、凭据泄露和环境信息，范围跟真实暴露而非去年 IP 表；可 Clear-box 或 Opaque-box。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-18.2-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "18.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-18.2-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "18.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Perform Periodic External Penetration Tests to its operating object—authorized external and internal attack paths across networks, applications, APIs, cloud, identity, physical controls, people, and chained business impact—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“周期性外部渗透测试”连接到其运营对象——网络、应用、API、云、身份、物理控制、人员及业务影响链上的授权内外部攻击路径——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-18.2-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "18.2",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "For Perform Periodic External Penetration Tests, express success as an observable decision over authorized attack hypothesis, realistic path, controlled objective, observable defense response, finding, remediation, independent retest, and regression; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“周期性外部渗透测试”，以 授权攻击假设、真实路径、受控目标、可观察防御响应、发现、修复、独立复测和回归 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-18.2-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "18.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-18.2-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "18.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-18.2-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "18.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-18.2-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "18.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-18.2-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "18.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across scope drift, unsafe techniques, shared tenants, third-party infrastructure, production impact, incomplete credentials, discovered critical paths, data handling, test detectability, and finding recurrence; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 范围漂移、不安全技术、共享租户、第三方基础设施、生产影响、凭据不完整、新发现关键路径、数据处理、测试可检测性和问题复发 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-18.2-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "18.2",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Include scope drift, unsafe techniques, shared tenants, third-party systems, production impact, incomplete credentials, newly discovered critical paths, sensitive test data, and undetected activity in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 范围漂移、不安全技术、共享租户、第三方系统、生产影响、凭据不完整、新发现关键路径、敏感测试数据和未检测活动 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-18.2-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "18.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-18.2-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "18.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-18.2-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "18.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-18.2-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "18.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-18.2-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "18.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind test sponsors, qualified testers, system and business owners, security operations, incident response, legal/privacy, safety, providers, and remediation teams to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 测试发起人、合格测试方、系统与业务责任人、安全运营、事件响应、法务/隐私、安全生产、提供商和修复团队 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-18.2-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "18.2",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Name who may transition authorized → scoped → rehearsed → executed with stop conditions → evidenced → triaged → remediated → independently retested → regression monitored, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 授权 → 定范围 → 预演 → 带停止条件执行 → 取证 → 分流 → 修复 → 独立复测 → 回归监测，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-18.2-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "18.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-18.2-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "18.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-18.2-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "18.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV54, M1) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV54, M1）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-18.2-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "18.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-18.2-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "18.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the penetration-testing scope, authorization, finding, remediation, validation, and regression authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把渗透测试范围、授权、发现、修复、验证与回归权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-18.2-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "18.2",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle authorized → scoped → rehearsed → executed with stop conditions → evidenced → triaged → remediated → independently retested → regression monitored.",
          "zh": "对生命周期“授权 → 定范围 → 预演 → 带停止条件执行 → 取证 → 分流 → 修复 → 独立复测 → 回归监测”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-18.2-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "18.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 18.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 18.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-18.2-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "18.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-18.2-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "18.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-18.2-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "18.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-18.2-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "18.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile asset and exposure inventories, architecture and threat models, rules of engagement, credentials, tester records, evidence, findings, remediation tickets, detections, and retest results and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 资产与暴露清单、架构与威胁模型、交战规则、凭据、测试人员记录、证据、发现、修复工单、检测和复测结果，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-18.2-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "18.2",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Require every connector carrying authorized attack hypothesis, realistic path, controlled objective, observable defense response, finding, remediation, independent retest, and regression to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 授权攻击假设、真实路径、受控目标、可观察防御响应、发现、修复、独立复测和回归 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-18.2-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "18.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Use a qualified independent party, freeze and verify targets/contacts, define safe proof and stop rules, test discovery through exploit chains and business impact, and coordinate without over-whitelisting defenses.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“用合格独立方，冻结并核对目标/联系人，定义安全证明/急停，测试从发现到利用链和业务影响，不要过度 Whitelist 防守；重大暴露/架构变化后追加。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-18.2-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "18.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-18.2-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "18.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-18.2-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "18.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-18.2-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "18.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the penetration-testing scope, authorization, finding, remediation, validation, and regression authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在渗透测试范围、授权、发现、修复、验证与回归权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-18.2-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "18.2",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Implement the explicit state machine authorized → scoped → rehearsed → executed with stop conditions → evidenced → triaged → remediated → independently retested → regression monitored; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“授权 → 定范围 → 预演 → 带停止条件执行 → 取证 → 分流 → 修复 → 独立复测 → 回归监测”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-18.2-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "18.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (annually, no less than annually); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（annually, no less than annually）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-18.2-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "18.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-18.2-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "18.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-18.2-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "18.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-18.2-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "18.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in authorized external and internal attack paths across networks, applications, APIs, cloud, identity, physical controls, people, and chained business impact; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 网络、应用、API、云、身份、物理控制、人员及业务影响链上的授权内外部攻击路径 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-18.2-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "18.2",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for authorized → scoped → rehearsed → executed with stop conditions → evidenced → triaged → remediated → independently retested → regression monitored; alert before each deadline becomes overdue.",
          "zh": "为“授权 → 定范围 → 预演 → 带停止条件执行 → 取证 → 分流 → 修复 → 独立复测 → 回归监测”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-18.2-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "18.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “CAS checks only the report date, so a one-host scan can pass.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“CAS 只看报告日期，一台主机扫描也可过。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-18.2-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "18.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-18.2-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "18.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-18.2-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "18.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-18.2-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "18.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat scope drift, unsafe techniques, shared tenants, third-party infrastructure, production impact, incomplete credentials, discovered critical paths, data handling, test detectability, and finding recurrence as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 范围漂移、不安全技术、共享租户、第三方基础设施、生产影响、凭据不完整、新发现关键路径、数据处理、测试可检测性和问题复发 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-18.2-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "18.2",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Treat scope drift, unsafe techniques, shared tenants, third-party systems, production impact, incomplete credentials, newly discovered critical paths, sensitive test data, and undetected activity as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 范围漂移、不安全技术、共享租户、第三方系统、生产影响、凭据不完整、新发现关键路径、敏感测试数据和未检测活动 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-18.2-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "18.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Compare tester reconnaissance with asset inventories, validate exploitable findings safely, test direct origin/IPv6/alternate domains and record detection/response observed.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“把测试者侦察与资产台账比较，安全验证可利用发现，测试直连 Origin、IPv6、替代域并记录检测/响应；保存版本、日期、限制和负控，发现路由并复测。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-18.2-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "18.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-18.2-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "18.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 0 pinned CAS metric branch(es), 2 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 0 个指标分支、2 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-18.2-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "18.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-18.2-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "18.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the penetration-testing scope, authorization, finding, remediation, validation, and regression authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以渗透测试范围、授权、发现、修复、验证与回归权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-18.2-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "18.2",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Publish planned, executed, stopped, out-of-scope, prevented, detected, contained, missed, found, fixed, retest-passed, recurrent, and untested attack paths with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 计划、执行、停止、越界、已阻断、已检测、已遏制、漏检、发现、修复、复测通过、复发和未测试攻击路径，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-18.2-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "18.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-18.2-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "18.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-18.2-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "18.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-18.2-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "18.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-18.2-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "18.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the penetration-testing scope, authorization, finding, remediation, validation, and regression authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护渗透测试范围、授权、发现、修复、验证与回归权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-18.2-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "18.2",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Restrict authority to change authorized → scoped → rehearsed → executed with stop conditions → evidenced → triaged → remediated → independently retested → regression monitored; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“授权 → 定范围 → 预演 → 带停止条件执行 → 取证 → 分流 → 修复 → 独立复测 → 回归监测”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-18.2-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "18.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-18.2-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "18.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-18.2-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "18.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-18.2-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "18.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-18.2-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "18.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise external and internal reconnaissance, unauthenticated and authenticated paths, segmentation and privilege chains, controlled objectives, stop conditions, detection response, remediation, and independent retest through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 外部与内部侦察、未认证与已认证路径、分段与权限链、受控目标、停止条件、检测响应、修复和独立复测，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-18.2-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "18.2",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Run the positive control a controlled objective that exercises prevention, detection, response, and safe recovery; exercise negative, stale, duplicate, bypass, and outage controls including an unauthorized path, scope ambiguity, missed detection, unsafe impact, incomplete evidence, failed remediation, transferred discovery method, and regression.",
          "zh": "运行正向控制“一项同时检验预防、检测、响应和安全恢复的受控目标”，并执行包含“未授权路径、范围歧义、漏检、不安全影响、证据不完整、修复失败、旧发现方法迁移和回归”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-18.2-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "18.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-18.2-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "18.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-18.2-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "18.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-18.2-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "18.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-18.2-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "18.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever asset and exposure inventories, architecture and threat models, rules of engagement, credentials, tester records, evidence, findings, remediation tickets, detections, and retest results change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 资产与暴露清单、架构与威胁模型、交战规则、凭据、测试人员记录、证据、发现、修复工单、检测和复测结果 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-18.2-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "18.2",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Use planned, executed, stopped, out-of-scope, prevented, detected, contained, missed, found, fixed, retest-passed, recurrent, and untested attack paths to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 计划、执行、停止、越界、已阻断、已检测、已遏制、漏检、发现、修复、复测通过、复发和未测试攻击路径 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "18.3",
      "control": 18,
      "title_en": "Remediate Penetration Test Findings",
      "title_zh": "渗透发现修复",
      "first_ig": 2,
      "implementation_groups": [
        2,
        3
      ],
      "asset_class": "Network",
      "security_function": "Protect",
      "patterns": [
        "adversarial",
        "vulnerability"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "18.2"
        ],
        "variables": [
          "GV53",
          "GV54",
          "M1",
          "M2",
          "M3",
          "M4",
          "M5"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "Every penetration finding maps to affected path/assets, consequence, reproduction evidence, owner, risk-based deadline and treatment under the vulnerability process.",
          "build": "Triage jointly with testers and owners, patch/redesign/configure/remove or contain, address root causes and retest the exact exploit plus normal business behavior.",
          "proof": "Have the tester or independent reviewer repeat the exploit after treatment with positive controls proving the path/test still works.",
          "boundary": "The CAS reverses M2/M3 meanings and its formula can reward still-unremediated findings, so it is unusable verbatim."
        },
        "zh": {
          "scope": "每个发现关联受影响路径/资产、后果、复现、责任人、风险到期和漏洞流程处置；串链发现保持关联，修掉一步不能误判整链消失。",
          "build": "测试者/责任人共同分诊，补丁/重设/改配/移除或遏制，处理根因，并复测准确利用与正常业务；例外写剩余链、补偿和到期，追踪后续复发。",
          "proof": "由测试者或独立者处理后复做利用，并用正控证明测试仍有效；核验运行状态和替代路径，分别报告验证修复、缓解、接受、误报和按风险逾期。",
          "boundary": "CAS 把 M2/M3 的已修/未修含义写反，公式反而会奖励未修，不能直接用。"
        }
      },
      "category_counts": {
        "outcome": 7,
        "scope": 7,
        "ownership": 7,
        "data": 7,
        "integration": 7,
        "control": 7,
        "timing": 7,
        "exception": 7,
        "evidence": 7,
        "security": 7,
        "testing": 7,
        "operations": 7
      },
      "requirement_count": 84,
      "requirements": [
        {
          "code": "CIS-18.3-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "18.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Remediate Penetration Test Findings; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“渗透发现修复”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-18.3-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "18.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 18.3, official Asset Class Network, Security Function Protect, and IG2 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 18.3、官方资产类别“网络”、安全功能“保护”和首次出现的 IG2，并保存来源抓取日期。"
        },
        {
          "code": "CIS-18.3-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "18.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “Every penetration finding maps to affected path/assets, consequence, reproduction evidence, owner, risk-based deadline and treatment under the vulnerability process.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“每个发现关联受影响路径/资产、后果、复现、责任人、风险到期和漏洞流程处置；串链发现保持关联，修掉一步不能误判整链消失。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-18.3-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "18.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-18.3-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "18.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Remediate Penetration Test Findings to its operating object—authorized external and internal attack paths across networks, applications, APIs, cloud, identity, physical controls, people, and chained business impact—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“渗透发现修复”连接到其运营对象——网络、应用、API、云、身份、物理控制、人员及业务影响链上的授权内外部攻击路径——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-18.3-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "18.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "For Remediate Penetration Test Findings, express success as an observable decision over authorized attack hypothesis, realistic path, controlled objective, observable defense response, finding, remediation, independent retest, and regression; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“渗透发现修复”，以 授权攻击假设、真实路径、受控目标、可观察防御响应、发现、修复、独立复测和回归 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-18.3-OUT-07",
          "local_code": "OUT-07",
          "display_code": "O07",
          "safeguard_id": "18.3",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "For Remediate Penetration Test Findings, express success as an observable decision over affected artifact identity, exploitability, business consequence, remediation choice, deployed fix, compensating control, and residual exposure; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“渗透发现修复”，以 受影响制品身份、可利用性、业务后果、修复选择、已部署修复、补偿控制和残余暴露 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-18.3-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "18.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-18.3-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "18.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-18.3-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "18.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-18.3-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "18.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-18.3-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "18.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across scope drift, unsafe techniques, shared tenants, third-party infrastructure, production impact, incomplete credentials, discovered critical paths, data handling, test detectability, and finding recurrence; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 范围漂移、不安全技术、共享租户、第三方基础设施、生产影响、凭据不完整、新发现关键路径、数据处理、测试可检测性和问题复发 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-18.3-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "18.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Include scope drift, unsafe techniques, shared tenants, third-party systems, production impact, incomplete credentials, newly discovered critical paths, sensitive test data, and undetected activity in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 范围漂移、不安全技术、共享租户、第三方系统、生产影响、凭据不完整、新发现关键路径、敏感测试数据和未检测活动 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-18.3-SCP-07",
          "local_code": "SCP-07",
          "display_code": "P07",
          "safeguard_id": "18.3",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Include unknown versions, false positives, unavailable fixes, vendor lag, ephemeral workloads, unscannable platforms, inherited dependencies, mitigation-only states, and recurrence in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 未知版本、误报、无可用修复、厂商滞后、短生工作负载、不可扫描平台、继承依赖、仅缓解状态和复发 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-18.3-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "18.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-18.3-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "18.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-18.3-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "18.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-18.3-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "18.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-18.3-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "18.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind test sponsors, qualified testers, system and business owners, security operations, incident response, legal/privacy, safety, providers, and remediation teams to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 测试发起人、合格测试方、系统与业务责任人、安全运营、事件响应、法务/隐私、安全生产、提供商和修复团队 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-18.3-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "18.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Name who may transition authorized → scoped → rehearsed → executed with stop conditions → evidenced → triaged → remediated → independently retested → regression monitored, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 授权 → 定范围 → 预演 → 带停止条件执行 → 取证 → 分流 → 修复 → 独立复测 → 回归监测，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-18.3-OWN-07",
          "local_code": "OWN-07",
          "display_code": "W07",
          "safeguard_id": "18.3",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Name who may transition discovered → validated → prioritized → assigned → fixed/mitigated/excepted → deployed → retested → closed/reopened, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 发现 → 验证 → 定级 → 分派 → 修复/缓解/例外 → 部署 → 复测 → 关闭/重开，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-18.3-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "18.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-18.3-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "18.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-18.3-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "18.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV53, GV54, M1, M2, M3, M4, M5) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV53, GV54, M1, M2, M3, M4, M5）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-18.3-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "18.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-18.3-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "18.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the penetration-testing scope, authorization, finding, remediation, validation, and regression authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把渗透测试范围、授权、发现、修复、验证与回归权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-18.3-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "18.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle authorized → scoped → rehearsed → executed with stop conditions → evidenced → triaged → remediated → independently retested → regression monitored.",
          "zh": "对生命周期“授权 → 定范围 → 预演 → 带停止条件执行 → 取证 → 分流 → 修复 → 独立复测 → 回归监测”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-18.3-DAT-07",
          "local_code": "DAT-07",
          "display_code": "D07",
          "safeguard_id": "18.3",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle discovered → validated → prioritized → assigned → fixed/mitigated/excepted → deployed → retested → closed/reopened.",
          "zh": "对生命周期“发现 → 验证 → 定级 → 分派 → 修复/缓解/例外 → 部署 → 复测 → 关闭/重开”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-18.3-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "18.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 18.2; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 18.2 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-18.3-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "18.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-18.3-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "18.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-18.3-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "18.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-18.3-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "18.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile asset and exposure inventories, architecture and threat models, rules of engagement, credentials, tester records, evidence, findings, remediation tickets, detections, and retest results and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 资产与暴露清单、架构与威胁模型、交战规则、凭据、测试人员记录、证据、发现、修复工单、检测和复测结果，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-18.3-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "18.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Require every connector carrying authorized attack hypothesis, realistic path, controlled objective, observable defense response, finding, remediation, independent retest, and regression to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 授权攻击假设、真实路径、受控目标、可观察防御响应、发现、修复、独立复测和回归 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-18.3-INT-07",
          "local_code": "INT-07",
          "display_code": "I07",
          "safeguard_id": "18.3",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Require every connector carrying affected artifact identity, exploitability, business consequence, remediation choice, deployed fix, compensating control, and residual exposure to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 受影响制品身份、可利用性、业务后果、修复选择、已部署修复、补偿控制和残余暴露 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-18.3-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "18.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Triage jointly with testers and owners, patch/redesign/configure/remove or contain, address root causes and retest the exact exploit plus normal business behavior.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“测试者/责任人共同分诊，补丁/重设/改配/移除或遏制，处理根因，并复测准确利用与正常业务；例外写剩余链、补偿和到期，追踪后续复发。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-18.3-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "18.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-18.3-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "18.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-18.3-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "18.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-18.3-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "18.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the penetration-testing scope, authorization, finding, remediation, validation, and regression authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在渗透测试范围、授权、发现、修复、验证与回归权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-18.3-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "18.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Implement the explicit state machine authorized → scoped → rehearsed → executed with stop conditions → evidenced → triaged → remediated → independently retested → regression monitored; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“授权 → 定范围 → 预演 → 带停止条件执行 → 取证 → 分流 → 修复 → 独立复测 → 回归监测”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-18.3-CTL-07",
          "local_code": "CTL-07",
          "display_code": "C07",
          "safeguard_id": "18.3",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Implement the explicit state machine discovered → validated → prioritized → assigned → fixed/mitigated/excepted → deployed → retested → closed/reopened; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“发现 → 验证 → 定级 → 分派 → 修复/缓解/例外 → 部署 → 复测 → 关闭/重开”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-18.3-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "18.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-18.3-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "18.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-18.3-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "18.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-18.3-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "18.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-18.3-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "18.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in authorized external and internal attack paths across networks, applications, APIs, cloud, identity, physical controls, people, and chained business impact; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 网络、应用、API、云、身份、物理控制、人员及业务影响链上的授权内外部攻击路径 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-18.3-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "18.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for authorized → scoped → rehearsed → executed with stop conditions → evidenced → triaged → remediated → independently retested → regression monitored; alert before each deadline becomes overdue.",
          "zh": "为“授权 → 定范围 → 预演 → 带停止条件执行 → 取证 → 分流 → 修复 → 独立复测 → 回归监测”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-18.3-TIM-07",
          "local_code": "TIM-07",
          "display_code": "T07",
          "safeguard_id": "18.3",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for discovered → validated → prioritized → assigned → fixed/mitigated/excepted → deployed → retested → closed/reopened; alert before each deadline becomes overdue.",
          "zh": "为“发现 → 验证 → 定级 → 分派 → 修复/缓解/例外 → 部署 → 复测 → 关闭/重开”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-18.3-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "18.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “The CAS reverses M2/M3 meanings and its formula can reward still-unremediated findings, so it is unusable verbatim.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“CAS 把 M2/M3 的已修/未修含义写反，公式反而会奖励未修，不能直接用。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-18.3-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "18.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-18.3-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "18.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-18.3-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "18.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-18.3-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "18.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat scope drift, unsafe techniques, shared tenants, third-party infrastructure, production impact, incomplete credentials, discovered critical paths, data handling, test detectability, and finding recurrence as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 范围漂移、不安全技术、共享租户、第三方基础设施、生产影响、凭据不完整、新发现关键路径、数据处理、测试可检测性和问题复发 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-18.3-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "18.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Treat scope drift, unsafe techniques, shared tenants, third-party systems, production impact, incomplete credentials, newly discovered critical paths, sensitive test data, and undetected activity as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 范围漂移、不安全技术、共享租户、第三方系统、生产影响、凭据不完整、新发现关键路径、敏感测试数据和未检测活动 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-18.3-EXC-07",
          "local_code": "EXC-07",
          "display_code": "X07",
          "safeguard_id": "18.3",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Treat unknown versions, false positives, unavailable fixes, vendor lag, ephemeral workloads, unscannable platforms, inherited dependencies, mitigation-only states, and recurrence as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 未知版本、误报、无可用修复、厂商滞后、短生工作负载、不可扫描平台、继承依赖、仅缓解状态和复发 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-18.3-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "18.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Have the tester or independent reviewer repeat the exploit after treatment with positive controls proving the path/test still works.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“由测试者或独立者处理后复做利用，并用正控证明测试仍有效；核验运行状态和替代路径，分别报告验证修复、缓解、接受、误报和按风险逾期。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-18.3-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "18.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-18.3-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "18.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 7 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、7 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-18.3-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "18.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-18.3-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "18.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the penetration-testing scope, authorization, finding, remediation, validation, and regression authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以渗透测试范围、授权、发现、修复、验证与回归权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-18.3-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "18.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Publish planned, executed, stopped, out-of-scope, prevented, detected, contained, missed, found, fixed, retest-passed, recurrent, and untested attack paths with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 计划、执行、停止、越界、已阻断、已检测、已遏制、漏检、发现、修复、复测通过、复发和未测试攻击路径，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-18.3-EVD-07",
          "local_code": "EVD-07",
          "display_code": "E07",
          "safeguard_id": "18.3",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Publish open, validated, false-positive, overdue, mitigated, excepted, deployed-unverified, retest-failed, reopened, and exposure-weighted findings with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 开放、已验证、误报、逾期、已缓解、例外、已部署未验证、复测失败、重开和暴露加权发现，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-18.3-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "18.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-18.3-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "18.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-18.3-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "18.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-18.3-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "18.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-18.3-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "18.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the penetration-testing scope, authorization, finding, remediation, validation, and regression authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护渗透测试范围、授权、发现、修复、验证与回归权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-18.3-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "18.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Restrict authority to change authorized → scoped → rehearsed → executed with stop conditions → evidenced → triaged → remediated → independently retested → regression monitored; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“授权 → 定范围 → 预演 → 带停止条件执行 → 取证 → 分流 → 修复 → 独立复测 → 回归监测”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-18.3-SEC-07",
          "local_code": "SEC-07",
          "display_code": "S07",
          "safeguard_id": "18.3",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Restrict authority to change discovered → validated → prioritized → assigned → fixed/mitigated/excepted → deployed → retested → closed/reopened; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“发现 → 验证 → 定级 → 分派 → 修复/缓解/例外 → 部署 → 复测 → 关闭/重开”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-18.3-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "18.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-18.3-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "18.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-18.3-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "18.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-18.3-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "18.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-18.3-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "18.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise external and internal reconnaissance, unauthenticated and authenticated paths, segmentation and privilege chains, controlled objectives, stop conditions, detection response, remediation, and independent retest through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 外部与内部侦察、未认证与已认证路径、分段与权限链、受控目标、停止条件、检测响应、修复和独立复测，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-18.3-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "18.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Run the positive control a controlled objective that exercises prevention, detection, response, and safe recovery; exercise negative, stale, duplicate, bypass, and outage controls including an unauthorized path, scope ambiguity, missed detection, unsafe impact, incomplete evidence, failed remediation, transferred discovery method, and regression.",
          "zh": "运行正向控制“一项同时检验预防、检测、响应和安全恢复的受控目标”，并执行包含“未授权路径、范围歧义、漏检、不安全影响、证据不完整、修复失败、旧发现方法迁移和回归”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-18.3-TST-07",
          "local_code": "TST-07",
          "display_code": "V07",
          "safeguard_id": "18.3",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Run the positive control a known vulnerable artifact repaired and independently retested; exercise negative, stale, duplicate, bypass, and outage controls including credential failure, wrong version match, unavailable fix, mitigation bypass, failed deployment, rollback, recurring finding, and exposed unowned asset.",
          "zh": "运行正向控制“一项已知漏洞制品完成修复并独立复测”，并执行包含“凭据失败、版本误配、无可用修复、缓解绕过、部署失败、回滚、问题复发和外露无主资产”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-18.3-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "18.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-18.3-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "18.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-18.3-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "18.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-18.3-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "18.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-18.3-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "18.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever asset and exposure inventories, architecture and threat models, rules of engagement, credentials, tester records, evidence, findings, remediation tickets, detections, and retest results change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 资产与暴露清单、架构与威胁模型、交战规则、凭据、测试人员记录、证据、发现、修复工单、检测和复测结果 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-18.3-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "18.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Use planned, executed, stopped, out-of-scope, prevented, detected, contained, missed, found, fixed, retest-passed, recurrent, and untested attack paths to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 计划、执行、停止、越界、已阻断、已检测、已遏制、漏检、发现、修复、复测通过、复发和未测试攻击路径 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        },
        {
          "code": "CIS-18.3-OPS-07",
          "local_code": "OPS-07",
          "display_code": "R07",
          "safeguard_id": "18.3",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original vulnerability pattern analysis",
          "basis_zh": "SOSEC 原创 vulnerability 模式分析",
          "en": "Use open, validated, false-positive, overdue, mitigated, excepted, deployed-unverified, retest-failed, reopened, and exposure-weighted findings to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 开放、已验证、误报、逾期、已缓解、例外、已部署未验证、复测失败、重开和暴露加权发现 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "18.4",
      "control": 18,
      "title_en": "Validate Security Measures",
      "title_zh": "验证安全措施",
      "first_ig": 3,
      "implementation_groups": [
        3
      ],
      "asset_class": "Network",
      "security_function": "Protect",
      "patterns": [
        "adversarial"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "18.1"
        ],
        "variables": [
          "GV53",
          "GV54",
          "GV55",
          "M1",
          "M2",
          "M3",
          "M4"
        ],
        "metric_branches": 1,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [],
      "implementation_contract": {
        "en": {
          "scope": "After each penetration test, evaluate whether preventive, detective and response controls observed the techniques and whether rules, telemetry, playbooks or architecture need change.",
          "build": "Map tester actions and timestamps to expected controls, reconstruct visibility and response, tune or add measures through reviewed changes and preserve adversary-emulation cases for regression.",
          "proof": "Replay representative techniques and benign controls after modifications, verify intended block/detect/respond without unacceptable false positives, then monitor in production and rollback if needed.",
          "boundary": "CAS counts measures marked modified but does not test that modifications work."
        },
        "zh": {
          "scope": "每次渗透后核对预防、检测和响应是否看见测试技术，规则、遥测、Playbook 或架构是否要改；成功与被拦动作都要看，因为拦住也可能没告警或权限过宽。",
          "build": "把测试动作/时间映射预期控制，重建可见性/响应，经评审调或新增，并把对手模拟保存作回归；缺口有责任人，区分阻断、检测、告警、分诊、遏制。",
          "proof": "修改后回放代表技术和正常对照，验证预期阻断/检测/响应且误报可接受，再生产观察并可回滚；统计已解决控制缺口和验证结果，“无需改”也要证据。",
          "boundary": "CAS 只数标为已修改的措施，不测试有效性。"
        }
      },
      "category_counts": {
        "outcome": 6,
        "scope": 6,
        "ownership": 6,
        "data": 6,
        "integration": 6,
        "control": 6,
        "timing": 6,
        "exception": 6,
        "evidence": 6,
        "security": 6,
        "testing": 6,
        "operations": 6
      },
      "requirement_count": 72,
      "requirements": [
        {
          "code": "CIS-18.4-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "18.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Validate Security Measures; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“验证安全措施”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-18.4-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "18.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 18.4, official Asset Class Network, Security Function Protect, and IG3 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 18.4、官方资产类别“网络”、安全功能“保护”和首次出现的 IG3，并保存来源抓取日期。"
        },
        {
          "code": "CIS-18.4-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "18.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “After each penetration test, evaluate whether preventive, detective and response controls observed the techniques and whether rules, telemetry, playbooks or architecture need change.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“每次渗透后核对预防、检测和响应是否看见测试技术，规则、遥测、Playbook 或架构是否要改；成功与被拦动作都要看，因为拦住也可能没告警或权限过宽。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-18.4-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "18.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-18.4-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "18.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Validate Security Measures to its operating object—authorized external and internal attack paths across networks, applications, APIs, cloud, identity, physical controls, people, and chained business impact—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“验证安全措施”连接到其运营对象——网络、应用、API、云、身份、物理控制、人员及业务影响链上的授权内外部攻击路径——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-18.4-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "18.4",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "For Validate Security Measures, express success as an observable decision over authorized attack hypothesis, realistic path, controlled objective, observable defense response, finding, remediation, independent retest, and regression; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“验证安全措施”，以 授权攻击假设、真实路径、受控目标、可观察防御响应、发现、修复、独立复测和回归 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-18.4-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "18.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-18.4-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "18.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-18.4-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "18.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-18.4-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "18.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-18.4-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "18.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across scope drift, unsafe techniques, shared tenants, third-party infrastructure, production impact, incomplete credentials, discovered critical paths, data handling, test detectability, and finding recurrence; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 范围漂移、不安全技术、共享租户、第三方基础设施、生产影响、凭据不完整、新发现关键路径、数据处理、测试可检测性和问题复发 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-18.4-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "18.4",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Include scope drift, unsafe techniques, shared tenants, third-party systems, production impact, incomplete credentials, newly discovered critical paths, sensitive test data, and undetected activity in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 范围漂移、不安全技术、共享租户、第三方系统、生产影响、凭据不完整、新发现关键路径、敏感测试数据和未检测活动 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-18.4-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "18.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-18.4-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "18.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-18.4-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "18.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-18.4-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "18.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-18.4-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "18.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind test sponsors, qualified testers, system and business owners, security operations, incident response, legal/privacy, safety, providers, and remediation teams to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 测试发起人、合格测试方、系统与业务责任人、安全运营、事件响应、法务/隐私、安全生产、提供商和修复团队 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-18.4-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "18.4",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Name who may transition authorized → scoped → rehearsed → executed with stop conditions → evidenced → triaged → remediated → independently retested → regression monitored, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 授权 → 定范围 → 预演 → 带停止条件执行 → 取证 → 分流 → 修复 → 独立复测 → 回归监测，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-18.4-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "18.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-18.4-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "18.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-18.4-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "18.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV53, GV54, GV55, M1, M2, M3, M4) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV53, GV54, GV55, M1, M2, M3, M4）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-18.4-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "18.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-18.4-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "18.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the penetration-testing scope, authorization, finding, remediation, validation, and regression authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把渗透测试范围、授权、发现、修复、验证与回归权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-18.4-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "18.4",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle authorized → scoped → rehearsed → executed with stop conditions → evidenced → triaged → remediated → independently retested → regression monitored.",
          "zh": "对生命周期“授权 → 定范围 → 预演 → 带停止条件执行 → 取证 → 分流 → 修复 → 独立复测 → 回归监测”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-18.4-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "18.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 18.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 18.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-18.4-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "18.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-18.4-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "18.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-18.4-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "18.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-18.4-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "18.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile asset and exposure inventories, architecture and threat models, rules of engagement, credentials, tester records, evidence, findings, remediation tickets, detections, and retest results and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 资产与暴露清单、架构与威胁模型、交战规则、凭据、测试人员记录、证据、发现、修复工单、检测和复测结果，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-18.4-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "18.4",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Require every connector carrying authorized attack hypothesis, realistic path, controlled objective, observable defense response, finding, remediation, independent retest, and regression to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 授权攻击假设、真实路径、受控目标、可观察防御响应、发现、修复、独立复测和回归 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-18.4-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "18.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Map tester actions and timestamps to expected controls, reconstruct visibility and response, tune or add measures through reviewed changes and preserve adversary-emulation cases for regression.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“把测试动作/时间映射预期控制，重建可见性/响应，经评审调或新增，并把对手模拟保存作回归；缺口有责任人，区分阻断、检测、告警、分诊、遏制。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-18.4-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "18.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-18.4-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "18.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-18.4-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "18.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-18.4-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "18.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the penetration-testing scope, authorization, finding, remediation, validation, and regression authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在渗透测试范围、授权、发现、修复、验证与回归权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-18.4-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "18.4",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Implement the explicit state machine authorized → scoped → rehearsed → executed with stop conditions → evidenced → triaged → remediated → independently retested → regression monitored; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“授权 → 定范围 → 预演 → 带停止条件执行 → 取证 → 分流 → 修复 → 独立复测 → 回归监测”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-18.4-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "18.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (event- and risk-defined local cadence); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（event- and risk-defined local cadence）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-18.4-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "18.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-18.4-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "18.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-18.4-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "18.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-18.4-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "18.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in authorized external and internal attack paths across networks, applications, APIs, cloud, identity, physical controls, people, and chained business impact; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 网络、应用、API、云、身份、物理控制、人员及业务影响链上的授权内外部攻击路径 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-18.4-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "18.4",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for authorized → scoped → rehearsed → executed with stop conditions → evidenced → triaged → remediated → independently retested → regression monitored; alert before each deadline becomes overdue.",
          "zh": "为“授权 → 定范围 → 预演 → 带停止条件执行 → 取证 → 分流 → 修复 → 独立复测 → 回归监测”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-18.4-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "18.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “CAS counts measures marked modified but does not test that modifications work.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“CAS 只数标为已修改的措施，不测试有效性。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-18.4-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "18.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-18.4-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "18.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-18.4-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "18.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-18.4-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "18.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat scope drift, unsafe techniques, shared tenants, third-party infrastructure, production impact, incomplete credentials, discovered critical paths, data handling, test detectability, and finding recurrence as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 范围漂移、不安全技术、共享租户、第三方基础设施、生产影响、凭据不完整、新发现关键路径、数据处理、测试可检测性和问题复发 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-18.4-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "18.4",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Treat scope drift, unsafe techniques, shared tenants, third-party systems, production impact, incomplete credentials, newly discovered critical paths, sensitive test data, and undetected activity as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 范围漂移、不安全技术、共享租户、第三方系统、生产影响、凭据不完整、新发现关键路径、敏感测试数据和未检测活动 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-18.4-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "18.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Replay representative techniques and benign controls after modifications, verify intended block/detect/respond without unacceptable false positives, then monitor in production and rollback if needed.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“修改后回放代表技术和正常对照，验证预期阻断/检测/响应且误报可接受，再生产观察并可回滚；统计已解决控制缺口和验证结果，“无需改”也要证据。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-18.4-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "18.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-18.4-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "18.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 1 pinned CAS metric branch(es), 7 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 1 个指标分支、7 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-18.4-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "18.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-18.4-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "18.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the penetration-testing scope, authorization, finding, remediation, validation, and regression authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以渗透测试范围、授权、发现、修复、验证与回归权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-18.4-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "18.4",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Publish planned, executed, stopped, out-of-scope, prevented, detected, contained, missed, found, fixed, retest-passed, recurrent, and untested attack paths with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 计划、执行、停止、越界、已阻断、已检测、已遏制、漏检、发现、修复、复测通过、复发和未测试攻击路径，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-18.4-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "18.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-18.4-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "18.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-18.4-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "18.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-18.4-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "18.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-18.4-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "18.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the penetration-testing scope, authorization, finding, remediation, validation, and regression authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护渗透测试范围、授权、发现、修复、验证与回归权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-18.4-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "18.4",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Restrict authority to change authorized → scoped → rehearsed → executed with stop conditions → evidenced → triaged → remediated → independently retested → regression monitored; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“授权 → 定范围 → 预演 → 带停止条件执行 → 取证 → 分流 → 修复 → 独立复测 → 回归监测”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-18.4-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "18.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-18.4-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "18.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-18.4-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "18.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-18.4-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "18.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-18.4-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "18.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise external and internal reconnaissance, unauthenticated and authenticated paths, segmentation and privilege chains, controlled objectives, stop conditions, detection response, remediation, and independent retest through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 外部与内部侦察、未认证与已认证路径、分段与权限链、受控目标、停止条件、检测响应、修复和独立复测，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-18.4-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "18.4",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Run the positive control a controlled objective that exercises prevention, detection, response, and safe recovery; exercise negative, stale, duplicate, bypass, and outage controls including an unauthorized path, scope ambiguity, missed detection, unsafe impact, incomplete evidence, failed remediation, transferred discovery method, and regression.",
          "zh": "运行正向控制“一项同时检验预防、检测、响应和安全恢复的受控目标”，并执行包含“未授权路径、范围歧义、漏检、不安全影响、证据不完整、修复失败、旧发现方法迁移和回归”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-18.4-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "18.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-18.4-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "18.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-18.4-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "18.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-18.4-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "18.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-18.4-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "18.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever asset and exposure inventories, architecture and threat models, rules of engagement, credentials, tester records, evidence, findings, remediation tickets, detections, and retest results change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 资产与暴露清单、架构与威胁模型、交战规则、凭据、测试人员记录、证据、发现、修复工单、检测和复测结果 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-18.4-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "18.4",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Use planned, executed, stopped, out-of-scope, prevented, detected, contained, missed, found, fixed, retest-passed, recurrent, and untested attack paths to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 计划、执行、停止、越界、已阻断、已检测、已遏制、漏检、发现、修复、复测通过、复发和未测试攻击路径 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    },
    {
      "id": "18.5",
      "control": 18,
      "title_en": "Perform Periodic Internal Penetration Tests",
      "title_zh": "周期性内部渗透测试",
      "first_ig": 3,
      "implementation_groups": [
        3
      ],
      "asset_class": "Network",
      "security_function": "Detect",
      "patterns": [
        "adversarial"
      ],
      "expanded_complexity": false,
      "cas_context": {
        "dependencies": [
          "18.1"
        ],
        "variables": [
          "GV55",
          "M1"
        ],
        "metric_branches": 0,
        "has_assumptions": false,
        "has_procedural_review": false
      },
      "official_cadence_terms": [
        "annually",
        "no less than annually"
      ],
      "implementation_contract": {
        "en": {
          "scope": "At least annually, test from realistic internal starting points across workstation, server, identity, cloud, wireless, management and sensitive zones, including assumed breach, ordinary user and relevant privileged/contractor contexts.",
          "build": "Use qualified independent testers, safe accounts/data and rules, coordinate critical/OT systems, vary knowledge level and starting points, and prevent broad defender whitelisting where the objective includes detection.",
          "proof": "Validate paths safely through credential/privilege, lateral, trust, cloud and data boundaries; record what prevention/detection/response observed and retest findings.",
          "boundary": "CAS again checks only test age."
        },
        "zh": {
          "scope": "至少年度从现实内部起点测试工作站、服务器、身份、云、无线、管理和敏感区，包括假设入侵、普通用户及相关特权/承包商情境；重点是横向和数据/对象授权，不只是内网端口扫。",
          "build": "使用合格独立测试者、安全账户/数据和规则，协调关键/OT，变化知识和起点；目标含检测时避免广泛白名单，重大分段/身份变化后触发目标测试。",
          "proof": "安全验证凭据/权限、横向、信任、云与数据边界，记录预防/检测/响应并复测；带允许业务正控，测试备用路由/IPv6，列未测高风险和服务商限制。",
          "boundary": "CAS 仍只看日期。"
        }
      },
      "category_counts": {
        "outcome": 6,
        "scope": 6,
        "ownership": 6,
        "data": 6,
        "integration": 6,
        "control": 6,
        "timing": 6,
        "exception": 6,
        "evidence": 6,
        "security": 6,
        "testing": 6,
        "operations": 6
      },
      "requirement_count": 72,
      "requirements": [
        {
          "code": "CIS-18.5-OUT-01",
          "local_code": "OUT-01",
          "display_code": "O01",
          "safeguard_id": "18.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Define the user, business, and risk outcome for Perform Periodic Internal Penetration Tests; name the protected decision and the observable state change produced by this Safeguard.",
          "zh": "为“周期性内部渗透测试”定义用户、业务与风险结果，明确该 Safeguard 保护的决策以及可以被观察到的状态变化。"
        },
        {
          "code": "CIS-18.5-OUT-02",
          "local_code": "OUT-02",
          "display_code": "O02",
          "safeguard_id": "18.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "CIS identity plus SOSEC acceptance model",
          "basis_zh": "CIS 身份信息与 SOSEC 验收模型",
          "en": "Bind every backlog item to CIS Safeguard 18.5, official Asset Class Network, Security Function Detect, and IG3 first appearance; retain the source retrieval date.",
          "zh": "每条需求都绑定 CIS Safeguard 18.5、官方资产类别“网络”、安全功能“检测”和首次出现的 IG3，并保存来源抓取日期。"
        },
        {
          "code": "CIS-18.5-OUT-03",
          "local_code": "OUT-03",
          "display_code": "O03",
          "safeguard_id": "18.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this original local scope claim as the starting contract: “At least annually, test from realistic internal starting points across workstation, server, identity, cloud, wireless, management and sensitive zones, including assumed breach, ordinary user and relevant privileged/contractor contexts.” Convert each object in the claim into a queryable population or an approved applicability decision.",
          "zh": "以这条原创本地范围判断为起点：“至少年度从现实内部起点测试工作站、服务器、身份、云、无线、管理和敏感区，包括假设入侵、普通用户及相关特权/承包商情境；重点是横向和数据/对象授权，不只是内网端口扫。”把其中每类对象转成可查询总体或经过批准的适用性决定。"
        },
        {
          "code": "CIS-18.5-OUT-04",
          "local_code": "OUT-04",
          "display_code": "O04",
          "safeguard_id": "18.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Maintain separate statuses for normative intent, design approval, deployment, fresh evidence, positive control, negative control, exception, and observed operating outcome.",
          "zh": "分别保存规范意图、设计批准、部署、证据新鲜、正向控制、反向控制、例外和实际运行结果状态。"
        },
        {
          "code": "CIS-18.5-OUT-05",
          "local_code": "OUT-05",
          "display_code": "O05",
          "safeguard_id": "18.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Connect Perform Periodic Internal Penetration Tests to its operating object—authorized external and internal attack paths across networks, applications, APIs, cloud, identity, physical controls, people, and chained business impact—and define the security decision, business consequence, and residual risk for every terminal state.",
          "zh": "把“周期性内部渗透测试”连接到其运营对象——网络、应用、API、云、身份、物理控制、人员及业务影响链上的授权内外部攻击路径——并为每个终态定义安全决策、业务后果和残余风险。"
        },
        {
          "code": "CIS-18.5-OUT-06",
          "local_code": "OUT-06",
          "display_code": "O06",
          "safeguard_id": "18.5",
          "category": "outcome",
          "category_en": "Outcome and decision",
          "category_zh": "目标与决策",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "For Perform Periodic Internal Penetration Tests, express success as an observable decision over authorized attack hypothesis, realistic path, controlled objective, observable defense response, finding, remediation, independent retest, and regression; name the business effect of each accepted, rejected, and unresolved state.",
          "zh": "对“周期性内部渗透测试”，以 授权攻击假设、真实路径、受控目标、可观察防御响应、发现、修复、独立复测和回归 上可观察决策表达成功，并说明接受、拒绝和未解决状态的业务影响。"
        },
        {
          "code": "CIS-18.5-SCP-01",
          "local_code": "SCP-01",
          "display_code": "P01",
          "safeguard_id": "18.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Build an authoritative denominator before calculating coverage; record the query, owner, collection time, tenant, environment, inclusions, exclusions, and unresolved objects.",
          "zh": "计算覆盖率前先建立权威分母，记录查询、责任人、采集时间、租户、环境、纳入项、排除项和未解决对象。"
        },
        {
          "code": "CIS-18.5-SCP-02",
          "local_code": "SCP-02",
          "display_code": "P02",
          "safeguard_id": "18.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original cross-environment analysis",
          "basis_zh": "SOSEC 原创跨环境分析",
          "en": "Evaluate on-premises, cloud IaaS/PaaS/SaaS, mobile, remote, IoT/OT, build, backup, provider, and AI surfaces whenever the Safeguard's named object exists.",
          "zh": "只要 Safeguard 所指对象存在，就评估本地、IaaS/PaaS/SaaS 云、移动、远程、IoT/OT、构建、备份、提供商和 AI 场景。"
        },
        {
          "code": "CIS-18.5-SCP-03",
          "local_code": "SCP-03",
          "display_code": "P03",
          "safeguard_id": "18.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Represent an empty population, discovery failure, unsupported platform, inaccessible provider evidence, and approved out-of-scope decision as five distinct results.",
          "zh": "把空总体、发现失败、平台不支持、提供商证据不可得和经批准不适用分别记录为五种结果。"
        },
        {
          "code": "CIS-18.5-SCP-04",
          "local_code": "SCP-04",
          "display_code": "P04",
          "safeguard_id": "18.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original verification guidance",
          "basis_zh": "SOSEC 原创验证指引",
          "en": "Sample in both directions—from the authority to the live estate and from the live estate to the authority—and retain missing, duplicate, stale, orphaned, and cross-tenant results.",
          "zh": "执行双向抽样：权威台账到真实环境、真实环境到权威台账；保留缺失、重复、陈旧、孤儿和跨租户结果。"
        },
        {
          "code": "CIS-18.5-SCP-05",
          "local_code": "SCP-05",
          "display_code": "P05",
          "safeguard_id": "18.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Resolve applicability across scope drift, unsafe techniques, shared tenants, third-party infrastructure, production impact, incomplete credentials, discovered critical paths, data handling, test detectability, and finding recurrence; each edge receives an evidenced in-scope, out-of-scope, unknown, or time-bounded exception result.",
          "zh": "解决 范围漂移、不安全技术、共享租户、第三方基础设施、生产影响、凭据不完整、新发现关键路径、数据处理、测试可检测性和问题复发 的适用性；每种边缘情形都获得有证据的适用、不适用、未知或有期限例外结果。"
        },
        {
          "code": "CIS-18.5-SCP-06",
          "local_code": "SCP-06",
          "display_code": "P06",
          "safeguard_id": "18.5",
          "category": "scope",
          "category_en": "Population and applicability",
          "category_zh": "总体与适用性",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Include scope drift, unsafe techniques, shared tenants, third-party systems, production impact, incomplete credentials, newly discovered critical paths, sensitive test data, and undetected activity in applicability and assign every object an in-scope, out-of-scope, unknown, failed, or exception state.",
          "zh": "把 范围漂移、不安全技术、共享租户、第三方系统、生产影响、凭据不完整、新发现关键路径、敏感测试数据和未检测活动 纳入适用性，为每个对象分配适用、不适用、未知、失败或例外状态。"
        },
        {
          "code": "CIS-18.5-OWN-01",
          "local_code": "OWN-01",
          "display_code": "W01",
          "safeguard_id": "18.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original PRD guidance",
          "basis_zh": "SOSEC 原创 PRD 指引",
          "en": "Name the accountable business owner, operating owner, evidence owner, exception approver, independent reviewer, and escalation recipient for this Safeguard.",
          "zh": "为该 Safeguard 指定业务最终责任人、运营责任人、证据责任人、例外审批人、独立复核人和升级接收人。"
        },
        {
          "code": "CIS-18.5-OWN-02",
          "local_code": "OWN-02",
          "display_code": "W02",
          "safeguard_id": "18.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original governance guidance",
          "basis_zh": "SOSEC 原创治理指引",
          "en": "Define who may create, change, approve, enforce, pause, roll back, renew an exception, and close the implementation; prevent one actor from self-approving every stage.",
          "zh": "定义谁能创建、变更、批准、执行、暂停、回滚、续期例外和关闭实施，阻止同一主体独自批准所有阶段。"
        },
        {
          "code": "CIS-18.5-OWN-03",
          "local_code": "OWN-03",
          "display_code": "W03",
          "safeguard_id": "18.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original shared-responsibility analysis",
          "basis_zh": "SOSEC 原创共享责任分析",
          "en": "For outsourced operation, assign an internal accountable owner and identify the provider operator, tenant administrator, evidence supplier, notification route, and contractual gap.",
          "zh": "外包运营仍指定内部最终责任人，并列出提供商操作方、租户管理员、证据提供方、通知路径和合同缺口。"
        },
        {
          "code": "CIS-18.5-OWN-04",
          "local_code": "OWN-04",
          "display_code": "W04",
          "safeguard_id": "18.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Specify delegation, backup personnel, on-call coverage, decision authority during an incident, and the handover test used when an owner leaves or becomes unavailable.",
          "zh": "定义委派、备份人员、值班覆盖、事件期间决策权限，以及责任人离职或不可用时的交接测试。"
        },
        {
          "code": "CIS-18.5-OWN-05",
          "local_code": "OWN-05",
          "display_code": "W05",
          "safeguard_id": "18.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Bind test sponsors, qualified testers, system and business owners, security operations, incident response, legal/privacy, safety, providers, and remediation teams to a RACI for the Safeguard and name the authority that resolves conflicting source or risk decisions.",
          "zh": "为 测试发起人、合格测试方、系统与业务责任人、安全运营、事件响应、法务/隐私、安全生产、提供商和修复团队 定义该 Safeguard 的 RACI，并指定解决来源或风险决策冲突的权威方。"
        },
        {
          "code": "CIS-18.5-OWN-06",
          "local_code": "OWN-06",
          "display_code": "W06",
          "safeguard_id": "18.5",
          "category": "ownership",
          "category_en": "Ownership and approval",
          "category_zh": "责任与审批",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Name who may transition authorized → scoped → rehearsed → executed with stop conditions → evidenced → triaged → remediated → independently retested → regression monitored, who approves the transition, who supplies evidence, and who independently reviews it.",
          "zh": "明确谁能转换 授权 → 定范围 → 预演 → 带停止条件执行 → 取证 → 分流 → 修复 → 独立复测 → 回归监测，谁批准、谁提供证据、谁独立复核。"
        },
        {
          "code": "CIS-18.5-DAT-01",
          "local_code": "DAT-01",
          "display_code": "D01",
          "safeguard_id": "18.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original data-contract guidance",
          "basis_zh": "SOSEC 原创数据契约指引",
          "en": "Define a stable object identity, aliases, parent/child relationships, tenant and environment keys, source provenance, first/last-seen time, owner, state, and tombstone behavior.",
          "zh": "定义稳定对象身份、别名、父子关系、租户与环境键、来源、首次/最后观测时间、责任人、状态和墓碑规则。"
        },
        {
          "code": "CIS-18.5-DAT-02",
          "local_code": "DAT-02",
          "display_code": "D02",
          "safeguard_id": "18.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original evidence guidance",
          "basis_zh": "SOSEC 原创证据指引",
          "en": "Version the schema and normalization rules; preserve the raw-source identifier, collection time, parser version, confidence, and prior value for every material decision field.",
          "zh": "对模式与归一化规则做版本管理；每个关键决策字段保留原始来源标识、采集时间、解析器版本、置信度和旧值。"
        },
        {
          "code": "CIS-18.5-DAT-03",
          "local_code": "DAT-03",
          "display_code": "D03",
          "safeguard_id": "18.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "CAS-derived mapping plus SOSEC analysis",
          "basis_zh": "CAS 映射与 SOSEC 分析",
          "en": "Map the pinned CAS variable set (GV55, M1) to local fields or mark each unavailable variable as unsupported, inapplicable, or unknown with a reason.",
          "zh": "把固定 CAS 变量集合（GV55, M1）映射到本地字段；不可获得的变量逐项标记为不支持、不适用或未知并说明原因。"
        },
        {
          "code": "CIS-18.5-DAT-04",
          "local_code": "DAT-04",
          "display_code": "D04",
          "safeguard_id": "18.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Define null, zero, duplicate, stale, deleted, unreachable, partially observed, and conflicting-source semantics before dashboards or automation consume the data.",
          "zh": "在仪表盘或自动化消费前，定义空值、零、重复、陈旧、删除、不可达、部分观测和来源冲突语义。"
        },
        {
          "code": "CIS-18.5-DAT-05",
          "local_code": "DAT-05",
          "display_code": "D05",
          "safeguard_id": "18.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Use the penetration-testing scope, authorization, finding, remediation, validation, and regression authority as the governed current-state record; persist identity, owner, provenance, prior/new state, reason, actor, time, and exception link.",
          "zh": "把渗透测试范围、授权、发现、修复、验证与回归权威记录作为受治理当前状态记录，保存身份、责任人、来源、旧/新状态、原因、执行人、时间和例外关联。"
        },
        {
          "code": "CIS-18.5-DAT-06",
          "local_code": "DAT-06",
          "display_code": "D06",
          "safeguard_id": "18.5",
          "category": "data",
          "category_en": "Data contract and identity",
          "category_zh": "数据契约与身份",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Persist stable identity, source provenance, timestamp, actor, reason, and prior/new state for the lifecycle authorized → scoped → rehearsed → executed with stop conditions → evidenced → triaged → remediated → independently retested → regression monitored.",
          "zh": "对生命周期“授权 → 定范围 → 预演 → 带停止条件执行 → 取证 → 分流 → 修复 → 独立复测 → 回归监测”保存稳定身份、来源、时间、执行人、原因和旧/新状态。"
        },
        {
          "code": "CIS-18.5-INT-01",
          "local_code": "INT-01",
          "display_code": "I01",
          "safeguard_id": "18.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "CAS dependency mapping plus SOSEC engineering analysis",
          "basis_zh": "CAS 依赖映射与 SOSEC 工程分析",
          "en": "Record prerequisite state for Safeguard 18.1; add locally required dependencies and justify every omitted or substituted predecessor.",
          "zh": "记录 Safeguard 18.1 的前置状态；补充本地必需依赖，并解释每项省略或替代的前置条件。"
        },
        {
          "code": "CIS-18.5-INT-02",
          "local_code": "INT-02",
          "display_code": "I02",
          "safeguard_id": "18.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original integration guidance",
          "basis_zh": "SOSEC 原创集成指引",
          "en": "For every API, agent, file, message, manual attestation, or provider export, specify authentication, authorization, schema, pagination, rate limits, replay, idempotency, and error handling.",
          "zh": "每个 API、代理、文件、消息、人工确认或提供商导出都定义认证、授权、模式、分页、限流、重放、幂等和错误处理。"
        },
        {
          "code": "CIS-18.5-INT-03",
          "local_code": "INT-03",
          "display_code": "I03",
          "safeguard_id": "18.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original data-lineage guidance",
          "basis_zh": "SOSEC 原创数据血缘指引",
          "en": "Preserve tenant, region, environment, object identity, source event time, collection time, and source-health state across every connector and normalization hop.",
          "zh": "在每次连接和归一化中保留租户、地域、环境、对象身份、来源事件时间、采集时间和来源健康状态。"
        },
        {
          "code": "CIS-18.5-INT-04",
          "local_code": "INT-04",
          "display_code": "I04",
          "safeguard_id": "18.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original failure-boundary guidance",
          "basis_zh": "SOSEC 原创失效边界指引",
          "en": "Define a fallback and reconciliation path for provider outage, credential expiry, network partition, schema drift, delayed delivery, partial results, and manual operation.",
          "zh": "为提供商中断、凭据过期、网络分区、模式漂移、延迟交付、部分结果和人工运行定义回退与对账路径。"
        },
        {
          "code": "CIS-18.5-INT-05",
          "local_code": "INT-05",
          "display_code": "I05",
          "safeguard_id": "18.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Reconcile asset and exposure inventories, architecture and threat models, rules of engagement, credentials, tester records, evidence, findings, remediation tickets, detections, and retest results and expose source-specific health, latency, confidence, omissions, and conflict resolution.",
          "zh": "对账 资产与暴露清单、架构与威胁模型、交战规则、凭据、测试人员记录、证据、发现、修复工单、检测和复测结果，逐来源暴露健康、延迟、置信度、遗漏和冲突解决结果。"
        },
        {
          "code": "CIS-18.5-INT-06",
          "local_code": "INT-06",
          "display_code": "I06",
          "safeguard_id": "18.5",
          "category": "integration",
          "category_en": "Dependencies and integrations",
          "category_zh": "依赖与集成",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Require every connector carrying authorized attack hypothesis, realistic path, controlled objective, observable defense response, finding, remediation, independent retest, and regression to preserve tenant, object identity, source time, collection time, completeness, and failure status.",
          "zh": "承载 授权攻击假设、真实路径、受控目标、可观察防御响应、发现、修复、独立复测和回归 的每个连接器都保留租户、对象身份、来源时间、采集时间、完整性和失败状态。"
        },
        {
          "code": "CIS-18.5-CTL-01",
          "local_code": "CTL-01",
          "display_code": "C01",
          "safeguard_id": "18.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original implementation analysis",
          "basis_zh": "SOSEC 原创实施分析",
          "en": "Use this implementation claim as the control-flow anchor: “Use qualified independent testers, safe accounts/data and rules, coordinate critical/OT systems, vary knowledge level and starting points, and prevent broad defender whitelisting where the objective includes detection.” Decompose it into input, validation, decision, action, recorded outcome, and closure states.",
          "zh": "以这条实施判断为控制流锚点：“使用合格独立测试者、安全账户/数据和规则，协调关键/OT，变化知识和起点；目标含检测时避免广泛白名单，重大分段/身份变化后触发目标测试。”拆成输入、校验、决策、动作、记录结果和关闭状态。"
        },
        {
          "code": "CIS-18.5-CTL-02",
          "local_code": "CTL-02",
          "display_code": "C02",
          "safeguard_id": "18.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original control-point analysis",
          "basis_zh": "SOSEC 原创控制点分析",
          "en": "Name the closest reliable policy, procedure, configuration, identity, network, application, data, provider, or human decision point that changes the protected state.",
          "zh": "明确最近且可靠的策略、流程、配置、身份、网络、应用、数据、提供商或人工决策点，由它真正改变受保护状态。"
        },
        {
          "code": "CIS-18.5-CTL-03",
          "local_code": "CTL-03",
          "display_code": "C03",
          "safeguard_id": "18.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original state-machine guidance",
          "basis_zh": "SOSEC 原创状态机指引",
          "en": "Define allowed, denied, contained, quarantined, deferred, exception, unknown, failed, rolled-back, and closed outcomes where they apply; each outcome needs an owner and next action.",
          "zh": "按需定义允许、拒绝、遏制、隔离、延后、例外、未知、失败、已回滚和已关闭结果；每种结果都有责任人与下一动作。"
        },
        {
          "code": "CIS-18.5-CTL-04",
          "local_code": "CTL-04",
          "display_code": "C04",
          "safeguard_id": "18.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original engineering guidance",
          "basis_zh": "SOSEC 原创工程指引",
          "en": "Specify validation, authorization, idempotency, retry, deduplication, concurrency, transaction boundary, rollback, and compensating action for automated and manual execution.",
          "zh": "为自动与人工执行定义校验、授权、幂等、重试、去重、并发、事务边界、回滚和补偿动作。"
        },
        {
          "code": "CIS-18.5-CTL-05",
          "local_code": "CTL-05",
          "display_code": "C05",
          "safeguard_id": "18.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Implement the state transition in the penetration-testing scope, authorization, finding, remediation, validation, and regression authority and preserve the exact operating control point, policy or procedure version, result, and downstream update.",
          "zh": "在渗透测试范围、授权、发现、修复、验证与回归权威记录中实现状态转换，保存精确运营控制点、策略或程序版本、结果和下游更新。"
        },
        {
          "code": "CIS-18.5-CTL-06",
          "local_code": "CTL-06",
          "display_code": "C06",
          "safeguard_id": "18.5",
          "category": "control",
          "category_en": "Control flow and enforcement",
          "category_zh": "控制流与执行",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Implement the explicit state machine authorized → scoped → rehearsed → executed with stop conditions → evidenced → triaged → remediated → independently retested → regression monitored; define validation, idempotency, retry, concurrency, rollback, and closure for each transition.",
          "zh": "实现显式状态机“授权 → 定范围 → 预演 → 带停止条件执行 → 取证 → 分流 → 修复 → 独立复测 → 回归监测”，逐转换定义校验、幂等、重试、并发、回滚和关闭。"
        },
        {
          "code": "CIS-18.5-TIM-01",
          "local_code": "TIM-01",
          "display_code": "T01",
          "safeguard_id": "18.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "CIS cadence reference plus SOSEC risk analysis",
          "basis_zh": "CIS 频率参照与 SOSEC 风险分析",
          "en": "Preserve the official cadence terms found in the pinned description (annually, no less than annually); define faster local SLOs where asset change, exposure, safety, or threat consequence requires them.",
          "zh": "保留固定官方描述中的频率术语（annually, no less than annually）；当资产变化、暴露、安全生产或威胁后果要求更快时定义本地 SLO。"
        },
        {
          "code": "CIS-18.5-TIM-02",
          "local_code": "TIM-02",
          "display_code": "T02",
          "safeguard_id": "18.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original operating guidance",
          "basis_zh": "SOSEC 原创运营指引",
          "en": "Set separate SLOs for discovery, ingestion, decision, action, owner acknowledgement, evidence freshness, exception review, verification, and final closure.",
          "zh": "分别设置发现、摄取、决策、动作、责任人确认、证据新鲜度、例外复核、验证和最终关闭 SLO。"
        },
        {
          "code": "CIS-18.5-TIM-03",
          "local_code": "TIM-03",
          "display_code": "T03",
          "safeguard_id": "18.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original timing guidance",
          "basis_zh": "SOSEC 原创时序指引",
          "en": "Store event time, source time zone, collection time, processing time, decision time, and expiry; define handling for clock skew, late arrivals, backfill, and daylight-saving changes.",
          "zh": "保存事件时间、来源时区、采集时间、处理时间、决策时间和到期时间，定义时钟偏移、迟到、回填和夏令时处理。"
        },
        {
          "code": "CIS-18.5-TIM-04",
          "local_code": "TIM-04",
          "display_code": "T04",
          "safeguard_id": "18.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original change-control guidance",
          "basis_zh": "SOSEC 原创变更控制指引",
          "en": "Trigger early review after material architecture, provider, policy, software, threat, regulation, ownership, data-use, incident, or control-source change.",
          "zh": "架构、提供商、策略、软件、威胁、法规、责任、数据用途、事件或控制来源发生重大变化时提前复核。"
        },
        {
          "code": "CIS-18.5-TIM-05",
          "local_code": "TIM-05",
          "display_code": "T05",
          "safeguard_id": "18.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Set freshness and action SLOs from the rate of change in authorized external and internal attack paths across networks, applications, APIs, cloud, identity, physical controls, people, and chained business impact; source age, queue age, exception age, and closure age remain separate clocks.",
          "zh": "根据 网络、应用、API、云、身份、物理控制、人员及业务影响链上的授权内外部攻击路径 的变化速度设置新鲜度和动作 SLO，把来源年龄、队列年龄、例外年龄和关闭年龄分开。"
        },
        {
          "code": "CIS-18.5-TIM-06",
          "local_code": "TIM-06",
          "display_code": "T06",
          "safeguard_id": "18.5",
          "category": "timing",
          "category_en": "Timing and lifecycle",
          "category_zh": "时序与生命周期",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Set detection, decision, action, freshness, review, and expiry SLOs for authorized → scoped → rehearsed → executed with stop conditions → evidenced → triaged → remediated → independently retested → regression monitored; alert before each deadline becomes overdue.",
          "zh": "为“授权 → 定范围 → 预演 → 带停止条件执行 → 取证 → 分流 → 修复 → 独立复测 → 回归监测”设置发现、决策、动作、新鲜度、复核与到期 SLO，在逾期前告警。"
        },
        {
          "code": "CIS-18.5-EXC-01",
          "local_code": "EXC-01",
          "display_code": "X01",
          "safeguard_id": "18.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original boundary analysis",
          "basis_zh": "SOSEC 原创边界分析",
          "en": "Use this failure-boundary claim as a required exception test: “CAS again checks only test age.” Convert every condition into a detectable state and response.",
          "zh": "把这条失效边界判断作为强制例外测试：“CAS 仍只看日期。”其中每种条件都转成可检测状态和响应。"
        },
        {
          "code": "CIS-18.5-EXC-02",
          "local_code": "EXC-02",
          "display_code": "X02",
          "safeguard_id": "18.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original exception guidance",
          "basis_zh": "SOSEC 原创例外指引",
          "en": "Require exception scope, exact affected objects, owner, reason, threat and business consequence, compensating control, evidence, start, expiry, review trigger, and tested exit.",
          "zh": "例外必须包含范围、精确对象、责任人、原因、威胁与业务后果、补偿控制、证据、起止时间、复核触发器和经过测试的退出。"
        },
        {
          "code": "CIS-18.5-EXC-03",
          "local_code": "EXC-03",
          "display_code": "X03",
          "safeguard_id": "18.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original failure-mode guidance",
          "basis_zh": "SOSEC 原创失效模式指引",
          "en": "Define fail-open, fail-closed, fail-safe, partial, unknown, stale, provider-unsupported, safety-constrained, privacy-constrained, and emergency states where relevant.",
          "zh": "按需定义故障开放、故障关闭、安全失效、部分、未知、陈旧、提供商不支持、安全生产约束、隐私约束和紧急状态。"
        },
        {
          "code": "CIS-18.5-EXC-04",
          "local_code": "EXC-04",
          "display_code": "X04",
          "safeguard_id": "18.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original lifecycle guidance",
          "basis_zh": "SOSEC 原创生命周期指引",
          "en": "Return expired or weakened exceptions to failure; reopen the root cause when the same object or acquisition path recurs after closure.",
          "zh": "到期或补偿控制减弱的例外回到失败；同一对象或获取路径在关闭后复发时重开根因。"
        },
        {
          "code": "CIS-18.5-EXC-05",
          "local_code": "EXC-05",
          "display_code": "X05",
          "safeguard_id": "18.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Treat scope drift, unsafe techniques, shared tenants, third-party infrastructure, production impact, incomplete credentials, discovered critical paths, data handling, test detectability, and finding recurrence as designed non-happy paths with an owner, compensating control, expiry, safety or business constraint, and retest.",
          "zh": "把 范围漂移、不安全技术、共享租户、第三方基础设施、生产影响、凭据不完整、新发现关键路径、数据处理、测试可检测性和问题复发 作为设计内异常路径，每项都有责任人、补偿控制、期限、安全或业务约束和复测。"
        },
        {
          "code": "CIS-18.5-EXC-06",
          "local_code": "EXC-06",
          "display_code": "X06",
          "safeguard_id": "18.5",
          "category": "exception",
          "category_en": "Exceptions and failure modes",
          "category_zh": "例外与失效模式",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Treat scope drift, unsafe techniques, shared tenants, third-party systems, production impact, incomplete credentials, newly discovered critical paths, sensitive test data, and undetected activity as named failure or exception paths with an owner, compensating control, expiry, and retest.",
          "zh": "把 范围漂移、不安全技术、共享租户、第三方系统、生产影响、凭据不完整、新发现关键路径、敏感测试数据和未检测活动 作为命名失败或例外路径，设置责任人、补偿控制、到期和复测。"
        },
        {
          "code": "CIS-18.5-EVD-01",
          "local_code": "EVD-01",
          "display_code": "E01",
          "safeguard_id": "18.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original verification analysis",
          "basis_zh": "SOSEC 原创验证分析",
          "en": "Use this verification claim as the first acceptance receipt: “Validate paths safely through credential/privilege, lateral, trust, cloud and data boundaries; record what prevention/detection/response observed and retest findings.” Retain the inputs, procedure, expected result, observed result, actor, time, and artifact identity.",
          "zh": "以这条验证判断作为首份验收回执：“安全验证凭据/权限、横向、信任、云与数据边界，记录预防/检测/响应并复测；带允许业务正控，测试备用路由/IPv6，列未测高风险和服务商限制。”保留输入、步骤、预期结果、实际结果、执行人、时间和制品身份。"
        },
        {
          "code": "CIS-18.5-EVD-02",
          "local_code": "EVD-02",
          "display_code": "E02",
          "safeguard_id": "18.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original measurement guidance",
          "basis_zh": "SOSEC 原创度量指引",
          "en": "Publish numerator and denominator as drill-down object sets with query version, collection time, exclusions, unknowns, duplicates, stale records, and a declared empty-population rule.",
          "zh": "把分子和分母发布为可下钻对象集，包含查询版本、采集时间、排除项、未知项、重复项、陈旧记录和空总体规则。"
        },
        {
          "code": "CIS-18.5-EVD-03",
          "local_code": "EVD-03",
          "display_code": "E03",
          "safeguard_id": "18.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "CAS structure audit plus SOSEC analysis",
          "basis_zh": "CAS 结构审计与 SOSEC 分析",
          "en": "Reconcile 0 pinned CAS metric branch(es), 2 named measure or global variable(s), assumption state, and local operating-effectiveness evidence before automating a score.",
          "zh": "自动评分前对账固定 CAS 的 0 个指标分支、2 个命名度量或全局变量、假设状态和本地运行有效性证据。"
        },
        {
          "code": "CIS-18.5-EVD-04",
          "local_code": "EVD-04",
          "display_code": "E04",
          "safeguard_id": "18.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original evidence-packet guidance",
          "basis_zh": "SOSEC 原创证据包指引",
          "en": "Retain configuration or procedure version, source receipt, positive and negative results, exception evidence, reviewer identity, integrity hash, retention class, and replay instructions.",
          "zh": "保留配置或程序版本、来源回执、正反向结果、例外证据、复核人身份、完整性哈希、保留类别和重放步骤。"
        },
        {
          "code": "CIS-18.5-EVD-05",
          "local_code": "EVD-05",
          "display_code": "E05",
          "safeguard_id": "18.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Derive coverage and effectiveness from the penetration-testing scope, authorization, finding, remediation, validation, and regression authority plus independent source receipts; report unknown, stale, conflicting, failed, and excepted objects separately.",
          "zh": "以渗透测试范围、授权、发现、修复、验证与回归权威记录和独立来源回执计算覆盖与有效性，分别报告未知、陈旧、冲突、失败和例外对象。"
        },
        {
          "code": "CIS-18.5-EVD-06",
          "local_code": "EVD-06",
          "display_code": "E06",
          "safeguard_id": "18.5",
          "category": "evidence",
          "category_en": "Evidence and metrics",
          "category_zh": "证据与指标",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Publish planned, executed, stopped, out-of-scope, prevented, detected, contained, missed, found, fixed, retest-passed, recurrent, and untested attack paths with query version, denominator timestamp, exclusions, unknowns, and drill-down receipts.",
          "zh": "发布 计划、执行、停止、越界、已阻断、已检测、已遏制、漏检、发现、修复、复测通过、复发和未测试攻击路径，附查询版本、分母时间、排除项、未知项和下钻回执。"
        },
        {
          "code": "CIS-18.5-SEC-01",
          "local_code": "SEC-01",
          "display_code": "S01",
          "safeguard_id": "18.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original security guidance",
          "basis_zh": "SOSEC 原创安全指引",
          "en": "Apply least privilege and separation of duties to the authority, connectors, policy engine, evidence store, exception workflow, break-glass path, and administrative recovery.",
          "zh": "对权威数据、连接器、策略引擎、证据库、例外流程、破窗路径和管理恢复应用最小权限与职责分离。"
        },
        {
          "code": "CIS-18.5-SEC-02",
          "local_code": "SEC-02",
          "display_code": "S02",
          "safeguard_id": "18.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original privacy guidance",
          "basis_zh": "SOSEC 原创隐私指引",
          "en": "Minimize secrets and personal or regulated data in requirements, telemetry, tests, screenshots, exports, and public evidence; define redaction and controlled raw-evidence access.",
          "zh": "在需求、遥测、测试、截图、导出和公开证据中最小化秘密、个人与受监管数据，并定义脱敏和受控原始证据访问。"
        },
        {
          "code": "CIS-18.5-SEC-03",
          "local_code": "SEC-03",
          "display_code": "S03",
          "safeguard_id": "18.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original evidence-integrity guidance",
          "basis_zh": "SOSEC 原创证据完整性指引",
          "en": "Protect policy, state, timestamps, logs, tests, and approvals against tampering with independent custody, immutable history where warranted, and alerting on disabled evidence paths.",
          "zh": "通过独立保管、必要时的不可变历史和证据路径停用告警，保护策略、状态、时间、日志、测试与审批免受篡改。"
        },
        {
          "code": "CIS-18.5-SEC-04",
          "local_code": "SEC-04",
          "display_code": "S04",
          "safeguard_id": "18.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original resilience guidance",
          "basis_zh": "SOSEC 原创韧性指引",
          "en": "Define capacity, quota, dependency, regional, provider, offline, and disaster behavior; preserve a tested degraded-mode decision and recovery path.",
          "zh": "定义容量、配额、依赖、地域、提供商、离线和灾难行为，并保留经过测试的降级决策与恢复路径。"
        },
        {
          "code": "CIS-18.5-SEC-05",
          "local_code": "SEC-05",
          "display_code": "S05",
          "safeguard_id": "18.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Protect write and approval authority over the penetration-testing scope, authorization, finding, remediation, validation, and regression authority; monitor privileged changes, exports, deletions, source disablement, and recovery.",
          "zh": "保护渗透测试范围、授权、发现、修复、验证与回归权威记录的写入与审批权限，监测特权变更、导出、删除、来源停用和恢复。"
        },
        {
          "code": "CIS-18.5-SEC-06",
          "local_code": "SEC-06",
          "display_code": "S06",
          "safeguard_id": "18.5",
          "category": "security",
          "category_en": "Security, privacy, and resilience",
          "category_zh": "安全、隐私与韧性",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Restrict authority to change authorized → scoped → rehearsed → executed with stop conditions → evidenced → triaged → remediated → independently retested → regression monitored; log privileged changes, protect evidence history, and test administrative recovery.",
          "zh": "限制改变“授权 → 定范围 → 预演 → 带停止条件执行 → 取证 → 分流 → 修复 → 独立复测 → 回归监测”的权限，记录特权变更，保护证据历史并测试管理恢复。"
        },
        {
          "code": "CIS-18.5-TST-01",
          "local_code": "TST-01",
          "display_code": "V01",
          "safeguard_id": "18.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original positive-control guidance",
          "basis_zh": "SOSEC 原创正向控制指引",
          "en": "Run a legitimate positive control through the real production-equivalent path and verify both business success and the complete evidence receipt.",
          "zh": "让合法正向控制走完真实或生产等价路径，同时验证业务成功和完整证据回执。"
        },
        {
          "code": "CIS-18.5-TST-02",
          "local_code": "TST-02",
          "display_code": "V02",
          "safeguard_id": "18.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original negative-control guidance",
          "basis_zh": "SOSEC 原创反向控制指引",
          "en": "Run an unauthorized or invalid negative control plus stale, duplicate, malformed, out-of-order, cross-tenant, and bypass variants; verify the intended denial or safe disposition.",
          "zh": "执行未授权或无效反向控制，并加入陈旧、重复、畸形、乱序、跨租户和绕过变体，验证预期拒绝或安全处置。"
        },
        {
          "code": "CIS-18.5-TST-03",
          "local_code": "TST-03",
          "display_code": "V03",
          "safeguard_id": "18.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original failure-injection guidance",
          "basis_zh": "SOSEC 原创故障注入指引",
          "en": "Inject source, credential, parser, policy, network, provider, queue, storage, clock, reviewer, and rollback failures; verify health detection and the declared degraded state.",
          "zh": "注入来源、凭据、解析器、策略、网络、提供商、队列、存储、时钟、复核人和回滚故障，验证健康检测与声明的降级状态。"
        },
        {
          "code": "CIS-18.5-TST-04",
          "local_code": "TST-04",
          "display_code": "V04",
          "safeguard_id": "18.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original sampling guidance",
          "basis_zh": "SOSEC 原创抽样指引",
          "en": "Use risk-stratified platform samples covering critical, common, exceptional, newly changed, provider-managed, safety-sensitive, remote, and ephemeral populations.",
          "zh": "采用风险分层平台样本，覆盖关键、常见、例外、刚变更、提供商托管、安全关键、远程和短生总体。"
        },
        {
          "code": "CIS-18.5-TST-05",
          "local_code": "TST-05",
          "display_code": "V05",
          "safeguard_id": "18.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Exercise external and internal reconnaissance, unauthenticated and authenticated paths, segmentation and privilege chains, controlled objectives, stop conditions, detection response, remediation, and independent retest through representative platforms and verify business behavior, control decision, telemetry, case workflow, rollback, and final state.",
          "zh": "在代表性平台演练 外部与内部侦察、未认证与已认证路径、分段与权限链、受控目标、停止条件、检测响应、修复和独立复测，验证业务行为、控制决策、遥测、案件流程、回滚和最终状态。"
        },
        {
          "code": "CIS-18.5-TST-06",
          "local_code": "TST-06",
          "display_code": "V06",
          "safeguard_id": "18.5",
          "category": "testing",
          "category_en": "Verification and adversarial tests",
          "category_zh": "验证与对抗测试",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Run the positive control a controlled objective that exercises prevention, detection, response, and safe recovery; exercise negative, stale, duplicate, bypass, and outage controls including an unauthorized path, scope ambiguity, missed detection, unsafe impact, incomplete evidence, failed remediation, transferred discovery method, and regression.",
          "zh": "运行正向控制“一项同时检验预防、检测、响应和安全恢复的受控目标”，并执行包含“未授权路径、范围歧义、漏检、不安全影响、证据不完整、修复失败、旧发现方法迁移和回归”的反向、陈旧、重复、绕过和中断控制。"
        },
        {
          "code": "CIS-18.5-OPS-01",
          "local_code": "OPS-01",
          "display_code": "R01",
          "safeguard_id": "18.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original rollout guidance",
          "basis_zh": "SOSEC 原创发布指引",
          "en": "Promote through design, observe, canary, enforce, and scale stages with entry and exit criteria, business positives, negative controls, exception readiness, and tested rollback.",
          "zh": "按设计、观察、金丝雀、强制和扩展阶段发布，每阶段都有进入/退出条件、业务正向、反向控制、例外准备和已测试回滚。"
        },
        {
          "code": "CIS-18.5-OPS-02",
          "local_code": "OPS-02",
          "display_code": "R02",
          "safeguard_id": "18.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original operational-metrics guidance",
          "basis_zh": "SOSEC 原创运营指标指引",
          "en": "Monitor population growth, source health, stale evidence, failed actions, backlog age, exception expiry, control bypass, false positives, false negatives, and recurring causes.",
          "zh": "监测总体增长、来源健康、证据陈旧、动作失败、积压年龄、例外到期、控制绕过、误报、漏报和复发根因。"
        },
        {
          "code": "CIS-18.5-OPS-03",
          "local_code": "OPS-03",
          "display_code": "R03",
          "safeguard_id": "18.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original evidence-renewal guidance",
          "basis_zh": "SOSEC 原创证据续期指引",
          "en": "Invalidate affected receipts after source, parser, policy, owner, provider, architecture, software, data-use, or threat change; retain history while displaying the current state as stale.",
          "zh": "来源、解析器、策略、责任人、提供商、架构、软件、数据用途或威胁变化后，使受影响回执失效；保留历史并显示当前为陈旧。"
        },
        {
          "code": "CIS-18.5-OPS-04",
          "local_code": "OPS-04",
          "display_code": "R04",
          "safeguard_id": "18.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original closure guidance",
          "basis_zh": "SOSEC 原创关闭指引",
          "en": "Close only after the protected state changes, evidence is fresh, positive and negative controls pass, downstream authorities reconcile, residual risk is recorded, and recurrence monitoring is active.",
          "zh": "只有受保护状态已改变、证据新鲜、正反向控制通过、下游权威对账、残余风险已记录且复发监测已启用时才关闭。"
        },
        {
          "code": "CIS-18.5-OPS-05",
          "local_code": "OPS-05",
          "display_code": "R05",
          "safeguard_id": "18.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC control-specific PRD analysis",
          "basis_zh": "SOSEC 按 Control 原创 PRD 分析",
          "en": "Re-run reconciliation and affected tests whenever asset and exposure inventories, architecture and threat models, rules of engagement, credentials, tester records, evidence, findings, remediation tickets, detections, and retest results change ownership, schema, coverage, provider, policy, or platform version.",
          "zh": "当 资产与暴露清单、架构与威胁模型、交战规则、凭据、测试人员记录、证据、发现、修复工单、检测和复测结果 的责任、模式、覆盖、提供商、策略或平台版本变化时重新对账并重跑受影响测试。"
        },
        {
          "code": "CIS-18.5-OPS-06",
          "local_code": "OPS-06",
          "display_code": "R06",
          "safeguard_id": "18.5",
          "category": "operations",
          "category_en": "Operations, change, and closure",
          "category_zh": "运营、变更与收口",
          "basis_en": "SOSEC original adversarial pattern analysis",
          "basis_zh": "SOSEC 原创 adversarial 模式分析",
          "en": "Use planned, executed, stopped, out-of-scope, prevented, detected, contained, missed, found, fixed, retest-passed, recurrent, and untested attack paths to drive backlog, renewal, incident handling, trend review, and retirement; recurrence reopens root-cause work.",
          "zh": "用 计划、执行、停止、越界、已阻断、已检测、已遏制、漏检、发现、修复、复测通过、复发和未测试攻击路径 驱动积压、续期、事件处置、趋势复核和退役；复发会重开根因工作。"
        }
      ]
    }
  ]
}
